Arcticguitar
Posts: 12 +0
Hi guys currently battling to get rid of some issues with my computer
I have run malwarebytes and it returns clean, Roguekiller returns a list of problems some of which it fails to delete. The log is below.. any help would be appreciated!
RogueKiller V10.11.0.0 (x64) [Oct 12 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 10 (10.0.10240) 64 bits version
Started in : Normal mode
User : Mark [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller.exe
Mode : Delete -- Date : 10/18/2015 01:26:43
¤¤¤ Processes : 1 ¤¤¤
[Suspicious.Path|VT.PUA.Win32.Bang5mai.B] B5TService.exe(1948) -- C:\Users\Mark\AppData\Local\B5T\Share\B5TService.exe[7] -> Killed [TermProc]
¤¤¤ Registry : 17 ¤¤¤
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB4F6285-4C32-49F2-950F-A5998F9CEC6C} -> Deleted
[Suspicious.Path|VT.PUA.Win32.Bang5mai.B] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\B5TService (C:\Users\Mark\AppData\Local\B5T\Share\B5TService.exe) -> ERROR [2]
[PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\globalUpdate (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc) -> Deleted
[PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\globalUpdatem (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc) -> Deleted
[PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\QMUdisk (\??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QMUdisk64.sys) -> Deleted
[PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\TS888x64 (\??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TS888x64.sys) -> Deleted
[Suspicious.Path|VT.PUA.Win32.Bang5mai.B] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\B5TService (C:\Users\Mark\AppData\Local\B5T\Share\B5TService.exe) -> ERROR [2]
[PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\globalUpdate (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc) -> Deleted
[PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\globalUpdatem (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc) -> Deleted
[PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\QMUdisk (\??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QMUdisk64.sys) -> Deleted
[PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TS888x64 (\??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TS888x64.sys) -> Deleted
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3ba57826-92ce-4be0-89c0-1b0fba1f948f} | DhcpNameServer : 132.181.2.225 ([NEW ZEALAND (NZ)]) -> Replaced ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{f06ede0b-67ad-4897-b95f-f19dcdb3f340} | DhcpNameServer : 172.20.10.1 ([(Private Address) (XX)]) -> Replaced ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{3ba57826-92ce-4be0-89c0-1b0fba1f948f} | DhcpNameServer : 132.181.2.225 ([NEW ZEALAND (NZ)]) -> Replaced ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{f06ede0b-67ad-4897-b95f-f19dcdb3f340} | DhcpNameServer : 172.20.10.1 ([(Private Address) (XX)]) -> Replaced ()
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs : C:\ProgramData\TomorrowGames\TomorrowGames64.dll [x] -> Replaced ()
[Suspicious.Path] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs : C:\ProgramData\TomorrowGames\TomorrowGames32.dll [x] -> Replaced ()
¤¤¤ Tasks : 7 ¤¤¤
[Suspicious.Path] %WINDIR%\Tasks\BjVpZR0KMXLmqFPxQqJf.job -- C:\Users\Mark\AppData\Roaming\BjVpZR0KMXLmqFPxQqJf.exe (--c=tzXn+l0JoRxG9RYoouIN5Tu2aap1T9ij7+LoFsJa8pUAszjg8IS09+ZeIiUZ49LlSaj35L7ZJJHs3OU05PenSHPlcde1/E5JYMmiRCp4Bc4wR4YO/1Z81he96aRkYt9JkCNSCQl4FOiXtGj3R73KTBMODEvLV6GB5BM4/t0UJpw6IZL2Ea/YMgSQc3zMqfQZCtkRpDZkFx5Fc3hwQs99NgHqIooMGmr2SncuQ1yNuJhPPUZSvpof74gOXjOwa40uLdtIBBDGPwyGzTjJsvwAQUrfkaZkgtTU0CANisnn7wDz8yz7qnGcGc6iBDbeYidosIjXI5XgQSvtDZDi08XJHw==) -> Not selected
[Suspicious.Path] %WINDIR%\Tasks\CRHJNcp9yj.job -- C:\Users\Mark\AppData\Roaming\CRHJNcp9yj.exe (--c=CVI6aS2tBJoY0gDgjNAuIl/NkiDwIjh2JrOByTHpYinHos3CdXan4rF3nVuD7fg0F2tIsoT/3Qm7FuYckumlG/PXaDj3gs21k+63Q1ns7Pnll2/7bvKmtkfX+kl7F4C/tDTXInLlpcS3IJyqvuie+ppbEXEhST1fXMmunIqXbp4SIzMQs0FTPQBVwrAhsVaaISjhHMBOg1gILv+McymLIK/8T+zkOvtbjjAQRjN8CX22AafSgGWHqq1rPcG9jI2B8Er9e9BltQwJKPOUcbSM2GJfTlSgOeYG5ZC0nSqEaZqNmzUS94Zhuksjl+8gvQL0gO5/1JOi9iPxJWni8i3F8g==) -> Not selected
[PUP] %WINDIR%\Tasks\PJLCHJVGLWIKYUCM.job -- C:\ProgramData\Service1104\Service1104.exe -> Not selected
[Suspicious.Path] \BjVpZR0KMXLmqFPxQqJf -- C:\Users\Mark\AppData\Roaming\BjVpZR0KMXLmqFPxQqJf.exe (--c=tzXn+l0JoRxG9RYoouIN5Tu2aap1T9ij7+LoFsJa8pUAszjg8IS09+ZeIiUZ49LlSaj35L7ZJJHs3OU05PenSHPlcde1/E5JYMmiRCp4Bc4wR4YO/1Z81he96aRkYt9JkCNSCQl4FOiXtGj3R73KTBMODEvLV6GB5BM4/t0UJpw6IZL2Ea/YMgSQc3zMqfQZCtkRpDZkFx5Fc3hwQs99NgHqIooMGmr2SncuQ1yNuJhPPUZSvpof74gOXjOwa40uLdtIBBDGPwyGzTjJsvwAQUrfkaZkgtTU0CANisnn7wDz8yz7qnGcGc6iBDbeYidosIjXI5XgQSvtDZDi08XJHw==) -> Not selected
[Suspicious.Path] \CD7FA4BF-227E-4328-9290-F43CDBCE314D -- C:\Users\Mark\AppData\Local\CD7FA4BF-227E-4328-9290-F43CDBCE314D\CD7FA4BF-227E-4328-9290-F43CDBCE314D.exe (/installapp /asru /reinstalltask) -> Not selected
[Suspicious.Path] \CRHJNcp9yj -- C:\Users\Mark\AppData\Roaming\CRHJNcp9yj.exe (--c=CVI6aS2tBJoY0gDgjNAuIl/NkiDwIjh2JrOByTHpYinHos3CdXan4rF3nVuD7fg0F2tIsoT/3Qm7FuYckumlG/PXaDj3gs21k+63Q1ns7Pnll2/7bvKmtkfX+kl7F4C/tDTXInLlpcS3IJyqvuie+ppbEXEhST1fXMmunIqXbp4SIzMQs0FTPQBVwrAhsVaaISjhHMBOg1gILv+McymLIK/8T+zkOvtbjjAQRjN8CX22AafSgGWHqq1rPcG9jI2B8Er9e9BltQwJKPOUcbSM2GJfTlSgOeYG5ZC0nSqEaZqNmzUS94Zhuksjl+8gvQL0gO5/1JOi9iPxJWni8i3F8g==) -> Not selected
[PUP] \System Optimizer Schedule -- "C:\Program Files (x86)\System Optimizer\SysOptLauncher.exe" -> Not selected
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.1 mssplus.mcafee.com
¤¤¤ Antirootkit : 62 (Driver: Loaded) ¤¤¤
[IAT:Addr(Hook.IEAT)] (chrome.exe) kernel32!CreateNamedPipeW : Unknown @ 0x800010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) kernel32!CreateNamedPipeW : Unknown @ 0x800010
[IAT:Addr(Hook.IEAT)] (chrome.exe) kernel32!CreateNamedPipeW : Unknown @ 0xc60010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GdiDllInitialize : Unknown @ 0xe70010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ msctf.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) user32!RegisterClassW : Unknown @ 0xc80010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shlwapi.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) kernel32!CreateNamedPipeW : Unknown @ 0xc60010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) user32!RegisterClassW : Unknown @ 0xc80010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) user32!RegisterClassW : Unknown @ 0xc80010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) user32!RegisterClassW : Unknown @ 0xc80010
[IAT:Addr(Hook.IEAT)] (chrome.exe) kernel32!CreateNamedPipeW : Unknown @ 0x940010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GdiDllInitialize : Unknown @ 0xc30010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ msctf.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) user32!RegisterClassW : Unknown @ 0x960010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shlwapi.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) kernel32!CreateNamedPipeW : Unknown @ 0x940010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) user32!RegisterClassW : Unknown @ 0x960010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) user32!RegisterClassW : Unknown @ 0x960010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) user32!RegisterClassW : Unknown @ 0x960010
[IAT:Addr(Hook.IEAT)] (chrome.exe) kernel32!CreateNamedPipeW : Unknown @ 0xb30010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GdiDllInitialize : Unknown @ 0xe50010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ msctf.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) user32!RegisterClassW : Unknown @ 0xb50010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shlwapi.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) kernel32!CreateNamedPipeW : Unknown @ 0xb30010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) user32!RegisterClassW : Unknown @ 0xb50010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) user32!RegisterClassW : Unknown @ 0xb50010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) user32!RegisterClassW : Unknown @ 0xb50010
[IAT:Addr(Hook.IEAT)] (chrome.exe) kernel32!CreateNamedPipeW : Unknown @ 0x470010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GdiDllInitialize : Unknown @ 0x680010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ msctf.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) user32!RegisterClassW : Unknown @ 0x490010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shlwapi.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) kernel32!CreateNamedPipeW : Unknown @ 0x470010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) user32!RegisterClassW : Unknown @ 0x490010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) user32!RegisterClassW : Unknown @ 0x490010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) user32!RegisterClassW : Unknown @ 0x490010
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD10EARX-00N0YB0 ATA Device +++++
--- User ---
[MBR] a841a0eaf1de2e416ed7e350a873a99b
[BSP] 21453ed1b20cd20f4501fc3821edbae8 : Compressed BootMgr|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1920221984 | Size: 886821 MB[Invalid]
1 - [XXXXXX] UNKNOWN (0x6c) [VISIBLE] Offset (sectors): 1936028192 | Size: 953932 MB
3 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 27722122 | Size: 0 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: WDC WD10EADS-00M2B0 ATA Device +++++
--- User ---
[MBR] 01440f12320463772ee16616ec5b3675
[BSP] 74d95262aaab550e6c598cebc84a026f : Empty|VT.Unknown MBR Code
Partition table:
0 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2048 | Size: 100 MB
1 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 206848 | Size: 128 MB
2 - Basic data partition | Offset (sectors): 468992 | Size: 953190 MB
3 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 1952602112 | Size: 450 MB
User = LL1 ... OK
User = LL2 ... OK
I have run malwarebytes and it returns clean, Roguekiller returns a list of problems some of which it fails to delete. The log is below.. any help would be appreciated!
RogueKiller V10.11.0.0 (x64) [Oct 12 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 10 (10.0.10240) 64 bits version
Started in : Normal mode
User : Mark [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller.exe
Mode : Delete -- Date : 10/18/2015 01:26:43
¤¤¤ Processes : 1 ¤¤¤
[Suspicious.Path|VT.PUA.Win32.Bang5mai.B] B5TService.exe(1948) -- C:\Users\Mark\AppData\Local\B5T\Share\B5TService.exe[7] -> Killed [TermProc]
¤¤¤ Registry : 17 ¤¤¤
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB4F6285-4C32-49F2-950F-A5998F9CEC6C} -> Deleted
[Suspicious.Path|VT.PUA.Win32.Bang5mai.B] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\B5TService (C:\Users\Mark\AppData\Local\B5T\Share\B5TService.exe) -> ERROR [2]
[PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\globalUpdate (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc) -> Deleted
[PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\globalUpdatem (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc) -> Deleted
[PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\QMUdisk (\??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QMUdisk64.sys) -> Deleted
[PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\TS888x64 (\??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TS888x64.sys) -> Deleted
[Suspicious.Path|VT.PUA.Win32.Bang5mai.B] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\B5TService (C:\Users\Mark\AppData\Local\B5T\Share\B5TService.exe) -> ERROR [2]
[PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\globalUpdate (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /svc) -> Deleted
[PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\globalUpdatem (C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe /medsvc) -> Deleted
[PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\QMUdisk (\??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QMUdisk64.sys) -> Deleted
[PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TS888x64 (\??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TS888x64.sys) -> Deleted
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3ba57826-92ce-4be0-89c0-1b0fba1f948f} | DhcpNameServer : 132.181.2.225 ([NEW ZEALAND (NZ)]) -> Replaced ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{f06ede0b-67ad-4897-b95f-f19dcdb3f340} | DhcpNameServer : 172.20.10.1 ([(Private Address) (XX)]) -> Replaced ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{3ba57826-92ce-4be0-89c0-1b0fba1f948f} | DhcpNameServer : 132.181.2.225 ([NEW ZEALAND (NZ)]) -> Replaced ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{f06ede0b-67ad-4897-b95f-f19dcdb3f340} | DhcpNameServer : 172.20.10.1 ([(Private Address) (XX)]) -> Replaced ()
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs : C:\ProgramData\TomorrowGames\TomorrowGames64.dll [x] -> Replaced ()
[Suspicious.Path] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs : C:\ProgramData\TomorrowGames\TomorrowGames32.dll [x] -> Replaced ()
¤¤¤ Tasks : 7 ¤¤¤
[Suspicious.Path] %WINDIR%\Tasks\BjVpZR0KMXLmqFPxQqJf.job -- C:\Users\Mark\AppData\Roaming\BjVpZR0KMXLmqFPxQqJf.exe (--c=tzXn+l0JoRxG9RYoouIN5Tu2aap1T9ij7+LoFsJa8pUAszjg8IS09+ZeIiUZ49LlSaj35L7ZJJHs3OU05PenSHPlcde1/E5JYMmiRCp4Bc4wR4YO/1Z81he96aRkYt9JkCNSCQl4FOiXtGj3R73KTBMODEvLV6GB5BM4/t0UJpw6IZL2Ea/YMgSQc3zMqfQZCtkRpDZkFx5Fc3hwQs99NgHqIooMGmr2SncuQ1yNuJhPPUZSvpof74gOXjOwa40uLdtIBBDGPwyGzTjJsvwAQUrfkaZkgtTU0CANisnn7wDz8yz7qnGcGc6iBDbeYidosIjXI5XgQSvtDZDi08XJHw==) -> Not selected
[Suspicious.Path] %WINDIR%\Tasks\CRHJNcp9yj.job -- C:\Users\Mark\AppData\Roaming\CRHJNcp9yj.exe (--c=CVI6aS2tBJoY0gDgjNAuIl/NkiDwIjh2JrOByTHpYinHos3CdXan4rF3nVuD7fg0F2tIsoT/3Qm7FuYckumlG/PXaDj3gs21k+63Q1ns7Pnll2/7bvKmtkfX+kl7F4C/tDTXInLlpcS3IJyqvuie+ppbEXEhST1fXMmunIqXbp4SIzMQs0FTPQBVwrAhsVaaISjhHMBOg1gILv+McymLIK/8T+zkOvtbjjAQRjN8CX22AafSgGWHqq1rPcG9jI2B8Er9e9BltQwJKPOUcbSM2GJfTlSgOeYG5ZC0nSqEaZqNmzUS94Zhuksjl+8gvQL0gO5/1JOi9iPxJWni8i3F8g==) -> Not selected
[PUP] %WINDIR%\Tasks\PJLCHJVGLWIKYUCM.job -- C:\ProgramData\Service1104\Service1104.exe -> Not selected
[Suspicious.Path] \BjVpZR0KMXLmqFPxQqJf -- C:\Users\Mark\AppData\Roaming\BjVpZR0KMXLmqFPxQqJf.exe (--c=tzXn+l0JoRxG9RYoouIN5Tu2aap1T9ij7+LoFsJa8pUAszjg8IS09+ZeIiUZ49LlSaj35L7ZJJHs3OU05PenSHPlcde1/E5JYMmiRCp4Bc4wR4YO/1Z81he96aRkYt9JkCNSCQl4FOiXtGj3R73KTBMODEvLV6GB5BM4/t0UJpw6IZL2Ea/YMgSQc3zMqfQZCtkRpDZkFx5Fc3hwQs99NgHqIooMGmr2SncuQ1yNuJhPPUZSvpof74gOXjOwa40uLdtIBBDGPwyGzTjJsvwAQUrfkaZkgtTU0CANisnn7wDz8yz7qnGcGc6iBDbeYidosIjXI5XgQSvtDZDi08XJHw==) -> Not selected
[Suspicious.Path] \CD7FA4BF-227E-4328-9290-F43CDBCE314D -- C:\Users\Mark\AppData\Local\CD7FA4BF-227E-4328-9290-F43CDBCE314D\CD7FA4BF-227E-4328-9290-F43CDBCE314D.exe (/installapp /asru /reinstalltask) -> Not selected
[Suspicious.Path] \CRHJNcp9yj -- C:\Users\Mark\AppData\Roaming\CRHJNcp9yj.exe (--c=CVI6aS2tBJoY0gDgjNAuIl/NkiDwIjh2JrOByTHpYinHos3CdXan4rF3nVuD7fg0F2tIsoT/3Qm7FuYckumlG/PXaDj3gs21k+63Q1ns7Pnll2/7bvKmtkfX+kl7F4C/tDTXInLlpcS3IJyqvuie+ppbEXEhST1fXMmunIqXbp4SIzMQs0FTPQBVwrAhsVaaISjhHMBOg1gILv+McymLIK/8T+zkOvtbjjAQRjN8CX22AafSgGWHqq1rPcG9jI2B8Er9e9BltQwJKPOUcbSM2GJfTlSgOeYG5ZC0nSqEaZqNmzUS94Zhuksjl+8gvQL0gO5/1JOi9iPxJWni8i3F8g==) -> Not selected
[PUP] \System Optimizer Schedule -- "C:\Program Files (x86)\System Optimizer\SysOptLauncher.exe" -> Not selected
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.1 mssplus.mcafee.com
¤¤¤ Antirootkit : 62 (Driver: Loaded) ¤¤¤
[IAT:Addr(Hook.IEAT)] (chrome.exe) kernel32!CreateNamedPipeW : Unknown @ 0x800010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) kernel32!CreateNamedPipeW : Unknown @ 0x800010
[IAT:Addr(Hook.IEAT)] (chrome.exe) kernel32!CreateNamedPipeW : Unknown @ 0xc60010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GdiDllInitialize : Unknown @ 0xe70010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ msctf.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) user32!RegisterClassW : Unknown @ 0xc80010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shlwapi.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) kernel32!CreateNamedPipeW : Unknown @ 0xc60010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) user32!RegisterClassW : Unknown @ 0xc80010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) user32!RegisterClassW : Unknown @ 0xc80010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) gdi32!GetStockObject : Unknown @ 0xe70050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) user32!RegisterClassW : Unknown @ 0xc80010
[IAT:Addr(Hook.IEAT)] (chrome.exe) kernel32!CreateNamedPipeW : Unknown @ 0x940010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GdiDllInitialize : Unknown @ 0xc30010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ msctf.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) user32!RegisterClassW : Unknown @ 0x960010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shlwapi.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) kernel32!CreateNamedPipeW : Unknown @ 0x940010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) user32!RegisterClassW : Unknown @ 0x960010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) user32!RegisterClassW : Unknown @ 0x960010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) gdi32!GetStockObject : Unknown @ 0xc30050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) user32!RegisterClassW : Unknown @ 0x960010
[IAT:Addr(Hook.IEAT)] (chrome.exe) kernel32!CreateNamedPipeW : Unknown @ 0xb30010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GdiDllInitialize : Unknown @ 0xe50010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ msctf.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) user32!RegisterClassW : Unknown @ 0xb50010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shlwapi.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) kernel32!CreateNamedPipeW : Unknown @ 0xb30010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) user32!RegisterClassW : Unknown @ 0xb50010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) user32!RegisterClassW : Unknown @ 0xb50010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) gdi32!GetStockObject : Unknown @ 0xe50050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) user32!RegisterClassW : Unknown @ 0xb50010
[IAT:Addr(Hook.IEAT)] (chrome.exe) kernel32!CreateNamedPipeW : Unknown @ 0x470010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GdiDllInitialize : Unknown @ 0x680010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ user32.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ msctf.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) user32!RegisterClassW : Unknown @ 0x490010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shell32.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ shlwapi.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) kernel32!CreateNamedPipeW : Unknown @ 0x470010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ chrome_child.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) user32!RegisterClassW : Unknown @ 0x490010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comdlg32.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ ole32.dll) user32!RegisterClassW : Unknown @ 0x490010
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) gdi32!GetStockObject : Unknown @ 0x680050
[IAT:Addr(Hook.IEAT)] (chrome.exe @ comctl32.dll) user32!RegisterClassW : Unknown @ 0x490010
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD10EARX-00N0YB0 ATA Device +++++
--- User ---
[MBR] a841a0eaf1de2e416ed7e350a873a99b
[BSP] 21453ed1b20cd20f4501fc3821edbae8 : Compressed BootMgr|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1920221984 | Size: 886821 MB[Invalid]
1 - [XXXXXX] UNKNOWN (0x6c) [VISIBLE] Offset (sectors): 1936028192 | Size: 953932 MB
3 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 27722122 | Size: 0 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: WDC WD10EADS-00M2B0 ATA Device +++++
--- User ---
[MBR] 01440f12320463772ee16616ec5b3675
[BSP] 74d95262aaab550e6c598cebc84a026f : Empty|VT.Unknown MBR Code
Partition table:
0 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2048 | Size: 100 MB
1 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 206848 | Size: 128 MB
2 - Basic data partition | Offset (sectors): 468992 | Size: 953190 MB
3 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 1952602112 | Size: 450 MB
User = LL1 ... OK
User = LL2 ... OK