RogueKiller V8.1.1 [10/03/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
https://www.techspot.com/downloads/5562-roguekiller.html
Website:
http://tigzy.geekstogo.com/roguekiller.php
Blog:
http://tigzyrk.blogspot.com
Operating
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 23 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\RunOnce : 109_95847513117 ("C:\Users\Meineke\AppData\Local\LogMeIn Rescue Applet\LMIR0003.tmp_r.bat") -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-1723799115-427907230-1844215600-1000[...]\RunOnce : 109_95847513117 ("C:\Users\Meineke\AppData\Local\LogMeIn Rescue Applet\LMIR0003.tmp_r.bat") -> FOUND
[TASK][BLACKLIST] {01737E60-5262-4105-BB88-FE5A39255548} : C:\Program Files (x86)\Meineke\Mkey3\MKey.exe -> FOUND
[TASK][BLACKLIST] {1578090A-EE37-4D7F-9770-B9752FB8E325} : C:\Program Files (x86)\Meineke\Mkey3\MKey.exe -> FOUND
[TASK][BLACKLIST] {1DE90D9B-5559-4FC6-B1B7-0C8FAE8B85E2} : C:\Program Files (x86)\Meineke\Mkey3\MKey.exe -> FOUND
[TASK][BLACKLIST] {5D5E8FD9-1876-4247-A429-0E14C149C163} : C:\Program Files (x86)\Meineke\Mkey3\MKey.exe -> FOUND
[TASK][BLACKLIST] {7D24B056-E7E1-41CA-9278-4B5273DFC620} : C:\Program Files (x86)\Meineke\Mkey3\MKey.exe -> FOUND
[TASK][BLACKLIST] {7E37A33E-B776-43AA-A029-0AE5F2194C94} : C:\Program Files (x86)\Meineke\Mkey3\MKey.exe -> FOUND
[TASK][BLACKLIST] {993C45FA-9EC8-4388-B31A-5D342BEBE463} : C:\Program Files (x86)\Meineke\Mkey3\MKey.exe -> FOUND
[TASK][BLACKLIST] {9A41EBB0-8302-4512-AC2B-5012B42A50A8} : C:\Program Files (x86)\Meineke\Mkey3\MKey.exe -> FOUND
[TASK][BLACKLIST] {BC5B9171-CE4F-48E9-82D5-5501FADB8BC8} : C:\Program Files (x86)\Meineke\Mkey3\MKey.exe -> FOUND
[TASK][BLACKLIST] {CAF12BD9-8F94-48DF-8EEA-A20B32B639C7} : C:\Program Files (x86)\Meineke\Mkey3\MKey.exe -> FOUND
[TASK][BLACKLIST] {DA888EF6-23D7-40AF-B57D-9F1A89DEFAF9} : C:\Program Files (x86)\Meineke\Mkey3\MKey.exe -> FOUND
[TASK][BLACKLIST] {F4E6E210-47F0-4DE7-B64B-A3A0829FE5C8} : C:\Program Files (x86)\Meineke\Mkey3\MKey.exe -> FOUND
[DNS] HKLM\[...]\ControlSet001\Services\Interfaces\{43F88FA6-A4CD-4941-A3AF-892DDADBB228} : NameServer (216.146.35.35,216.146.36.36,209.26.88.31,204.215.43.3) -> FOUND
[DNS] HKLM\[...]\ControlSet002\Services\Interfaces\{43F88FA6-A4CD-4941-A3AF-892DDADBB228} : NameServer (216.146.35.35,216.146.36.36,209.26.88.31,204.215.43.3) -> FOUND
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ] HKLM\[...]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
[HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\Users\Meineke\AppData\Local\{babeb83d-cb3f-7df7-b90e-f5ed8b6f3e53}\n.) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [NOT LOADED] ¤¤¤
¤¤¤ Infection : ZeroAccess|Root.MBR ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: WDC WD64 00AAKS-65Z7B0 SATA Disk Device +++++
--- User ---
[MBR] f20b8895274faa97fc10ad77d41a65d5
[BSP] 013490bbf7b0cdca1e05843829568fda : Windows Vista/7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 598024 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1224960000 | Size: 12354 Mo
User = LL1 ... OK!
User != LL2 ... KO!
--- LL2 ---
[MBR] f865fd65e9c3c863a930c5dd4a862f34
[BSP] 289999ed92a6a1d82d22dd89dfce7063 : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 264071168 | Size: 300 Mo
+++++ PhysicalDrive1: SanDisk Cruzer USB Device +++++
--- User ---
[MBR] a124dc1f32b91ceacb765c7a5ad6ec2e
[BSP] df4f83c1f72e36823a12b0dfc7617313 : MBR Code unknown
Partition table:
0 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 32 | Size: 15266 Mo
User = LL1 ... OK!
Error reading LL2 MBR!
Finished : << RKreport[1].txt >>
RKreport[1].txt