Results from roguekiller:
RogueKiller V10.0.4.0 [Oct 29 2014] by Adlice Software
mail :
http://www.adlice.com/contact/
Feedback :
http://forum.adlice.com
Website :
http://www.adlice.com/softwares/roguekiller/
Blog :
http://www.adlice.com
Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : e4300 [Administrator]
Mode : Delete -- Date : 11/02/2014 20:18:10
¤¤¤ Processes : 2 ¤¤¤
[Suspicious.Path] explorer.exe -- C:\ProgramData\{D9E629DC-CB1C-4A97-9900-81922B4EFFD4}\zipfldr.dll[-] -> Unloaded
[Suspicious.Path] rundll32.exe -- C:\Users\e4300\AppData\Local\movziuz.dll[-] -> Unloaded
¤¤¤ Registry : 12 ¤¤¤
[PUP] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} -> Not selected
[PUP] HKEY_CLASSES_ROOT\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} -> Not selected
[PUP] HKEY_USERS\S-1-5-21-2579459372-583501214-59938211-1000\Software\Microsoft\Windows\CurrentVersion\Run | PriceMeterW : "C:\Users\e4300\AppData\Local\PriceMeter\pricemeterw.exe" -> Not selected
[Suspicious.Path] HKEY_USERS\S-1-5-21-2579459372-583501214-59938211-1000\Software\Microsoft\Windows\CurrentVersion\Run | movziuz : rundll32 "C:\Users\e4300\AppData\Local\movziuz.dll",movziuz [x][x] -> Deleted
[Suspicious.Path] HKEY_USERS\S-1-5-21-2579459372-583501214-59938211-1000\Software\Microsoft\Windows\CurrentVersion\Run | PoxkEsosv : regsvr32.exe "C:\ProgramData\PoxkEsosv\PoxkEsosv.dat" [7][-] -> Deleted
[Suspicious.Path] HKEY_USERS\S-1-5-21-2579459372-583501214-59938211-1000\Software\Microsoft\Windows\CurrentVersion\Run | OufjeZfoze : regsvr32.exe "C:\ProgramData\OufjeZfoze\OufjeZfoze.dat" [7][-] -> Deleted
[PUM.HomePage] HKEY_USERS\S-1-5-21-2579459372-583501214-59938211-1000\Software\Microsoft\Internet Explorer\Main | Start Page :
http://www.yahoo.com/ -> Not selected
[PUM.Policies] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Not selected
[PUM.StartMenu] HKEY_USERS\S-1-5-21-2579459372-583501214-59938211-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Not selected
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Not selected
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Not selected
[Tr.Poweliks] HKEY_USERS\S-1-5-21-2579459372-583501214-59938211-1000\Software\classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\LocalServer32 -> Deleted
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 59 (Driver: Loaded) ¤¤¤
[IAT:Inl] (explorer.exe) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ USER32.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ MSCTF.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ iertutil.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Addr] (explorer.exe @ USERENV.dll) GPAPI.dll - RegisterGPNotificationInternal : Unknown @ 0x74d3278f
[IAT:Inl] (explorer.exe @ SETUPAPI.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ apphelp.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ CLBCatQ.DLL) ADVAPI32.dll - CreateProcessAsUserW : Unknown @ 0x699b3cd (jmp 0x655ee9b)
[IAT:Inl] (explorer.exe @ CLBCatQ.DLL) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ SndVolSSO.DLL) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ urlmon.dll) KERNEL32.dll - CreateProcessA : Unknown @ 0x699b32b (jmp 0xffffffff90a292a9)
[IAT:Addr] (explorer.exe @ schannel.DLL) ncrypt.dll - SslIncrementProviderReferenceCount : Unknown @ 0x752b5c53
[IAT:Addr] (explorer.exe @ schannel.DLL) ncrypt.dll - SslEncryptPacket : Unknown @ 0x752b38a3
[IAT:Addr] (explorer.exe @ schannel.DLL) ncrypt.dll - SslOpenProvider : Unknown @ 0x752ba8ed
[IAT:Addr] (explorer.exe @ schannel.DLL) ncrypt.dll - SslLookupCipherSuiteInfo : Unknown @ 0x752b59c7
[IAT:Addr] (explorer.exe @ schannel.DLL) ncrypt.dll - SslImportKey : Unknown @ 0x752b5bb1
[IAT:Inl] (explorer.exe @ CRYPTUI.dll) CRYPT32.dll - PFXImportCertStore : Unknown @ 0x6999d69 (jmp 0xffffffff910684b1)
[IAT:Inl] (explorer.exe @ wer.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ msi.dll) ADVAPI32.dll - CreateProcessAsUserW : Unknown @ 0x699b3cd (jmp 0x655ee9b)
[IAT:Inl] (explorer.exe @ ieframe.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ stobject.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ es.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ pnidui.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ FXSAPI.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ netcenter.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ ADVPACK.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ werconcpl.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ EhStorAPI.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ sysmain.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ igfxpph.dll) KERNEL32.dll - CreateProcessA : Unknown @ 0x699b32b (jmp 0xffffffff90a292a9)
[IAT:Inl] (explorer.exe @ sbdrop.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ acppage.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (explorer.exe @ xwizards.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x699b285 (jmp 0xffffffff90a29238)
[IAT:Inl] (firefox.exe @ MSVCR100.dll) KERNEL32.dll - CreateProcessA : Unknown @ 0x40b32b (jmp 0xffffffff8a4992a9)
[IAT:Inl] (firefox.exe @ MSVCR100.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x40b285 (jmp 0xffffffff8a499238)
[IAT:Inl] (firefox.exe @ USER32.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x40b285 (jmp 0xffffffff8a499238)
[IAT:Inl] (firefox.exe @ MSCTF.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x40b285 (jmp 0xffffffff8a499238)
[IAT:Inl] (firefox.exe @ iertutil.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x40b285 (jmp 0xffffffff8a499238)
[IAT:Inl] (firefox.exe @ sandboxbroker.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x40b285 (jmp 0xffffffff8a499238)
[IAT:Inl] (firefox.exe @ sandboxbroker.dll) ADVAPI32.dll - CreateProcessAsUserW : Unknown @ 0x40b3cd (jmp 0xffffffff8a3aee9b)
[IAT:Inl] (firefox.exe @ nss3.dll) KERNEL32.dll - CreateProcessA : Unknown @ 0x40b32b (jmp 0xffffffff8a4992a9)
[IAT:Inl] (firefox.exe @ xul.dll) nss3.dll - PR_Read : Unknown @ 0x40a21c (jmp 0xffffffff9573757c)
[IAT:Inl] (firefox.exe @ xul.dll) nss3.dll - PR_Close : Unknown @ 0x40a106 (jmp 0xffffffff95732a26)
[IAT:Inl] (firefox.exe @ xul.dll) nss3.dll - PR_Write : Unknown @ 0x40a34c (jmp 0xffffffff9573769c)
[IAT:Inl] (firefox.exe @ xul.dll) nss3.dll - PR_DestroyPollableEvent : Unknown @ 0x40a106 (jmp 0xffffffff95732a26)
[IAT:Inl] (firefox.exe @ xul.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x40b285 (jmp 0xffffffff8a499238)
[IAT:Inl] (firefox.exe @ SETUPAPI.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x40b285 (jmp 0xffffffff8a499238)
[IAT:Inl] (firefox.exe @ apphelp.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x40b285 (jmp 0xffffffff8a499238)
[IAT:Inl] (firefox.exe @ CLBCatQ.DLL) ADVAPI32.dll - CreateProcessAsUserW : Unknown @ 0x40b3cd (jmp 0xffffffff8a3aee9b)
[IAT:Inl] (firefox.exe @ CLBCatQ.DLL) KERNEL32.dll - CreateProcessW : Unknown @ 0x40b285 (jmp 0xffffffff8a499238)
[IAT:Inl] (firefox.exe @ browsercomps.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x40b285 (jmp 0xffffffff8a499238)
[IAT:Inl] (firefox.exe @ Wpc.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x40b285 (jmp 0xffffffff8a499238)
[IAT:Inl] (firefox.exe @ nssdbm3.dll) nss3.dll - PR_Read : Unknown @ 0x40a21c (jmp 0xffffffff9573757c)
[IAT:Inl] (firefox.exe @ nssdbm3.dll) nss3.dll - PR_Write : Unknown @ 0x40a34c (jmp 0xffffffff9573769c)
[IAT:Inl] (firefox.exe @ nssdbm3.dll) nss3.dll - PR_Close : Unknown @ 0x40a106 (jmp 0xffffffff95732a26)
[IAT:Inl] (firefox.exe @ freebl3.dll) nss3.dll - PR_Close : Unknown @ 0x40a106 (jmp 0xffffffff95732a26)
[IAT:Inl] (firefox.exe @ freebl3.dll) nss3.dll - PR_Read : Unknown @ 0x40a21c (jmp 0xffffffff9573757c)
[IAT:Inl] (firefox.exe @ urlmon.dll) KERNEL32.dll - CreateProcessA : Unknown @ 0x40b32b (jmp 0xffffffff8a4992a9)
[IAT:Inl] (firefox.exe @ mf.dll) KERNEL32.dll - CreateProcessW : Unknown @ 0x40b285 (jmp 0xffffffff8a499238)
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 29fdfa556d13eb95d2083272401a4ed7
[BSP] e7a4d88e39462edee4d9ce59ade9badd : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 152525 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: +++++
--- User ---
[MBR] ad33a3a547bba123744a073c3fd010a6
[BSP] 33a07a59d299ab4ea9f4ab0156f9d86f : Windows XP MBR Code
Partition table:
0 - [ACTIVE] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 8064 | Size: 14883 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] The request is not supported. )
============================================
RKreport_SCN_11022014_201622.log