RogueKiller V9.2.4.0 [Jul 11 2014] by Adlice Software mail : http://www.adlice.com/contact/ Feedback : http://forum.adlice.com Website : http://www.adlice.com/softwares/roguekiller/ Blog : http://www.adlice.com Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version Started in : Normal mode User : QuiP [Admin rights] Mode : Scan -- Date : 08/07/2014 03:07:17 ¤¤¤ Bad processes : 0 ¤¤¤ ¤¤¤ Registry Entries : 10 ¤¤¤ [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aswMBR -> FOUND [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aswVmm -> FOUND [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aswMBR -> FOUND [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aswVmm -> FOUND [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 195.54.122.204 81.26.226.3 -> FOUND [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 195.54.122.204 81.26.226.3 -> FOUND [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 81.26.227.3 195.54.122.198 -> FOUND [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D7B6AEC1-605C-4985-BB4E-F016735E9EF1} | DhcpNameServer : 195.54.122.204 81.26.226.3 -> FOUND [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{D7B6AEC1-605C-4985-BB4E-F016735E9EF1} | DhcpNameServer : 195.54.122.204 81.26.226.3 -> FOUND [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{D7B6AEC1-605C-4985-BB4E-F016735E9EF1} | DhcpNameServer : 81.26.227.3 195.54.122.198 -> FOUND ¤¤¤ Scheduled tasks : 0 ¤¤¤ ¤¤¤ Files : 0 ¤¤¤ ¤¤¤ HOSTS File : 0 ¤¤¤ ¤¤¤ Antirootkit : 0 (Driver: NOT LOADED [0xc000036b]) ¤¤¤ ¤¤¤ Web browsers : 0 ¤¤¤ ¤¤¤ MBR Check : ¤¤¤ +++++ PhysicalDrive0: Samsung SSD 840 EVO 500GB ATA Device +++++ --- User --- [MBR] 99256d98decee2328e21688344cb0723 [BSP] 0103a45d6b840ed1516a5441d52748c0 : Windows Vista/7/8 MBR Code Partition table: 0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 476937 MB User = LL1 ... OK User = LL2 ... OK +++++ PhysicalDrive1: WDC WD6400AAKS-00A7B2 ATA Device +++++ --- User --- [MBR] 3c0c42a1a36e2fad7e539a07ec630c9c [BSP] e717f24d6d244c18e59b79e40ab2617d : Windows Vista/7/8 MBR Code Partition table: 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 610478 MB User = LL1 ... OK User = LL2 ... OK +++++ PhysicalDrive2: WDC WD6400AAKS-00A7B2 ATA Device +++++ --- User --- [MBR] 926fe47886bc8d5f32abef94586bde5d [BSP] 4eb6286e8240657cba3a325c7d167a91 : Windows Vista/7/8 MBR Code Partition table: 0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 610478 MB User = LL1 ... OK User = LL2 ... OK +++++ PhysicalDrive3: KINGSTON SH103S3120G ATA Device +++++ --- User --- [MBR] 598f2384d0f8d50b4db811adaf572f40 [BSP] d6d0032e6c2e59bdee703b50d23b3c7c : Windows Vista/7/8 MBR Code Partition table: 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB 1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 114371 MB User = LL1 ... OK User = LL2 ... OK ============================================ RKreport_DEL_08072014_015328.log - RKreport_DEL_08072014_015600.log - RKreport_DEL_08072014_015957.log - RKreport_SCN_08072014_015259.log RKreport_SCN_08072014_015431.log - RKreport_SCN_08072014_015945.log