Hi, here is RKreport.txt
RogueKiller V7.4.3 [05/04/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
http://www.geekstogo...13-roguekiller/
Blog:
http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: owner [Admin rights]
Mode: Scan -- Date: 05/04/2012 16:50:26
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 13 ¤¤¤
[BLACKLIST DLL] HKUS\S-1-5-19[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> FOUND
[BLACKLIST DLL] HKUS\S-1-5-19_Classes[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> FOUND
[BLACKLIST DLL] HKUS\S-1-5-20[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> FOUND
[BLACKLIST DLL] HKUS\S-1-5-20_Classes[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> FOUND
[BLACKLIST DLL] HKUS\S-1-5-21-1229272821-823518204-1177238915-1003_Classes[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowUser (0) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowMyPics (0) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowMyMusic (0) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowSetProgramAccessAndDefaults (0) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : Root.MBR ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
94.63.147.16 www.google.com
94.63.147.17 www.bing.com
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: WDC WD6400AACS-00D6B1 +++++
--- User ---
[MBR] f675b690aea3e8a9396c12ac68fa5243
[BSP] b7cb42b22dc882131a6a6f85b63be1e5 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 610477 Mo
User = LL1 ... OK!
User != LL2 ... KO!
--- LL2 ---
[MBR] edf33485b046a262948988e834209fc8
[BSP] b7cb42b22dc882131a6a6f85b63be1e5 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 610477 Mo
1 - [ACTIVE] NTFS (0x17) [HIDDEN!] Offset (sectors): 1250258625 | Size: 2 Mo
Finished : << RKreport[1].txt >>
RKreport[1].txt
RogueKiller V7.4.3 [05/04/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
http://www.geekstogo...13-roguekiller/
Blog:
http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: owner [Admin rights]
Mode: Remove -- Date: 05/04/2012 16:56:45
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 13 ¤¤¤
[BLACKLIST DLL] HKUS\S-1-5-19[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-19_Classes[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-20[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-20_Classes[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-21-1229272821-823518204-1177238915-1003_Classes[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[HJ] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowUser (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyPics (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyMusic (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowSetProgramAccessAndDefaults (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : Root.MBR ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
94.63.147.16 www.google.com
94.63.147.17 www.bing.com
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: WDC WD6400AACS-00D6B1 +++++
--- User ---
[MBR] f675b690aea3e8a9396c12ac68fa5243
[BSP] b7cb42b22dc882131a6a6f85b63be1e5 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 610477 Mo
User = LL1 ... OK!
User != LL2 ... KO!
--- LL2 ---
[MBR] edf33485b046a262948988e834209fc8
[BSP] b7cb42b22dc882131a6a6f85b63be1e5 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 610477 Mo
1 - [ACTIVE] NTFS (0x17) [HIDDEN!] Offset (sectors): 1250258625 | Size: 2 Mo
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
RogueKiller V7.4.3 [05/04/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
http://www.geekstogo...13-roguekiller/
Blog:
http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: owner [Admin rights]
Mode: Remove -- Date: 05/04/2012 16:56:45
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 13 ¤¤¤
[BLACKLIST DLL] HKUS\S-1-5-19[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-19_Classes[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-20[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-20_Classes[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-21-1229272821-823518204-1177238915-1003_Classes[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[HJ] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowUser (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyPics (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyMusic (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowSetProgramAccessAndDefaults (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : Root.MBR ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
94.63.147.16 www.google.com
94.63.147.17 www.bing.com
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: WDC WD6400AACS-00D6B1 +++++
--- User ---
[MBR] f675b690aea3e8a9396c12ac68fa5243
[BSP] b7cb42b22dc882131a6a6f85b63be1e5 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 610477 Mo
User = LL1 ... OK!
User != LL2 ... KO!
--- LL2 ---
[MBR] edf33485b046a262948988e834209fc8
[BSP] b7cb42b22dc882131a6a6f85b63be1e5 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 610477 Mo
1 - [ACTIVE] NTFS (0x17) [HIDDEN!] Offset (sectors): 1250258625 | Size: 2 Mo
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
RogueKiller V7.4.3 [05/04/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
http://www.geekstogo...13-roguekiller/
Blog:
http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: owner [Admin rights]
Mode: Remove -- Date: 05/04/2012 16:56:45
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 13 ¤¤¤
[BLACKLIST DLL] HKUS\S-1-5-19[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-19_Classes[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-20[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-20_Classes[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-21-1229272821-823518204-1177238915-1003_Classes[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[HJ] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowUser (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyPics (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyMusic (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowSetProgramAccessAndDefaults (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : Root.MBR ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
94.63.147.16 www.google.com
94.63.147.17 www.bing.com
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: WDC WD6400AACS-00D6B1 +++++
--- User ---
[MBR] f675b690aea3e8a9396c12ac68fa5243
[BSP] b7cb42b22dc882131a6a6f85b63be1e5 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 610477 Mo
User = LL1 ... OK!
User != LL2 ... KO!
--- LL2 ---
[MBR] edf33485b046a262948988e834209fc8
[BSP] b7cb42b22dc882131a6a6f85b63be1e5 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 610477 Mo
1 - [ACTIVE] NTFS (0x17) [HIDDEN!] Offset (sectors): 1250258625 | Size: 2 Mo
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
RogueKiller V7.4.3 [05/04/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
http://www.geekstogo...13-roguekiller/
Blog:
http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: owner [Admin rights]
Mode: Remove -- Date: 05/04/2012 16:56:45
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 13 ¤¤¤
[BLACKLIST DLL] HKUS\S-1-5-19[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-19_Classes[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-20[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-20_Classes[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[BLACKLIST DLL] HKUS\S-1-5-21-1229272821-823518204-1177238915-1003_Classes[...]\Run : Update (rundll32.exe "C:\Documents and Settings\owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware.com\wmgaaaizl.dll",DllRegisterServer) -> DELETED
[HJ] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowUser (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyPics (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyMusic (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowSetProgramAccessAndDefaults (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : Root.MBR ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
94.63.147.16 www.google.com
94.63.147.17 www.bing.com
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: WDC WD6400AACS-00D6B1 +++++
--- User ---
[MBR] f675b690aea3e8a9396c12ac68fa5243
[BSP] b7cb42b22dc882131a6a6f85b63be1e5 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 610477 Mo
User = LL1 ... OK!
User != LL2 ... KO!
--- LL2 ---
[MBR] edf33485b046a262948988e834209fc8
[BSP] b7cb42b22dc882131a6a6f85b63be1e5 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 610477 Mo
1 - [ACTIVE] NTFS (0x17) [HIDDEN!] Offset (sectors): 1250258625 | Size: 2 Mo
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
There is a Quarantine File and a RK(2).txt (it appears to be the same as the above though)