RogueKiller V7.6.5 [08/03/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
http://www.geekstogo...13-roguekiller/
Blog:
http://tigzyrk.blogspot.com
Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: owner [Admin rights]
Mode: Remove -- Date: 08/03/2012 23:48:38
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 4 ¤¤¤
[HJ] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowSetProgramAccessAndDefaults (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
SSDT[13] : NtAlertResumeThread @ 0x8289B5C3 -> HOOKED (Unknown @ 0x91F37A80)
SSDT[14] : NtAlertThread @ 0x82814255 -> HOOKED (Unknown @ 0x91F37B60)
SSDT[18] : NtAllocateVirtualMemory @ 0x828504FB -> HOOKED (Unknown @ 0x971F03F8)
SSDT[21] : NtAlpcConnectPort @ 0x827F2887 -> HOOKED (Unknown @ 0x87D3CF70)
SSDT[42] : NtAssignProcessToJobObject @ 0x827C5B43 -> HOOKED (Unknown @ 0x91F0BCC8)
SSDT[67] : NtCreateMutant @ 0x82828812 -> HOOKED (Unknown @ 0x91F142B0)
SSDT[77] : NtCreateSymbolicLinkObject @ 0x827C835A -> HOOKED (Unknown @ 0x91F0CE60)
SSDT[78] : NtCreateThread @ 0x82899BE0 -> HOOKED (Unknown @ 0x91F07180)
SSDT[116] : NtDebugActiveProcess @ 0x8286CD22 -> HOOKED (Unknown @ 0x91F0BDA8)
SSDT[129] : NtDuplicateObject @ 0x82800551 -> HOOKED (Unknown @ 0x91FD5C58)
SSDT[147] : NtFreeVirtualMemory @ 0x8268CF1D -> HOOKED (Unknown @ 0x971F0218)
SSDT[156] : NtImpersonateAnonymousToken @ 0x827C2F12 -> HOOKED (Unknown @ 0x91F143A0)
SSDT[158] : NtImpersonateThread @ 0x827D854F -> HOOKED (Unknown @ 0x91F14008)
SSDT[165] : NtLoadDriver @ 0x82773DEE -> HOOKED (Unknown @ 0x87D3CEF8)
SSDT[177] : NtMapViewOfSection @ 0x8281889A -> HOOKED (Unknown @ 0x971F0118)
SSDT[184] : NtOpenEvent @ 0x82801DCF -> HOOKED (Unknown @ 0x91F141D0)
SSDT[194] : NtOpenProcess @ 0x82828FAE -> HOOKED (Unknown @ 0x91F07068)
SSDT[195] : NtOpenProcessToken @ 0x82809A2E -> HOOKED (Unknown @ 0x91FD5B98)
SSDT[197] : NtOpenSection @ 0x8281966D -> HOOKED (Unknown @ 0x91F0BFD0)
SSDT[201] : NtOpenThread @ 0x828244FF -> HOOKED (Unknown @ 0x91FD5D28)
SSDT[210] : NtProtectVirtualMemory @ 0x828222E2 -> HOOKED (Unknown @ 0x91F0BBD8)
SSDT[282] : NtResumeThread @ 0x82823B4A -> HOOKED (Unknown @ 0x91F37C40)
SSDT[289] : NtSetContextThread @ 0x8289B06F -> HOOKED (Unknown @ 0x91FD4C40)
SSDT[305] : NtSetInformationProcess @ 0x8281C8C8 -> HOOKED (Unknown @ 0x91FD4D20)
SSDT[317] : NtSetSystemInformation @ 0x827EEEEB -> HOOKED (Unknown @ 0x91F0BE88)
SSDT[330] : NtSuspendProcess @ 0x8289B4FF -> HOOKED (Unknown @ 0x91F140F0)
SSDT[331] : NtSuspendThread @ 0x827A292B -> HOOKED (Unknown @ 0x91F37D20)
SSDT[334] : NtTerminateProcess @ 0x827F9143 -> HOOKED (Unknown @ 0x91F07260)
SSDT[335] : NtTerminateThread @ 0x82824534 -> HOOKED (Unknown @ 0x91FD4B60)
SSDT[348] : NtUnmapViewOfSection @ 0x82818B5D -> HOOKED (Unknown @ 0x91FD4E10)
SSDT[358] : NtWriteVirtualMemory @ 0x8281592D -> HOOKED (Unknown @ 0x971F0308)
SSDT[382] : NtCreateThreadEx @ 0x82823FE9 -> HOOKED (Unknown @ 0x91F0CF50)
S_SSDT[317] : Unknown -> HOOKED (Unknown @ 0x972A28C8)
S_SSDT[397] : Unknown -> HOOKED (Unknown @ 0x971DF1A0)
S_SSDT[428] : Unknown -> HOOKED (Unknown @ 0x971DF0E0)
S_SSDT[430] : Unknown -> HOOKED (Unknown @ 0x86F125C0)
S_SSDT[442] : Unknown -> HOOKED (Unknown @ 0x971DF2E8)
S_SSDT[479] : Unknown -> HOOKED (Unknown @ 0x9732F378)
S_SSDT[497] : Unknown -> HOOKED (Unknown @ 0x9732F008)
S_SSDT[498] : Unknown -> HOOKED (Unknown @ 0x9732F448)
S_SSDT[573] : Unknown -> HOOKED (Unknown @ 0x86F143C8)
S_SSDT[576] : Unknown -> HOOKED (Unknown @ 0x86F0EAA0)
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
::1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: FUJITSU MHX2250BT ATA Device +++++
--- User ---
[MBR] 5fda213a8146ffd7df142aa50ce8c7a4
[BSP] 2c60e3e08a4fa002faabe1a5a0bd19e2 : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 3074048 | Size: 236974 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt