Adlice forum
Software feedback => RogueKiller => Topic started by: Medli on May 18, 2015, 11:40:44 PM
-
Hello, very sorry if this is the wrong forum location! I've just been really stressed after not being able to remove 6 registries...they come up as "Hj.known.dll" and every time I try to remove them it comes up with "Error [5]", which I read online means "ERROR_ACCESS_DENIED"?...I'm on a windows 8.1, and have tried booting in safe mode, ran RogueKiller, and still the same exact error. If you need any more information, just ask, I appreciate ANY help!!! Thank you so much for your time!
I've also scanned my computer with MalwareBytes (But i don't think that deals with any registries), and it came up with nothing.
-
Hi Medli,
Welcome to Adlice.com Forum.
Could you please copy/paste RogueKiller's full report in your next reply ?
Regards.
-
Sure, thanks for the help. Here it is:
RogueKiller V10.6.4.0 [May 18 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 8.1 (6.3.9200 ) 64 bits version
Started in : Normal mode
User : Medli [Administrator]
Started from : C:\Users\abyss_000\Desktop\RogueKiller.exe
Mode : Delete -- Date : 05/19/2015 07:35:11
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 12 ¤¤¤
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.1 [(Private Address) (XX)] -> Replaced ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.1 [(Private Address) (XX)] -> Replaced ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2C6BB16A-D347-435C-963F-83919036E32A} | DhcpNameServer : 10.0.0.1 [(Private Address) (XX)] -> Replaced ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3655FE8B-7A91-4041-AA18-A00A3ADF3A46} | DhcpNameServer : 10.0.0.1 [(Private Address) (XX)] -> Replaced ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{2C6BB16A-D347-435C-963F-83919036E32A} | DhcpNameServer : 10.0.0.1 [(Private Address) (XX)] -> Replaced ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{3655FE8B-7A91-4041-AA18-A00A3ADF3A46} | DhcpNameServer : 10.0.0.1 [(Private Address) (XX)] -> Replaced ()
[Hj.KnownDLL] (X64) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs | _Wow64cpu : Wow64cpu.dll -> ERROR [5]
[Hj.KnownDLL] (X64) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs | _Wow64win : Wow64win.dll -> ERROR [5]
[Hj.KnownDLL] (X64) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs | _Wow64 : Wow64.dll -> ERROR [5]
[Hj.KnownDLL] (X86) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs | _Wow64cpu : Wow64cpu.dll -> ERROR [5]
[Hj.KnownDLL] (X86) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs | _Wow64win : Wow64win.dll -> ERROR [5]
[Hj.KnownDLL] (X86) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs | _Wow64 : Wow64.dll -> ERROR [5]
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Not loaded [0x20]) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD10EZEX-08M2NA0 +++++
--- User ---
[MBR] 6f27a42f0838e2ffbfb899736caffad3
[BSP] 3076f8477a3b57dd4a72f5833b8f6f91 : Empty MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 2048 | Size: 1000 MB
1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2050048 | Size: 260 MB
2 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 2582528 | Size: 500 MB
3 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 3606528 | Size: 128 MB
4 - Basic data partition | Offset (sectors): 3868672 | Size: 926980 MB
5 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 1902323712 | Size: 25000 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_SCN_10142014_010746.log - RKreport_DEL_10142014_010751.log - RKreport_DEL_10142014_010756.log - RKreport_SCN_10142014_012130.log
RKreport_SCN_11302014_122324.log - RKreport_DEL_11302014_122407.log - RKreport_SCN_11302014_122535.log - RKreport_DEL_11302014_122643.log
RKreport_SCN_11302014_122945.log - RKreport_SCN_12032014_201731.log - RKreport_SCN_12112014_210821.log - RKreport_SCN_01142015_095301.log
RKreport_SCN_02012015_005003.log - RKreport_SCN_02202015_170721.log - RKreport_SCN_05182015_164314.log - RKreport_DEL_05182015_164402.log
RKreport_SCN_05182015_164940.log - RKreport_DEL_05182015_165523.log - RKreport_SCN_05182015_170257.log - RKreport_DEL_05182015_170300.log
RKreport_SCN_05182015_172015.log - RKreport_DEL_05182015_172018.log - RKreport_SCN_05182015_172757.log - RKreport_DEL_05182015_173209.log
RKreport_SCN_05182015_173850.log - RKreport_DEL_05182015_173907.log - RKreport_SCN_05182015_181920.log - RKreport_SCN_05182015_184303.log
RKreport_DEL_05182015_184336.log - RKreport_SCN_05182015_184505.log - RKreport_DEL_05182015_184507.log - RKreport_DEL_05182015_184513.log
RKreport_DEL_05182015_184516.log - RKreport_DEL_05182015_195905.log - RKreport_SCN_05192015_073438.log
-
Hi Medli,
Your report is clean.
Thoses detections are known false positives. This will be fixed in RogueKiller's next release.
Regards.