Hi all.
So scanning using the free version of RK on my main PC it finds
`Root.Wajam` Process {3560} svchost.exe, C:Windows\system32\svchost.exe
after the scan has finish RK does not remove it even tho i ask it to,it just says `not killed`.
so i attached the C drive to a laptop off line as an external drive and run the scan there but RK finds nothing,see results:
RogueKiller V12.12.17.0 (x64) [May 14 2018] (Free) by Adlice Software
mail :
http://www.adlice.com/contact/Feedback :
https://forum.adlice.comWebsite :
http://www.adlice.com/download/roguekiller/Blog :
http://www.adlice.comOperating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : mymymy [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 05/20/2018 10:54:26 (Duration : 00:23:40)
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 0 ¤¤¤
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: SAMSUNG SSD 830 Series +++++
--- User ---
[MBR] 20cc2867d6ad27fc1bbcd6a6f3071511
[BSP] e2026deed788ef6974619d346073f586 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 219776 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: Samsung SSD 840 PRO Seri USB Device +++++
--- User ---
[MBR] 9128758dae42cc7f521c0a393b9de029
[BSP] 64d01f4eb4d3707fccac81bf32decce3 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 219676 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
Error reading LL2 MBR! ([32] The request is not supported. )
i was a bit concerned about this:
Error reading LL2 MBR! ([32] The request is not supported. )
so i put the drive back into my main pc and started it up,i ran RK again and it finds Wajam again straight away.
no other tools are finding this Wajam
thanks in advance for any help peope.
burneyboty