1
RogueKiller / Report Analysis
« on: May 19, 2015, 07:37:01 PM »
Hey guys,
is there anything to worry about? Thanks in advance.
RogueKiller V10.6.4.0 [May 18 2015] by Adlice Software
Mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Betriebssystem : Windows 8.1 (6.3.9200 ) 32 bits version
gestarted in : normaler Modus
User : Lena [Administrator]
Started from : C:\Users\Lena\Downloads\RogueKiller.exe
Modus : Scannen -- Datum : 05/19/2015 19:25:15
¤¤¤ Prozesse : 2 ¤¤¤
[Suspicious.Path] AsPatchTouchPanel.exe(3204) -- C:\ProgramData\AsTouchPanel\AsPatchTouchPanel.exe[7] -> beendet [TermProc]
[Suspicious.Path] (SVC) MpKsld538d331 -- \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BB02760A-6448-4CCC-AE2F-9DC6E9404761}\MpKsld538d331.sys[7] -> gestoppt
¤¤¤ Registry : 7 ¤¤¤
[PUM.Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED} -> Gefunden
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MpKsld538d331 (\??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BB02760A-6448-4CCC-AE2F-9DC6E9404761}\MpKsld538d331.sys) -> Gefunden
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MpKsld538d331 (\??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BB02760A-6448-4CCC-AE2F-9DC6E9404761}\MpKsld538d331.sys) -> Gefunden
[PUM.HomePage] HKEY_USERS\S-1-5-21-358101494-2269781373-366943959-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://asus13.msn.com/?pc=ASJB -> Gefunden
[PUM.HomePage] HKEY_USERS\S-1-5-21-358101494-2269781373-366943959-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://asus13.msn.com/?pc=ASJB -> Gefunden
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Gefunden
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Gefunden
¤¤¤ Aufgaben : 2 ¤¤¤
[Suspicious.Path] \\ASUS Patch for Touch Panel -- C:\ProgramData\AsTouchPanel\AsPatchTouchPanel.exe -> Gefunden
[Suspicious.Path] \\Microsoft OneDrive Auto Update Task-S-1-5-21-358101494-2269781373-366943959-1001 -- %localappdata%\Microsoft\OneDrive\OneDrive.exe -> Gefunden
¤¤¤ Dateien : 0 ¤¤¤
¤¤¤ Host Dateien : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: geladen) ¤¤¤
¤¤¤ Web Browser : 0 ¤¤¤
¤¤¤ MBR Überprüfung : ¤¤¤
+++++ PhysicalDrive0: Hynix HCG8e +++++
--- User ---
[MBR] a53a99ff10e89e318dba618a92e10326
[BSP] cd43bed3045d3d75140c1581037ca242 : Empty MBR Code
Partition table:
0 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2048 | Size: 100 MB
1 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 206848 | Size: 128 MB
2 - Basic data partition | Offset (sectors): 468992 | Size: 51226 MB
3 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 105379840 | Size: 8192 MB
User = LL1 ... OK
Error reading LL2 MBR! ([1] Unzulässige Funktion. )
+++++ PhysicalDrive1: HGST HTS 725050A7E630 USB Device +++++
--- User ---
[MBR] 94cb296f3acf6442b22d004a180be7b3
[BSP] 4485e7032d80ad6d543d76a201934f64 : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 476937 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
Error reading LL2 MBR! ([32] Die Anforderung wird nicht unterstützt. )
is there anything to worry about? Thanks in advance.
RogueKiller V10.6.4.0 [May 18 2015] by Adlice Software
Mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Betriebssystem : Windows 8.1 (6.3.9200 ) 32 bits version
gestarted in : normaler Modus
User : Lena [Administrator]
Started from : C:\Users\Lena\Downloads\RogueKiller.exe
Modus : Scannen -- Datum : 05/19/2015 19:25:15
¤¤¤ Prozesse : 2 ¤¤¤
[Suspicious.Path] AsPatchTouchPanel.exe(3204) -- C:\ProgramData\AsTouchPanel\AsPatchTouchPanel.exe[7] -> beendet [TermProc]
[Suspicious.Path] (SVC) MpKsld538d331 -- \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BB02760A-6448-4CCC-AE2F-9DC6E9404761}\MpKsld538d331.sys[7] -> gestoppt
¤¤¤ Registry : 7 ¤¤¤
[PUM.Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED} -> Gefunden
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MpKsld538d331 (\??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BB02760A-6448-4CCC-AE2F-9DC6E9404761}\MpKsld538d331.sys) -> Gefunden
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MpKsld538d331 (\??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BB02760A-6448-4CCC-AE2F-9DC6E9404761}\MpKsld538d331.sys) -> Gefunden
[PUM.HomePage] HKEY_USERS\S-1-5-21-358101494-2269781373-366943959-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://asus13.msn.com/?pc=ASJB -> Gefunden
[PUM.HomePage] HKEY_USERS\S-1-5-21-358101494-2269781373-366943959-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://asus13.msn.com/?pc=ASJB -> Gefunden
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Gefunden
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Gefunden
¤¤¤ Aufgaben : 2 ¤¤¤
[Suspicious.Path] \\ASUS Patch for Touch Panel -- C:\ProgramData\AsTouchPanel\AsPatchTouchPanel.exe -> Gefunden
[Suspicious.Path] \\Microsoft OneDrive Auto Update Task-S-1-5-21-358101494-2269781373-366943959-1001 -- %localappdata%\Microsoft\OneDrive\OneDrive.exe -> Gefunden
¤¤¤ Dateien : 0 ¤¤¤
¤¤¤ Host Dateien : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: geladen) ¤¤¤
¤¤¤ Web Browser : 0 ¤¤¤
¤¤¤ MBR Überprüfung : ¤¤¤
+++++ PhysicalDrive0: Hynix HCG8e +++++
--- User ---
[MBR] a53a99ff10e89e318dba618a92e10326
[BSP] cd43bed3045d3d75140c1581037ca242 : Empty MBR Code
Partition table:
0 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2048 | Size: 100 MB
1 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 206848 | Size: 128 MB
2 - Basic data partition | Offset (sectors): 468992 | Size: 51226 MB
3 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 105379840 | Size: 8192 MB
User = LL1 ... OK
Error reading LL2 MBR! ([1] Unzulässige Funktion. )
+++++ PhysicalDrive1: HGST HTS 725050A7E630 USB Device +++++
--- User ---
[MBR] 94cb296f3acf6442b22d004a180be7b3
[BSP] 4485e7032d80ad6d543d76a201934f64 : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 476937 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
Error reading LL2 MBR! ([32] Die Anforderung wird nicht unterstützt. )