1
RogueKiller / Re: ===> False Positives <===
« on: January 13, 2016, 04:07:37 PM »
Are these IAT hook detections false positives? Thanks.
RogueKiller V11.0.7.0 (x64) [Jan 11 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Doug [Administrator]
Started from : C:\Users\Doug\Desktop\Security\RogueKillerX64.exe
Mode : Scan -- Date : 01/13/2016 10:03:19
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 18 ¤¤¤
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyComputer : 2 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowControlPanel : 2 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyDocs : 2 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyMusic : 2 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowUser : 2 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyPics : 2 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 2 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowVideos : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyComputer : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowControlPanel : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyDocs : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyMusic : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowUser : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyPics : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowVideos : 2 -> Found
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 3 (Driver: Loaded) ¤¤¤
[IAT:Inl(Hook.IEAT)] (explorer.exe @ kernel32.dll) ntdll!NtProtectVirtualMemory : Unknown @ 0x77b90040 (jmp 0xfffffffffffa2190)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ kernel32.dll) ntdll!NtFreeVirtualMemory : Unknown @ 0x77b90028 (jmp 0xfffffffffffa2498)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ kernel32.dll) ntdll!NtAllocateVirtualMemory : Unknown @ 0x77b90010 (jmp 0xfffffffffffa24e0)
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD5002AALX-00J37A0 ATA Device +++++
--- User ---
[MBR] 9debdbc5daad6cceb51027dde86ff823
[BSP] 79bcbb79a1dc3c4533ed9e69a5766432 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 476838 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
RogueKiller V11.0.7.0 (x64) [Jan 11 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Doug [Administrator]
Started from : C:\Users\Doug\Desktop\Security\RogueKillerX64.exe
Mode : Scan -- Date : 01/13/2016 10:03:19
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 18 ¤¤¤
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyComputer : 2 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowControlPanel : 2 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyDocs : 2 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyMusic : 2 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowUser : 2 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyPics : 2 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 2 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowVideos : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyComputer : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowControlPanel : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyDocs : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyMusic : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowUser : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyPics : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 2 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3423139568-2959105372-4068864383-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowVideos : 2 -> Found
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 3 (Driver: Loaded) ¤¤¤
[IAT:Inl(Hook.IEAT)] (explorer.exe @ kernel32.dll) ntdll!NtProtectVirtualMemory : Unknown @ 0x77b90040 (jmp 0xfffffffffffa2190)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ kernel32.dll) ntdll!NtFreeVirtualMemory : Unknown @ 0x77b90028 (jmp 0xfffffffffffa2498)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ kernel32.dll) ntdll!NtAllocateVirtualMemory : Unknown @ 0x77b90010 (jmp 0xfffffffffffa24e0)
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD5002AALX-00J37A0 ATA Device +++++
--- User ---
[MBR] 9debdbc5daad6cceb51027dde86ff823
[BSP] 79bcbb79a1dc3c4533ed9e69a5766432 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 476838 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK