Hi,
I'm new to RK and this forum, so I'm not sure if this is the place to ask question... sorry if it is not. I've read the tutorial and seen the FAQs page but there is no mention of RED color warnings. I don't know what to do....
I've run RogueKiller and the scan picked up some PUPs which I have deleted.
It also picked up 3 objects in the Antirootkit tab that are highlighted in RED. These appear to be bad. It looks like they are keyloggers. I don't know if they are important to remove - and how to remove them.
Can you help please?
I ran the scan process again, so the PUPs are not in the report now. here's the report
Thanks
Richard
RogueKiller V9.2.3.0 (x64) [Jul 11 2014] by Adlice Software
mail :
http://www.adlice.com/contact/Feedback :
http://forum.adlice.comWebsite :
http://www.adlice.com/softwares/roguekiller/Blog :
http://www.adlice.comOperating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : user [Admin rights]
Mode : Remove -- Date : 07/20/2014 10:56:56
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 0 ¤¤¤
¤¤¤ Scheduled tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ HOSTS File : 0 ¤¤¤
¤¤¤ Antirootkit : 3 (Driver: LOADED) ¤¤¤
[Filter(Root.Keylogger)] \Driver\kbdclass @ \Device\KeyboardClass3 : \Driver\SynTP @ \Device\0000009b (\SystemRoot\System32\drivers\dxgmms1.sys)
[Filter(Root.Keylogger)] \Driver\kbdclass @ \Device\KeyboardClass2 : \Driver\SynTP @ \Device\0000008c (\SystemRoot\System32\drivers\dxgmms1.sys)
[Filter(Root.Keylogger)] \Driver\kbdclass @ \Device\KeyboardClass0 : \Driver\SynTP @ \Device\0000008a (\SystemRoot\System32\drivers\dxgmms1.sys)
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ATA TOSHIBA MQ01ABD0 SCSI Disk Device +++++
--- User ---
[MBR] 239b791ed077fd1471a55625c40b17dd
[BSP] 9f5a57385805106117475533f18d9e31 : HP MBR Code
Partition table:
0 - [ACTIVE] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 3074048 | Size: 462765 MB
2 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 950816768 | Size: 12673 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: ATA TOSHIBA MK5075GS SCSI Disk Device +++++
--- User ---
[MBR] b511322079f9d2811392685783f2e20f
[BSP] 726112a5b743585243c98ba617487edd : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 476938 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_SCN_07202014_103048.log - RKreport_DEL_07202014_103918.log - RKreport_SCN_07202014_104914.log