OK re-imaged my computer and re-run RogueKiller here the outcome below:
RogueKiller V9.2.4.0 [Jul 11 2014] by Adlice Software
mail :
http://www.adlice.com/contact/Feedback :
http://forum.adlice.comWebsite :
http://www.adlice.com/softwares/roguekiller/Blog :
http://www.adlice.comOperating System : Windows 8.1 (6.3.9200 ) 32 bits version
Started in : Normal mode
User : asoul_000 [Admin rights]
Mode : Scan -- Date : 07/26/2014 17:12:07
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 10 ¤¤¤
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters |
DhcpNameServer : 61.9.195.193 61.9.194.49 -> FOUND
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer :
61.9.195.193 61.9.194.49 -> FOUND
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces
\{3E1869CF-1651-4DF2-B7B6-5632E71C2731} | DhcpNameServer : 61.9.195.193 61.9.194.49 -> FOUND
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces
\{4D73C91C-0D46-4856-9857-F1A7C08DDAEA} | DhcpNameServer : 61.9.195.193 61.9.194.49 -> FOUND
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces
\{3E1869CF-1651-4DF2-B7B6-5632E71C2731} | DhcpNameServer : 61.9.195.193 61.9.194.49 -> FOUND
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces
\{4D73C91C-0D46-4856-9857-F1A7C08DDAEA} | DhcpNameServer : 61.9.195.193 61.9.194.49 -> FOUND
[PUM.Policies] HKEY_USERS\S-1-5-21-183892547-3926755635-2953811617-1001\Software\Microsoft
\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> FOUND
[PUM.Policies] HKEY_USERS\S-1-5-21-183892547-3926755635-2953811617-1001\Software\Microsoft
\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0 -> FOUND
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer
\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> FOUND
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer
\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> FOUND
¤¤¤ Scheduled tasks : 1 ¤¤¤
[Suspicious.Path] \\SomotoUpdateCheckerAutoStart -- C:\Users\asoul_000\AppData\Local\FilesFrog
Update Checker\update_checker.exe (/auto) -> FOUND
¤¤¤ Files : 0 ¤¤¤
¤¤¤ HOSTS File : 0 ¤¤¤
¤¤¤ Antirootkit : 8 (Driver: LOADED) ¤¤¤
[IAT:Addr] (explorer.exe) dwmapi.dll - : Unknown @ 0xaff0000
[IAT:Addr] (explorer.exe) dwmapi.dll - : Unknown @ 0xaff0014
[IAT:Addr] (explorer.exe) dwmapi.dll - : Unknown @ 0xaff0028
[EAT:Addr] (explorer.exe) MSVCR80.dll - MappingDoAction : C:\Windows\system32\elscore.dll @
0x68337834
[EAT:Addr] (explorer.exe) MSVCR80.dll - MappingFreePropertyBag : C:\Windows
\system32\elscore.dll @ 0x68331230
[EAT:Addr] (explorer.exe) MSVCR80.dll - MappingFreeServices : C:\Windows\system32\elscore.dll
@ 0x68337908
[EAT:Addr] (explorer.exe) MSVCR80.dll - MappingGetServices : C:\Windows\system32\elscore.dll @
0x68332fa1
[EAT:Addr] (explorer.exe) MSVCR80.dll - MappingRecognizeText : C:\Windows\system32\elscore.dll
@ 0x683310d0
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: HGST HTS721010A9E630 +++++
--- User ---
[MBR] 968b68c9ed36a3c42cfbf4ccb6686a21
[BSP] 95710b1fd0045563c6af269b8702db8b : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 1092 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2238464 | Size: 749404 MB
2 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 1537017856 | Size: 203370 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive2: Multiple Card Reader USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )