Author Topic: Rogue Killer Report, What to do now  (Read 7915 times)

0 Members and 3 Guests are viewing this topic.

May 23, 2014, 06:10:06 AM

Searide17

  • Guest
Rogue Killer Report, What to do now
« on: May 23, 2014, 06:10:06 AM »
My computer has been insisting that my homepage on Firefox be set to startsear.info instead of google like i would prefer. I my attempt to correct this issue has lead me to Rogue Killer. Following is my scan report, can anyone tell me what the next step(s) is to fixing this?

RogueKiller V8.8.15 _x64_ [Mar 27 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Sean [Admin rights]
Mode : Scan -- Date : 05/22/2014 22:59:04
| ARK || FAK || MBR |

¤¤¤ Bad processes : 2 ¤¤¤
[SUSP PATH] play.exe -- C:\Users\Sean\AppData\Roaming\play.exe [-] -> KILLED [TermProc]
[SUSP PATH] Sean.exe -- C:\Users\Sean\AppData\Roaming\THEBEAST-HP\Sean.exe [-] -> KILLED [TermProc]

¤¤¤ Registry Entries : 4 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : THEBEAST-HP (C:\Users\Sean\AppData\Roaming\play.exe [-]) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-618405602-1203449950-2020951064-1000\[...]\Run : THEBEAST-HP (C:\Users\Sean\AppData\Roaming\play.exe [-]) -> FOUND
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤
[Address] EAT @explorer.exe (DllCanUnloadNow) : thumbcache.dll -> HOOKED (C:\Windows\System32\AltTab.dll @ 0xEFBC20D8)
[Address] EAT @explorer.exe (DllGetClassObject) : thumbcache.dll -> HOOKED (C:\Windows\System32\AltTab.dll @ 0xEFBC20EC)

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection :  ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) Hitachi HTS547575A9E384 +++++
--- User ---
[MBR] 6e6593f4b48efee5b2dfa280405be7fe
[BSP] 49d0ba0b24236561241ecfdd602e3c7d : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 MB
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 689528 MB
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1412562944 | Size: 21613 MB
3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 1456826368 | Size: 4062 MB
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ USB) Seagate FreeAgent GoFlex USB Device +++++
--- User ---
[MBR] e843e4fcf69a0831b79f979bc5d0f63a
[BSP] 27c2fff8e4cb246929a22d993c20a83b : MBR Code unknown
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1936269394 | Size: 896492 MB
1 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1917848077 | Size: 265838 MB
2 - [XXXXXX] SYLSTOR (0x2b) [VISIBLE] Offset (sectors): 1818575915 | Size: 265710 MB
3 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): -1450442742 | Size: 26 MB
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )

Finished : << RKreport[0]_S_05222014_225904.txt >>





Reply #1May 23, 2014, 11:43:56 AM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Rogue Killer Report, What to do now
« Reply #1 on: May 23, 2014, 11:43:56 AM »
Hello
I'd suggest to scan with AdwCleaner, because you have a resident in your browser

Reply #2May 23, 2014, 09:33:32 PM

Searide17

  • Guest
Re: Rogue Killer Report, What to do now
« Reply #2 on: May 23, 2014, 09:33:32 PM »
# AdwCleaner v3.210 - Report created 23/05/2014 at 14:30:40
# Updated 19/05/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Sean - THEBEAST-HP
# Running from : C:\Program Files (x86)\Rogue Killer\adwcleaner_3.210.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v0.0.0.0

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://startsear.info

-\\ Mozilla Firefox v14.0.1 (en-US)

[ File : C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\gfcwi93j.default\prefs.js ]

Line Found : user_pref("browser.startup.homepage", "hxxp://startsear.info");

-\\ Google Chrome v

[ File : C:\Users\Sean\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Found [Search Provider] : hxxp://www.google.com/cse?cx=partner-pub-0236192664760821%3A4680426847&ie=UTF-8&q={searchTerms}&sa=Search&siteurl=startsear.info%2F

*************************

AdwCleaner[R0].txt - [5297 octets] - [23/05/2014 11:12:41]
AdwCleaner[R1].txt - [1156 octets] - [23/05/2014 14:30:41]
AdwCleaner[S0].txt - [5344 octets] - [23/05/2014 11:13:58]

########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [1276 octets] ##########

Reply #3May 24, 2014, 08:57:53 AM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Rogue Killer Report, What to do now
« Reply #3 on: May 24, 2014, 08:57:53 AM »
Yes, now Delete :)

Reply #4May 24, 2014, 07:08:59 PM

Searide17

  • Guest
Re: Rogue Killer Report, What to do now
« Reply #4 on: May 24, 2014, 07:08:59 PM »
That didnt fix it. My browser is still setting my homepage at Startsear.

Reply #5May 26, 2014, 05:23:04 AM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Rogue Killer Report, What to do now
« Reply #5 on: May 26, 2014, 05:23:04 AM »
Which browser do you use?