Author Topic: RK x64: Hidden processes, Registry Hits  (Read 5551 times)

0 Members and 1 Guest are viewing this topic.

July 14, 2014, 10:32:45 PM

derek123456789

  • Newbie

  • Offline
  • *

  • 5
  • Reputation:
    0
    • View Profile
RK x64: Hidden processes, Registry Hits
« on: July 14, 2014, 10:32:45 PM »
Hi - I have already cleaned these items once, but they came back.  I am running windows 8.1 w/ Malwarebytes Real-time protection and the Windows embedded malware protection program (used to be MSE, not sure what it is called now).

One thing to note, this is my laptop and I remote connect into my desktop with Windows 7....through the desktop, I have recently accessed the virtual drive to run Windows XP mode with a couple programs...not sure if this made me vulnerable...the remote connecting and XP Mode is temporary and possibly even done with


Very much appreciate your help/advice

RogueKiller V9.2.3.0 (x64) [Jul 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 8.1 (6.3.9200 ) 64 bits version
Started in : Normal mode
User : Derek [Admin rights]
Mode : Scan -- Date : 07/14/2014  16:27:52

¤¤¤ Bad processes : 2 ¤¤¤
[Proc.Hidden]  --
  • -> KILLED [TermThr]
[Proc.Hidden]  --
  • -> KILLED [TermThr]


¤¤¤ Registry Entries : 6 ¤¤¤
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SWUpdateService -> FOUND
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SWUpdateService -> FOUND
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-3345471694-2689826623-465696368-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0  -> FOUND
[PUM.Policies] (X64) HKEY_USERS\S-1-5-21-3345471694-2689826623-465696368-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0  -> FOUND
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-3345471694-2689826623-465696368-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0  -> FOUND
[PUM.Policies] (X86) HKEY_USERS\S-1-5-21-3345471694-2689826623-465696368-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0  -> FOUND

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ HOSTS File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: LOADED) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: HGST HTS541010A9E680 +++++
--- User ---
[MBR] ab09653465709269358ca86c4345e29e
[BSP] 7ee15af64f1544c7ab9f5888cf56cf4c : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 2097152 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_DEL_06302014_073846.log - RKreport_DEL_06302014_074303.log - RKreport_DEL_07032014_003308.log - RKreport_DEL_07042014_192104.log
RKreport_SCN_06302014_073823.log - RKreport_SCN_06302014_074210.log - RKreport_SCN_07032014_003016.log - RKreport_SCN_07042014_191752.log
« Last Edit: July 14, 2014, 10:34:47 PM by derek123456789 »

Reply #1July 18, 2014, 04:00:56 PM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 956
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: RK x64: Hidden processes, Registry Hits
« Reply #1 on: July 18, 2014, 04:00:56 PM »
Hello :)

this is a known issue: http://forum.adlice.com/index.php?topic=47