Author Topic: Can you please analyze my report?  (Read 5482 times)

0 Members and 1 Guest are viewing this topic.

July 14, 2014, 11:10:10 PM

nitrousable

  • Newbie

  • Offline
  • *

  • 38
  • Reputation:
    0
    • View Profile
Can you please analyze my report?
« on: July 14, 2014, 11:10:10 PM »
I just installed a new legit Windows and I get this in report and don't know what to think. If any of you knowing folks would describe it for me I'd greatly appreciate it




RogueKiller V9.2.3.0 (x64) [Jul 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 8.1 (6.3.9200 ) 64 bits version
Started in : Normal mode
User : Alex [Admin rights]
Mode : Scan -- Date : 07/14/2014  14:02:12

¤¤¤ Bad processes : 1 ¤¤¤
[Proc.Hidden]  --
  • -> KILLED [TermThr]


¤¤¤ Registry Entries : 0 ¤¤¤

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ HOSTS File : 0 ¤¤¤

¤¤¤ Antirootkit : 20 (Driver: LOADED) ¤¤¤
[EAT:Addr] (explorer.exe) framedynos.dll - DllCanUnloadNow : C:\Windows\System32\qmgrprxy.dll @ 0x7ff8ee148160
[EAT:Addr] (explorer.exe) framedynos.dll - DllGetClassObject : C:\Windows\System32\qmgrprxy.dll @ 0x7ff8ee148118
[EAT:Addr] (explorer.exe) framedynos.dll - DllRegisterServer : C:\Windows\System32\qmgrprxy.dll @ 0x7ff8ee1481b0
[EAT:Addr] (explorer.exe) framedynos.dll - DllUnregisterServer : C:\Windows\System32\qmgrprxy.dll @ 0x7ff8ee1481e4
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllCanUnloadNow : C:\Windows\SysWOW64\ieapfltr.dll @ 0x749d1845
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllGetClassObject : C:\Windows\SysWOW64\ieapfltr.dll @ 0x749c7390
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllRegisterServer : C:\Windows\SysWOW64\ieapfltr.dll @ 0x74a00fe0
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllUnregisterServer : C:\Windows\SysWOW64\ieapfltr.dll @ 0x74a01042
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllCanUnloadNow : C:\Windows\SysWOW64\ieapfltr.dll @ 0x749d1845
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllGetClassObject : C:\Windows\SysWOW64\ieapfltr.dll @ 0x749c7390
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllRegisterServer : C:\Windows\SysWOW64\ieapfltr.dll @ 0x74a00fe0
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllUnregisterServer : C:\Windows\SysWOW64\ieapfltr.dll @ 0x74a01042
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllCanUnloadNow : C:\Windows\SysWOW64\ieapfltr.dll @ 0x749d1845
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllGetClassObject : C:\Windows\SysWOW64\ieapfltr.dll @ 0x749c7390
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllRegisterServer : C:\Windows\SysWOW64\ieapfltr.dll @ 0x74a00fe0
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllUnregisterServer : C:\Windows\SysWOW64\ieapfltr.dll @ 0x74a01042
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllCanUnloadNow : C:\Windows\SysWOW64\ieapfltr.dll @ 0x749d1845
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllGetClassObject : C:\Windows\SysWOW64\ieapfltr.dll @ 0x749c7390
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllRegisterServer : C:\Windows\SysWOW64\ieapfltr.dll @ 0x74a00fe0
[EAT:Addr] (iexplore.exe) DPAPI.DLL - DllUnregisterServer : C:\Windows\SysWOW64\ieapfltr.dll @ 0x74a01042

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: SAMSUNG HD103SI +++++
--- User ---
[MBR] 6f31a3b4e2438f6f852eb4a71421b31a
[BSP] d2c032d2125283caa119df8964ce8bd7 : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1892796416 | Size: 29651 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 152899 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 313344000 | Size: 770867 MB
3 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 1892079616 | Size: 350 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: WDC WD2002FAEX-007BA0 +++++
--- User ---
[MBR] c94a3f644b9df44855dcce7dcdcd19f1
[BSP] 56eea2c0bc00d01469255301e21a3c32 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 1857727 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): -490340352 | Size: 49999 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_DEL_07142014_134723.log - RKreport_SCN_07142014_134635.log


Reply #1July 18, 2014, 04:01:54 PM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Can you please analyze my report?
« Reply #1 on: July 18, 2014, 04:01:54 PM »
Hello :)

Hidden processes is a known issue: http://forum.adlice.com/index.php?topic=47
Antirootkit entries are false positives, they will be whitelisted.