0 Members and 1 Guest are viewing this topic.
RogueKiller V9.2.4.0 (x64) [Jul 11 2014] by Adlice Softwaremail : http://www.adlice.com/contact/Feedback : http://forum.adlice.comWebsite : http://www.adlice.com/softwares/roguekiller/Blog : http://www.adlice.comOperating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits versionStarted in : Normal modeUser : Norikoul [Admin rights]Mode : Remove -- Date : 07/25/2014 14:37:32¤¤¤ Bad processes : 0 ¤¤¤¤¤¤ Registry Entries : 27 ¤¤¤[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3252924142-313350365-2090274538-1002\Software\Microsoft\Windows\CurrentVersion\Run | GenieoUpdaterService : "C:\Users\Norikoul\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe" -wait 5 -> DELETED[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3252924142-313350365-2090274538-1002\Software\Microsoft\Windows\CurrentVersion\Run | GenieoSystemTray : "C:\Users\Norikoul\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe" -> DELETED[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3252924142-313350365-2090274538-1002\Software\Microsoft\Windows\CurrentVersion\Run | MediaFire Tray : "C:\Users\Norikoul\AppData\Local\MediaFire Desktop\mf_watch.exe" --boot-start -> DELETED[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3252924142-313350365-2090274538-1002\Software\Microsoft\Windows\CurrentVersion\Run | GenieoUpdaterService : "C:\Users\Norikoul\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe" -wait 5 -> ERROR [2] [Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3252924142-313350365-2090274538-1002\Software\Microsoft\Windows\CurrentVersion\Run | GenieoSystemTray : "C:\Users\Norikoul\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe" -> ERROR [2][Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3252924142-313350365-2090274538-1002\Software\Microsoft\Windows\CurrentVersion\Run | MediaFire Tray : "C:\Users\Norikoul\AppData\Local\MediaFire Desktop\mf_watch.exe" --boot-start -> ERROR [2][Suspicious.Path] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del91458097 : cmd.exe /Q /D /c del "C:\Users\Norikoul\AppData\Local\Temp\0.del" -> DELETED[Suspicious.Path] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del92122365 : cmd.exe /Q /D /c del "C:\Users\Norikoul\AppData\Local\Temp\0.del" -> DELETED[Suspicious.Path] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce | DelTr4273818 : cmd.exe /c rd /s /q "C:\Users\Norikoul\AppData\Roaming\mysearchdial" -> DELETED[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3252924142-313350365-2090274538-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del91458097 : cmd.exe /Q /D /c del "C:\Users\Norikoul\AppData\Local\Temp\0.del" -> DELETED[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3252924142-313350365-2090274538-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del92122365 : cmd.exe /Q /D /c del "C:\Users\Norikoul\AppData\Local\Temp\0.del" -> DELETED[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3252924142-313350365-2090274538-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce | DelTr4273818 : cmd.exe /c rd /s /q "C:\Users\Norikoul\AppData\Roaming\mysearchdial" -> DELETED[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3252924142-313350365-2090274538-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del91458097 : cmd.exe /Q /D /c del "C:\Users\Norikoul\AppData\Local\Temp\0.del" -> ERROR [2][Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3252924142-313350365-2090274538-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del92122365 : cmd.exe /Q /D /c del "C:\Users\Norikoul\AppData\Local\Temp\0.del" -> ERROR [2][Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3252924142-313350365-2090274538-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce | DelTr4273818 : cmd.exe /c rd /s /q "C:\Users\Norikoul\AppData\Roaming\mysearchdial" -> ERROR [2][Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MF NTFS Monitor -> NOT SELECTED[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PCDSRVC{2368CD8C-B0B7C4E5-06020101}_0 -> NOT SELECTED[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MF NTFS Monitor -> NOT SELECTED[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCDSRVC{2368CD8C-B0B7C4E5-06020101}_0 -> NOT SELECTED[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MF NTFS Monitor -> NOT SELECTED[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PCDSRVC{2368CD8C-B0B7C4E5-06020101}_0 -> NOT SELECTED[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NOT SELECTED[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> NOT SELECTED[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NOT SELECTED[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NOT SELECTED[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NOT SELECTED[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NOT SELECTED¤¤¤ Scheduled tasks : 3 ¤¤¤[Suspicious.Path] Digital Sites.job -- C:\Users\Norikoul\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE (/Check) -> DELETED[Suspicious.Path] \\Digital Sites -- C:\Users\Norikoul\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE (/Check) -> DELETED[Suspicious.Path] \SaveDailyDeals\Updater\SaveDailyDeals updater -- C:\Windows\TEMP\1009.exe (/update /killb) -> DELETED¤¤¤ Files : 0 ¤¤¤¤¤¤ HOSTS File : 1 ¤¤¤[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost¤¤¤ Antirootkit : 2 (Driver: LOADED) ¤¤¤[Filter(Kernel.Filter)] \Driver\atapi @ \Device\Ide\IdeDeviceP1T0L0-1 : \Driver\UBHelper @ \Device\UBHelper0 (\SystemRoot\system32\DRIVERS\atikmdag.sys)[Filter(Kernel.Filter)] \Driver\atapi @ \Device\CdRom0 : \Driver\NTIDrvr @ \Device\NTIDrvr1 (\??\C:\Windows\system32\drivers\UBHelper.sys)¤¤¤ Web browsers : 0 ¤¤¤¤¤¤ MBR Check : ¤¤¤+++++ PhysicalDrive0: TOSHIBA MK2565GSX ATA Device +++++--- User ---[MBR] 07ab5bb391448b0fd248d2ae615d1b54[BSP] c0ed2e26908bcda25363a784cc81afcc : Windows Vista/7/8 MBR CodePartition table:0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 15360 MB1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 31459328 | Size: 100 MB2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 31664128 | Size: 223013 MBUser = LL1 ... OKUser = LL2 ... OK============================================RKreport_SCN_07252014_140727.log
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3252924142-313350365-2090274538-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del91458097 : cmd.exe /Q /D /c del "C:\Users\Norikoul\AppData\Local\Temp\0.del" -> DELETED[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3252924142-313350365-2090274538-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce | Del91458097 : cmd.exe /Q /D /c del "C:\Users\Norikoul\AppData\Local\Temp\0.del" -> ERROR [2]