Author Topic: Rogue killer results list really confusing / positive computer is clean  (Read 4783 times)

0 Members and 1 Guest are viewing this topic.

November 12, 2014, 05:28:04 PM

herbc

  • Guest
Hi everyone , Rogue killer flagged the below and i have no idea if any of these are dangerous , i would appreciate any assistance .


Kaspersky. Eset online scanner , Mbam scans always come up clean.
Thank you very much



RogueKiller V10.0.5.0 (x64) [Nov 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : charles [Administrator]
Mode : Scan -- Date : 11/12/2014  10:54:22

¤¤¤ Processes : 5 ¤¤¤
[Proc.Injected] mbam.exe -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7] -> Killed [TermProc]
[Proc.Injected] psi_tray.exe -- C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[7] -> Killed [TermProc]
[Proc.Injected] SonicFocusTray.exe -- C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[7] -> Killed [TermProc]
[Proc.Injected] LMS.exe --
  • -> Killed [TermProc]
[Proc.Injected] UNS.exe --
  • -> Killed [TermProc]


¤¤¤ Registry : 4 ¤¤¤
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Found
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Found

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 1 (Driver: Loaded) ¤¤¤
[Filter(Kernel.Filter)] \Driver\Disk @ \Device\Harddisk0\DR0 : \Driver\partmgr @ Unknown (\SystemRoot\system32\DRIVERS\cm_km_w.sys)

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: INTEL SSDSC2BW240A4 +++++
--- User ---
[MBR] e0834eb685b51832d3ad23d85f7afa26
[BSP] 463ecf2c1db817a6fedecb203f7fa0a8 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 228934 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_DEL_11032014_232515.log - RKreport_SCN_11032014_232310.log
« Last Edit: November 12, 2014, 05:40:06 PM by herbc »

Reply #1November 13, 2014, 08:12:00 AM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Rogue killer results list really confusing / positive computer is clean
« Reply #1 on: November 13, 2014, 08:12:00 AM »
Hello
There's something wrong here, will take a look.

Reply #2November 13, 2014, 08:38:40 AM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Rogue killer results list really confusing / positive computer is clean
« Reply #2 on: November 13, 2014, 08:38:40 AM »
Could you dump the process memory of a few of these (with process hacker/process explorer), and attach them here?
I couldn't reproduce with MBAM.

Reply #3November 13, 2014, 06:04:40 PM

herbc

  • Guest
Re: Rogue killer results list really confusing / positive computer is clean
« Reply #3 on: November 13, 2014, 06:04:40 PM »
Can you explain the steps in how to do that ?

Thank you very much

Reply #4November 13, 2014, 08:18:40 PM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Rogue killer results list really confusing / positive computer is clean
« Reply #4 on: November 13, 2014, 08:18:40 PM »
With Process Hacker, right click => dump