Ok im running the new one on the problematic laptop now. Erlier i ran it on the desktop that had the same behavior and issues. It came back with the same ones as the laptop usually does but the MJ ones on the top are new. So this is the desktops log, the new log for the laptop that you asked for will be posted once its finished.
RogueKiller V11.0.10.0 (x64) [Feb 1 2016] (Free) by Adlice Software
mail :
http://www.adlice.com/contact/Feedback :
http://forum.adlice.comWebsite :
http://www.adlice.com/software/roguekiller/Blog :
http://www.adlice.com Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Gamer [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 02/08/2016 14:57:00
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 2 ¤¤¤
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-657907023-3029220830-3103070258-1000\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve -> Found
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-657907023-3029220830-3103070258-1000\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve -> Found
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 66 (Driver: Loaded) ¤¤¤
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_CREATE[0] : Unknown @ 0xfffffa80031362c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_CLOSE[2] : Unknown @ 0xfffffa80031362c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_DEVICE_CONTROL[14] : Unknown @ 0xfffffa80031362c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_INTERNAL_DEVICE_CONTROL[15] : Unknown @ 0xfffffa80031362c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_POWER[22] : Unknown @ 0xfffffa80031362c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_SYSTEM_CONTROL[23] : Unknown @ 0xfffffa80031362c0
[IRP:Addr(Hook.IRP)] \Driver\atapi - IRP_MJ_PNP[27] : Unknown @ 0xfffffa80031362c0
[IAT:Inl(Hook.IEAT)] (explorer.exe @ kernel32.dll) ntdll!NtTerminateProcess : Unknown @ 0x775d03d0 (jmp 0x162760|jmp 0xfffffffffffffc29|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ KERNELBASE.dll) ntdll!NtTerminateThread : Unknown @ 0x775d03e0 (jmp 0x162500|jmp 0xfffffffffffffc19|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (explorer.exe @ rpcrt4.dll) ntdll!NtAlpcSendWaitReceivePort : Unknown @ 0x775d0470 (jmp 0x162270|jmp 0xfffffffffffffb89|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ kernel32.dll) ntdll!NtTerminateProcess : Unknown @ 0x775d03d0 (jmp 0x162760|jmp 0xfffffffffffffc29|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ kernel32.dll) ntdll!LdrUnloadDll : Unknown @ 0x1c075c (jmp 0xffffffff88d7d50b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ kernel32.dll) ntdll!LdrLoadDll : Unknown @ 0x1c03a4 (jmp 0xffffffff88d795e3)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ KERNELBASE.dll) ntdll!NtTerminateThread : Unknown @ 0x775d03e0 (jmp 0x162500|jmp 0xfffffffffffffc19|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ rpcrt4.dll) ntdll!NtAlpcSendWaitReceivePort : Unknown @ 0x775d0470 (jmp 0x162270|jmp 0xfffffffffffffb89|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ kernel32.dll) ntdll!LdrUnloadDll : Unknown @ 0x303fc (jmp 0x889ec870|jmp 0x66abd334)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtCreateSection : Unknown @ 0x230300 (jmp 0x88dc24b0|jmp 0xfffffcf9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtTerminateThread : Unknown @ 0x2303e0 (jmp 0x88dc2500|jmp 0xfffffc19|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtQueryObject : Unknown @ 0x230440 (jmp 0x88dc2990|jmp 0xfffffbb9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtOpenProcess : Unknown @ 0x230360 (jmp 0x88dc2750|jmp 0xfffffc99|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtOpenThread : Unknown @ 0x230370 (jmp 0x88dc19b0|jmp 0xfffffc89|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtWriteVirtualMemory : Unknown @ 0x2303a0 (jmp 0x88dc2650|jmp 0xfffffc59|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtTerminateProcess : Unknown @ 0x2303d0 (jmp 0x88dc2760|jmp 0xfffffc29|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtCreateThreadEx : Unknown @ 0x2303c0 (jmp 0x88dc1f90|jmp 0xfffffc39|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtCreateThread : Unknown @ 0x2303b0 (jmp 0x88dc2520|jmp 0xfffffc49|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtSuspendThread : Unknown @ 0x230420 (jmp 0x88dc1290|jmp 0xfffffbd9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtSetContextThread : Unknown @ 0x2303f0 (jmp 0x88dc1510|jmp 0xfffffc09|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtSetBootOptions : Unknown @ 0x230260 (jmp 0x88dc1390|jmp 0xfffffd99|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtOpenTimer : Unknown @ 0x230330 (jmp 0x88dc1960|jmp 0xfffffcc9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtNotifyChangeMultipleKeys : Unknown @ 0x230490 (jmp 0x88dc1bf0|jmp 0xfffffb69|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtSuspendProcess : Unknown @ 0x230410 (jmp 0x88dc1290|jmp 0xfffffbe9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtCreateTimer : Unknown @ 0x230320 (jmp 0x88dc1ee0|jmp 0xfffffcd9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtSetSystemInformation : Unknown @ 0x2301e0 (jmp 0x88dc1140|jmp 0xfffffe19|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtCreateIoCompletion : Unknown @ 0x230340 (jmp 0x88dc2020|jmp 0xfffffcb9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtModifyBootEntry : Unknown @ 0x230240 (jmp 0x88dc19e0|jmp 0xfffffdb9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtOpenMutant : Unknown @ 0x230290 (jmp 0x88dc1950|jmp 0xfffffd69|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtSetSystemPowerState : Unknown @ 0x230200 (jmp 0x88dc1150|jmp 0xfffffdf9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtReplyWaitReceivePortEx : Unknown @ 0x230460 (jmp 0x88dc2800|jmp 0xfffffb99|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtShutdownSystem : Unknown @ 0x2301f0 (jmp 0x88dc10d0|jmp 0xfffffe09|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtOpenIoCompletion : Unknown @ 0x230350 (jmp 0x88dc1a70|jmp 0xfffffca9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtAddBootEntry : Unknown @ 0x230220 (jmp 0x88dc21e0|jmp 0xfffffdd9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtReplyWaitReceivePort : Unknown @ 0x230450 (jmp 0x88dc29f0|jmp 0xfffffba9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtDeleteBootEntry : Unknown @ 0x230230 (jmp 0x88dc1d50|jmp 0xfffffdc9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtSetBootEntryOrder : Unknown @ 0x230250 (jmp 0x88dc1390|jmp 0xfffffda9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtOpenSection : Unknown @ 0x230310 (jmp 0x88dc25f0|jmp 0xfffffce9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtDebugActiveProcess : Unknown @ 0x230400 (jmp 0x88dc1f50|jmp 0xfffffbf9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtAssignProcessToJobObject : Unknown @ 0x230390 (jmp 0x88dc2160|jmp 0xfffffc69|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtOpenEvent : Unknown @ 0x2302d0 (jmp 0x88dc2520|jmp 0xfffffd29|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtAlpcSendWaitReceivePort : Unknown @ 0x230470 (jmp 0x88dc2270|jmp 0xfffffb89|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtNotifyChangeKey : Unknown @ 0x230480 (jmp 0x88dc1bf0|jmp 0xfffffb79|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtOpenEventPair : Unknown @ 0x2302f0 (jmp 0x88dc1a20|jmp 0xfffffd09|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtCreateEvent : Unknown @ 0x2302c0 (jmp 0x88dc2490|jmp 0xfffffd39|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtCreateSemaphore : Unknown @ 0x2302a0 (jmp 0x88dc1e90|jmp 0xfffffd59|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtSystemDebugControl : Unknown @ 0x230210 (jmp 0x88dc1070|jmp 0xfffffde9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtCreateMutant : Unknown @ 0x230280 (jmp 0x88dc1f00|jmp 0xfffffd79|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtLoadDriver : Unknown @ 0x2301d0 (jmp 0x88dc1a30|jmp 0xfffffe29|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtCreateEventPair : Unknown @ 0x2302e0 (jmp 0x88dc1fd0|jmp 0xfffffd19|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtQueueApcThreadEx : Unknown @ 0x230430 (jmp 0x88dc1770|jmp 0xfffffbc9|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtDuplicateObject : Unknown @ 0x230380 (jmp 0x88dc2610|jmp 0xfffffc79|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ wow64.dll) ntdll!NtOpenSemaphore : Unknown @ 0x2302b0 (jmp 0x88dc1920|jmp 0xfffffd49|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ kernel32.dll) ntdll!NtTerminateProcess : Unknown @ 0x775d03d0 (jmp 0x162760|jmp 0xfffffffffffffc29|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ kernel32.dll) ntdll!LdrUnloadDll : Unknown @ 0x21075c (jmp 0xffffffff88dcd50b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ kernel32.dll) ntdll!LdrLoadDll : Unknown @ 0x2103a4 (jmp 0xffffffff88dc95e3)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ KERNELBASE.dll) ntdll!NtTerminateThread : Unknown @ 0x775d03e0 (jmp 0x162500|jmp 0xfffffffffffffc19|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ rpcrt4.dll) ntdll!NtAlpcSendWaitReceivePort : Unknown @ 0x775d0470 (jmp 0x162270|jmp 0xfffffffffffffb89|jmp 0x19b)
[IAT:Inl(Hook.IEAT)] (iexplore.exe @ kernel32.dll) ntdll!LdrUnloadDll : Unknown @ 0x303fc (jmp 0x889ec870|jmp 0x66abd334)
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD5000AAKS-00TMA0 ATA Device +++++
--- User ---
[MBR] 318109287bf4e56f6acd71d2947900e9
[BSP] ab31d1196dec9cb8678d79a76f375704 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 476838 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: Generic USB SD Reader USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )
+++++ PhysicalDrive2: Generic USB CF Reader USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )
+++++ PhysicalDrive3: Generic USB SM Reader USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )
+++++ PhysicalDrive4: Generic USB MS Reader USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )