Author Topic: Help with understanding RK Report  (Read 3836 times)

0 Members and 1 Guest are viewing this topic.

October 14, 2014, 10:16:27 PM

Oden45

  • Guest
Help with understanding RK Report
« on: October 14, 2014, 10:16:27 PM »
Hey guys!

 I just need some help understanding the log report from the scan I performed. RK did detect an item that was highlighted red in the registry and I deleted that immediately (Thanks for that), but I do not understand what is highlighted in grey for the registry entries. I am not sure whether to keep them, leave them alone, or delete them if I do not need them. There are 10 entries listed below that are highlighted in grey. Everything else in the report is highlighted green so I just need help with the registry entries. Thanks.

RogueKiller V9.0.3.0 [Jun 17 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User : Stephan [Admin rights]
Mode : Scan -- Date : 10/14/2014  10:49:11

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 10 ¤¤¤
[PUM.Policies] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableTaskMgr : 0  -> FOUND
[PUM.Policies] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0  -> FOUND
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3021322240-4194111586-4179583563-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {645FF040-5081-101B-9F08-00AA002F954E} : 1  -> FOUND
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3021322240-4194111586-4179583563-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> FOUND
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\RK_Software_ON_D_D593\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> FOUND
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\RK_Software_ON_D_D593\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> FOUND
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> FOUND
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> FOUND
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3021322240-4194111586-4179583563-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {645FF040-5081-101B-9F08-00AA002F954E} : 1  -> FOUND
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-3021322240-4194111586-4179583563-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> FOUND

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ HOSTS File : 2 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1       localhost
[C:\Windows\System32\drivers\etc\hosts] ::1             localhost

¤¤¤ Antirootkit : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS542525K9SA00 +++++
--- User ---
[MBR] d2d7036e7be04ac3826d9f3c3d1053b4
[BSP] dcda6abd8ed780a846fb9e740d03a8c3 : HP MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 94 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 194560 | Size: 10240 MB
2 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 21166080 | Size: 225578 MB
3 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 483151872 | Size: 2560 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_DEL_10132014_222612.log - RKreport_SCN_10132014_220245.log

Reply #1October 15, 2014, 07:25:02 AM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Help with understanding RK Report
« Reply #1 on: October 15, 2014, 07:25:02 AM »
Hello
I'm pretty sure this can help you ;)

http://www.adlice.com/softwares/roguekiller/documentation/