Author Topic: Drivers appear infected please confirm  (Read 9253 times)

0 Members and 1 Guest are viewing this topic.

March 06, 2014, 02:48:41 PM

icub4ucme

  • Guest
Drivers appear infected please confirm
« on: March 06, 2014, 02:48:41 PM »
I am having some difficulty reading the scan on the driver tab in Rogue Killer.  It  pulled a bunch of drivers that all begin with NT about 50 of them.  I need to know how to check them to see if they are in fact malicious and if they are do I use the delete button to kill them.  I just loaded the operating system windows 7 pro 2 days ago.

 I will post the log if that is the preferred way to analyse this data.  In the report the area that lists driver shows this as loaded but it doesn't list the drivers that the scan pulled up as possibly infected.  Should I post the report or copy the list infected drivers from the scan and post them in here?  Maybe both. Please advise.  Your help is greatly appreciated. 

Thanks!

Reply #1March 06, 2014, 02:58:34 PM

icub4ucme

  • Guest
Re: Drivers appear infected please confirm
« Reply #1 on: March 06, 2014, 02:58:34 PM »
it looks as if others are posting the report so here is the one from the scan I ran 30 minutes ago.

RogueKiller V8.8.10 [Feb 28 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : Michael [Admin rights]
Mode : Scan -- Date : 03/06/2014 06:07:24
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 0 ¤¤¤

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection :  ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ SCSI) WDC WD10EAVS-00D7B0 +++++
--- User ---
[MBR] 9ca8b912e609102a59145a9fcd2367d5
[BSP] 70d46e45a3edc3690bc6ba4076ff034e : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 953869 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ USB) Lexar USB Flash Drive USB Device +++++
--- User ---
[MBR] 9c1153d7f635efe9841aa61be7289383
[BSP] 33a07a59d299ab4ea9f4ab0156f9d86f : Windows XP MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 10448 | Size: 15278 Mo
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] The request is not supported. )

Finished : << RKreport[0]_S_03062014_060724.txt >>
RKreport[0]_D_03052014_120534.txt;RKreport[0]_S_03052014_120448.txt




Reply #2March 06, 2014, 05:46:12 PM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 956
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Drivers appear infected please confirm
« Reply #2 on: March 06, 2014, 05:46:12 PM »
Hello :)

Quote
In the report the area that lists driver shows this as loaded but it doesn't list the drivers that the scan pulled up as possibly infected.
This is because they are whitelisted :)
You can see in RogueKiller's driver tab a column named 'Legit', with True/False. I'm pretty sure they are all on 'True'
So they are legit indeed.

Reply #3March 07, 2014, 06:36:11 PM

icub4ucme

  • Guest
Re: Drivers appear infected please confirm
« Reply #3 on: March 07, 2014, 06:36:11 PM »
thank you very much for the insite.  Is there a user guide for this application.  Rogue killer?

Reply #4March 13, 2014, 08:07:32 AM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 956
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software

Reply #5March 13, 2014, 04:37:21 PM

icub4ucme

  • Guest
Re: Drivers appear infected please confirm
« Reply #5 on: March 13, 2014, 04:37:21 PM »
Thank you very much.  This is a big help.  You do excellent work I will tell anyone that is interested about your site.