Author Topic: Not sure if I need to remove anything  (Read 3172 times)

0 Members and 1 Guest are viewing this topic.

May 24, 2015, 01:37:03 am

Ibanez

  • Newbie

  • Offline
  • *

  • 1
  • Reputation:
    0
    • View Profile
Not sure if I need to remove anything
« on: May 24, 2015, 01:37:03 am »
This is the log, 3 under registry are highlighted and say might be malware. Also a few under antirootkit. I use Avira as my anti-virus.


RogueKiller V10.6.5.0 [May 20 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User : K [Administrator]
Started from : C:\Users\K\Desktop\RogueKiller (1).exe
Mode : Scan -- Date : 05/23/2015  16:23:01

Processes : 0

Registry : 7
[PUM.Orphan] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263} | CLSID : {E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16}  -> Found
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SessionLauncher (C:\Users\K\AppData\Local\Temp\DX9\SessionLauncher.exe) -> Found
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SessionLauncher (C:\Users\K\AppData\Local\Temp\DX9\SessionLauncher.exe) -> Found
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SessionLauncher (C:\Users\K\AppData\Local\Temp\DX9\SessionLauncher.exe) -> Found
[PUM.StartMenu] HKEY_USERS\S-1-5-21-1601794610-4058933670-4169639-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRun : 0  -> Found
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Found
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Found

Tasks : 0

Files : 0

Hosts File : 2
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1       localhost
[C:\Windows\System32\drivers\etc\hosts] ::1             localhost

Antirootkit : 7 (Driver: Loaded)
[ShwSSDT:Addr(Hook.Shadow)] NtUserSetWindowsHookEx[573] : Unknown @ 0x8959c9ae
[ShwSSDT:Addr(Hook.Shadow)] NtUserSetWinEventHook[576] : Unknown @ 0x8959c9b3
[IAT:Inl(Hook.IEAT)] (explorer.exe) rtl150.bpl - @System@ExceptionClass : Unknown @ 0xffffffffdd6a1039 (call 0x8d505010)
[IAT:Inl(Hook.IEAT)] (explorer.exe) rtl150.bpl - @Classes@TReader@ : Unknown @ 0xffffffffb45933bc (call 0x64500a34)
[IAT:Inl(Hook.IEAT)] (explorer.exe) rtl150.bpl - @Wincodec@GUID_ContainerFormatTiff : Unknown @ 0xffffffffe667d20b (jmp 0x964f0be7)
[IAT:Inl(Hook.IEAT)] (explorer.exe) Jcl150.bpl - @Jclansistrings@TJclAnsiStringList@ : Unknown @ 0x6c4ac960 (call 0x24480048)
[IAT:Inl(Hook.IEAT)] (explorer.exe) rtl150.bpl - @System@ExceptionAcquired : Unknown @ 0xffffffffdd6a1039 (call 0x8d505010)

Web browsers : 0

MBR Check :
+++++ PhysicalDrive0: FUJITSU MHZ2160BH G2 ATA Device +++++
--- User ---
[MBR] 4037848c423e1372f48385aa603cb58e
[BSP] 1cc8cd8a7ac4d1ac4a3e1f4ec3681d2b : HP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 152625 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK


Reply #1May 25, 2015, 05:54:32 pm

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2450
  • Reputation:
    84
    • View Profile
Re: Not sure if I need to remove anything
« Reply #1 on: May 25, 2015, 05:54:32 pm »
Hi Ibanez,

Welcome to Adlice.com Forum.

This detection is a false positive and will be fixed as soon as possible.
Thanks for bringing this to your attention.

Regards.