0 Members and 1 Guest are viewing this topic.
RogueKiller V10.10.1.0 (x64) [Aug 17 2015] by Adlice Softwaremail : http://www.adlice.com/contact/Feedback : http://forum.adlice.comWebsite : http://www.adlice.com/softwares/roguekiller/Blog : http://www.adlice.comOperating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits versionStarted in : Normal modeUser : Jacobens [Administrator]Started from : C:\Program Files\RogueKiller\RogueKiller.exeMode : Delete -- Date : 08/19/2015 13:15:23¤¤¤ Processes : 2 ¤¤¤[Proc.Injected] iexplore.exe(5428) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe[7] -> Killed [TermProc][Proc.Injected] iexplore.exe(3452) -- C:\Program Files\Internet Explorer\iexplore.exe[7] -> Killed [TermProc]¤¤¤ Registry : 6 ¤¤¤[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 83.255.245.11 193.150.193.150 ([-][EUROPEAN UNION (EU)]) -> Not selected[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 83.255.245.11 193.150.193.150 ([-][EUROPEAN UNION (EU)]) -> Not selected[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5518317A-09C5-47FF-8CEC-F6D8077EA3DB} | DhcpNameServer : 83.255.245.11 193.150.193.150 ([-][EUROPEAN UNION (EU)]) -> Not selected[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{5518317A-09C5-47FF-8CEC-F6D8077EA3DB} | DhcpNameServer : 83.255.245.11 193.150.193.150 ([-][EUROPEAN UNION (EU)]) -> Not selected[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Not selected[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Not selected¤¤¤ Tasks : 0 ¤¤¤¤¤¤ Files : 0 ¤¤¤¤¤¤ Hosts File : 1 ¤¤¤[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost¤¤¤ Antirootkit : 7 (Driver: Loaded) ¤¤¤[IAT:Inl(Hook.IEAT)] (iexplore.exe) kernel32.dll - CreateProcessW : Unknown @ 0x56792b2 (jmp 0x90018275|call 0x306c)[IAT:Inl(Hook.IEAT)] (iexplore.exe @ LPK.dll) user32.DLL - MessageBeep : Unknown @ 0x567ac9d (jmp 0x8e60ec67)[IAT:Inl(Hook.IEAT)] (iexplore.exe @ IMM32.DLL) user32.DLL - SetWindowPos : Unknown @ 0x56792eb (jmp 0x8e62049d|call 0x3070|jmp 0x25)[IAT:Inl(Hook.IEAT)] (iexplore.exe @ IMM32.DLL) user32.DLL - ShowWindow : Unknown @ 0x5679330 (jmp 0x8e618535|call 0x302b|jmp 0x25)[IAT:Inl(Hook.IEAT)] (iexplore.exe @ shell32.DLL) user32.DLL - SetForegroundWindow : Unknown @ 0x56792e6 (jmp 0x8e5fa176|call 0x3070|jmp 0x25)[IAT:Inl(Hook.IEAT)] (iexplore.exe @ CLBCatQ.DLL) advapi32.DLL - RegQueryValueExW : Unknown @ 0x567a963 (jmp 0x8fcc634e)[IAT:Inl(Hook.IEAT)] (iexplore.exe @ Flash32_18_0_0_232.ocx) winmm.dll - waveOutWrite : Unknown @ 0x567acaf (jmp 0x90845d34|jmp 0xd6|call 0xfffe724f)¤¤¤ Web browsers : 0 ¤¤¤¤¤¤ MBR Check : ¤¤¤+++++ PhysicalDrive0: ST1000DM003-1CH162 ATA Device +++++--- User ---[MBR] fa43237d720c81fcddb62387a135d2c8[BSP] 3b5745a6888676fcf126c62d9d6cf5b4 : Windows Vista/7/8|VT.Unknown MBR CodePartition table:0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 953867 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]User = LL1 ... OKUser = LL2 ... OK+++++ PhysicalDrive1: ST31500341AS ATA Device +++++--- User ---[MBR] d2f672e1decfd1aecee5935fdc15d6b4[BSP] ab88def906e35d777a66520bcfeb76f2 : HP|VT.Unknown MBR CodePartition table:0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 1430797 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]User = LL1 ... OKUser = LL2 ... OK+++++ PhysicalDrive2: WDC WD1500AHFD-00RAR5 ATA Device +++++--- User ---[MBR] 66d369bc063226dd0262422cd7910bea[BSP] fb3b3a56cba24c34b05339176b740eef : Windows Vista/7/8|VT.Unknown MBR CodePartition table:0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 142987 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]User = LL1 ... OKUser = LL2 ... OK+++++ PhysicalDrive3: HP DPF USB Device +++++Error reading User MBR! ([15] The device is not ready. )Error reading LL1 MBR! NOT VALID!Error reading LL2 MBR! ([32] The request is not supported. )+++++ PhysicalDrive4: HP DPF USB Device +++++Error reading User MBR! ([15] The device is not ready. )Error reading LL1 MBR! NOT VALID!Error reading LL2 MBR! ([32] The request is not supported. )+++++ PhysicalDrive5: HP DPF USB Device +++++Error reading User MBR! ([15] The device is not ready. )Error reading LL1 MBR! NOT VALID!Error reading LL2 MBR! ([32] The request is not supported. )
http://pastebin.com/1zZ08i9x
http://pastebin.com/HbYwSHVC