First thank you so much for helping.
I have installed and run the 64 bit version.
I do not have detekt running, at least I don't think I do, I've never heard of it.
Here are my results:
RogueKiller V10.10.1.0 (x64) [Aug 17 2015] by Adlice Software
mail :
http://www.adlice.com/contact/Feedback :
http://forum.adlice.comWebsite :
http://www.adlice.com/softwares/roguekiller/Blog :
http://www.adlice.comOperating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : David [Administrator]
Started from : C:\Users\David\Downloads\RogueKillerX64_10_10_1_0 (1).exe
Mode : Scan -- Date : 08/19/2015 10:13:19
¤¤¤ Processes : 3 ¤¤¤
[VT.Unknown] EasyDmsExplorer.dll(3472) -- C:\Program Files\SAP\EasyDmsInterface\Ansi\EasyDmsExplorer.dll[-] -> Unloaded
[VT.Unknown] EasyDmsPrxy.dll(3472) -- C:\Program Files\SAP\EasyDmsInterface\Ansi\EasyDmsPrxy.dll[-] -> Unloaded
[VT.Unknown] librfc32.dll(3472) -- C:\Program Files\SAP\EasyDmsInterface\Ansi\librfc32.dll[-] -> Unloaded
¤¤¤ Registry : 11 ¤¤¤
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> Found
[Suspicious.Path] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | CitrixReceiver : "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk"
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pmem (\??\C:\Users\David\AppData\Local\Temp\_MEI110402\drivers\winpmem64.sys) -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pmem (\??\C:\Users\David\AppData\Local\Temp\_MEI110402\drivers\winpmem64.sys) -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\pmem (\??\C:\Users\David\AppData\Local\Temp\_MEI110402\drivers\winpmem64.sys) -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2087372787-698181960-4156799124-1001\Software\Microsoft\Internet Explorer\Main | Start Page :
http://finance.yahoo.com/ -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2087372787-698181960-4156799124-1001\Software\Microsoft\Internet Explorer\Main | Start Page :
http://finance.yahoo.com/ -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2087372787-698181960-4156799124-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=bestbuy&pf=cnnb -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2087372787-698181960-4156799124-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=bestbuy&pf=cnnb -> Found
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-2087372787-698181960-4156799124-1001\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve -> Found
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-2087372787-698181960-4156799124-1001\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve -> Found
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: KINGSTON SH100S3240G +++++
--- User ---
[MBR] 44a18fa383b29672982d934a3cf9f67e
[BSP] 88ca0319269ad6323fba2737c9302e92 : Unknown|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 199 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 409600 | Size: 211861 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 435040200 | Size: 16457 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
3 - [XXXXXX] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 468758528 | Size: 50 MB
User = LL1 ... OK
User = LL2 ... OK