RogueKiller V10.10.0.0 (x64) [Aug 11 2015] by Adlice Software mail : http://www.adlice.com/contact/ Feedback : http://forum.adlice.com Website : http://www.adlice.com/softwares/roguekiller/ Blog : http://www.adlice.com Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version Started in : Normal mode User : asus [Administrator] Started from : C:\Users\asus\Desktop\RogueKillerX64.exe Mode : Scan -- Date : 08/14/2015 08:32:29 ¤¤¤ Processes : 1 ¤¤¤ [VT.Unknown] SYSASUS-PC.exe(4040) -- C:\Windows\SysWOW64\SYSASUS-PC.exe[-] -> Killed [TermProc] ¤¤¤ Registry : 7 ¤¤¤ [VT.Unknown] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | Java7 Update : C:\Windows\SysWOW64\SYSASUS-PC.exe [-] -> Found [PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-2894406037-275763777-2117583697-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : 127.0.0.1:6038 -> Found [PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-2894406037-275763777-2117583697-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : 127.0.0.1:6038 -> Found [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 20.23.52.1 ([UNITED STATES (US)]) -> Found [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 20.23.52.1 ([UNITED STATES (US)]) -> Found [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D6FC9E43-CEB0-49C8-9B8C-725C8E082D4E} | DhcpNameServer : 20.23.52.1 ([UNITED STATES (US)]) -> Found [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{D6FC9E43-CEB0-49C8-9B8C-725C8E082D4E} | DhcpNameServer : 20.23.52.1 ([UNITED STATES (US)]) -> Found ¤¤¤ Tasks : 0 ¤¤¤ ¤¤¤ Files : 0 ¤¤¤ ¤¤¤ Hosts File : 0 ¤¤¤ ¤¤¤ Antirootkit : 7 (Driver: Loaded) ¤¤¤ [IRP:Addr(Hook.IRP)] \SystemRoot\system32\DRIVERS\iaStor.sys - IRP_MJ_CREATE[0] : Unknown @ 0x4186339600000000 [IRP:Addr(Hook.IRP)] \SystemRoot\system32\DRIVERS\iaStor.sys - IRP_MJ_CLOSE[2] : Unknown @ 0x4186339600000000 [IRP:Addr(Hook.IRP)] \SystemRoot\system32\DRIVERS\iaStor.sys - IRP_MJ_DEVICE_CONTROL[14] : Unknown @ 0x4186339600000000 [IRP:Addr(Hook.IRP)] \SystemRoot\system32\DRIVERS\iaStor.sys - IRP_MJ_INTERNAL_DEVICE_CONTROL[15] : Unknown @ 0x4186339600000000 [IRP:Addr(Hook.IRP)] \SystemRoot\system32\DRIVERS\iaStor.sys - IRP_MJ_POWER[22] : Unknown @ 0x4186339600000000 [IRP:Addr(Hook.IRP)] \SystemRoot\system32\DRIVERS\iaStor.sys - IRP_MJ_SYSTEM_CONTROL[23] : Unknown @ 0x4186339600000000 [IRP:Addr(Hook.IRP)] \SystemRoot\system32\DRIVERS\iaStor.sys - IRP_MJ_PNP[27] : Unknown @ 0x4186339600000000 ¤¤¤ Web browsers : 2 ¤¤¤ [PUM.Proxy][FIREFX:Config] cc97mfff.default : user_pref("network.proxy.http", "127.0.0.1"); -> Found [PUM.Proxy][FIREFX:Config] cc97mfff.default : user_pref("network.proxy.http_port", 6038); -> Found ¤¤¤ MBR Check : ¤¤¤ +++++ PhysicalDrive0: +++++ --- User --- [MBR] 857636eae35702b1e828739e2c98a9d2 [BSP] 7ff85546762696473b914de074c0c292 : Windows Vista/7/8|VT.Unknown MBR Code Partition table: 0 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 2048 | Size: 12000 MB 1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 24578048 | Size: 119235 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 2 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 268771328 | Size: 345703 MB User = LL1 ... OK User = LL2 ... OK