ÿþRogueKiller V12.6.3.0 [Sep 19 2016] (Premium) by Adlice Software mail : http://www.adlice.com/contact/ Feedback : http://forum.adlice.com Website : http://www.adlice.com/download/roguekiller/ Blog : http://www.adlice.com Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version Started in : Normal mode User : DrSergiooW [Administrator] Started from : C:\Users\DrSergiooW\Downloads\Programs\RogueKiller_2.exe Mode : Scan -- Date : 09/24/2016 13:30:41 (Duration : 00:29:34) ¤¤¤ Processes : 3 ¤¤¤ [PUP] PCFasterSvc.exe(908) -- C:\Program Files (x86)\PC Faster\5.1.0.0\PCFasterSvc.exe[7] -> Found [PUP] PCFasterSvc.exe(2372) -- C:\Program Files (x86)\PC Faster\5.1.0.0\PCFasterSvc.exe[7] -> Found [PUP] (SVC) PCFApiUtil -- \??\C:\Program Files (x86)\PC Faster\5.1.0.0\PCFApiUtil64.sys[x] -> Found ¤¤¤ Registry : 15 ¤¤¤ [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{47F40CF9-2D34-462A-B404-0E6E85636BB9} (C:\Program Files (x86)\PC Faster\5.1.0.0\WiFiDeskBand64.dll) -> Found [PUP] (X64) HKEY_CLASSES_ROOT\metnsd -> Found [PUP] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PCFApiUtil (\??\C:\Program Files (x86)\PC Faster\5.1.0.0\PCFApiUtil64.sys) -> Found [PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=22.7.0.76 -> Found [PUM.HomePage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=22.7.0.76 -> Found [PUM.HomePage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=22.7.0.76 -> Found [PUM.HomePage] (X64) HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=22.7.0.76 -> Found [PUM.HomePage] (X86) HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=22.7.0.76 -> Found [PUM.HomePage] (X64) HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=22.7.0.76 -> Found [PUM.HomePage] (X86) HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=22.7.0.76 -> Found [PUM.HomePage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=22.7.0.76 -> Found [PUM.HomePage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=22.7.0.76 -> Found [PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://securityresponse.symantec.com/avcenter/fix_homepage/ -> Found [PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://securityresponse.symantec.com/avcenter/fix_homepage/ -> Found [PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Search_URL : http://securityresponse.symantec.com/avcenter/fix_homepage/ -> Found ¤¤¤ Tasks : 0 ¤¤¤ ¤¤¤ Files : 17 ¤¤¤ [PUP][File] C:\Users\DrSergiooW\Desktop\Baidu PC Faster.lnk [LNK@] C:\PROGRA~2\PCFAST~1\510~1.0\PCFTray.exe -shortcut -> Found [PUP][File] C:\Users\DrSergiooW\Desktop\Baidu WiFi Hotspot.lnk [LNK@] C:\PROGRA~2\PCFAST~1\510~1.0\WIFIHO~2.EXE -shortcut -> Found [PUP][File] C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster\Uninstall.lnk [LNK@] C:\PROGRA~2\PCFAST~1\510~1.0\UNINST~2.EXE -> Found [PUP][File] C:\Users\DrSergiooW\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster\Baidu PC Faster.lnk [LNK@] C:\PROGRA~2\PCFAST~1\510~1.0\PCFTray.exe -startmenu -> Found [PUP][File] C:\Users\DrSergiooW\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster\Feedback.lnk [LNK@] C:\PROGRA~2\PCFAST~1\510~1.0\PCFAST~4.EXE -start_menu -> Found [PUP][File] C:\Users\DrSergiooW\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster\Uninstall.lnk [LNK@] C:\PROGRA~2\PCFAST~1\510~1.0\UNINST~2.EXE -> Found [PUP][Folder] C:\Users\DrSergiooW\AppData\Roaming\PC Faster -> Found [PUP][Folder] C:\Users\DrSergiooW\AppData\Roaming\Tencent -> Found [PUP][File] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster\Baidu PC Faster.lnk [LNK@] C:\PROGRA~2\PCFAST~1\510~1.0\PCFTray.exe -startmenu -> Found [PUP][File] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster\Feedback.lnk [LNK@] C:\PROGRA~2\PCFAST~1\510~1.0\PCFAST~4.EXE -start_menu -> Found [PUP][File] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster\Uninstall.lnk [LNK@] C:\PROGRA~2\PCFAST~1\510~1.0\UNINST~2.EXE -> Found [PUP][Folder] C:\ProgramData\PC Faster -> Found [PUP][Folder] C:\ProgramData\Tencent -> Found [PUP][Folder] C:\Program Files (x86)\PC Faster -> Found [PUP][File] C:\Users\DrSergiooW\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster\Baidu PC Faster.lnk [LNK@] C:\PROGRA~2\PCFAST~1\510~1.0\PCFTray.exe -startmenu -> Found [PUP][File] C:\Users\DrSergiooW\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster\Feedback.lnk [LNK@] C:\PROGRA~2\PCFAST~1\510~1.0\PCFAST~4.EXE -start_menu -> Found [PUP][File] C:\Users\DrSergiooW\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster\Uninstall.lnk [LNK@] C:\PROGRA~2\PCFAST~1\510~1.0\UNINST~2.EXE -> Found ¤¤¤ WMI : 0 ¤¤¤ ¤¤¤ Hosts File : 0 ¤¤¤ ¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤ ¤¤¤ Web browsers : 0 ¤¤¤ ¤¤¤ MBR Check : ¤¤¤ +++++ PhysicalDrive0: +++++ --- User --- [MBR] 2299f1b6a04d4395202ed1b4e98d9fbc [BSP] 92df1db1e484b3612ab9b1eb33ba1f26 : Windows Vista/7/8 MBR Code Partition table: 0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 305242 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] User = LL1 ... OK User = LL2 ... OK +++++ PhysicalDrive1: ST3500312CS ATA Device +++++ --- User --- [MBR] 10152b65c58d8143d5e1b835044b0a3d [BSP] 499f6b7aa0beeb5bc6040a3339f46863 : Windows Vista/7/8|VT.Unknown MBR Code Partition table: 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 215260 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 441059328 | Size: 261577 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] User = LL1 ... OK User = LL2 ... OK