RogueKiller V12.9.4.0 (x64) [Jan 16 2017] (Free) by Adlice Software mail : http://www.adlice.com/contact/ Feedback : http://forum.adlice.com Website : http://www.adlice.com/download/roguekiller/ Blog : http://www.adlice.com Operating System : Windows 10 (10.0.14393) 64 bits version Started in : Normal mode User : PC-ABDERRAHMEN [Administrator] Started from : C:\Users\PC-ABDERRAHMEN\Desktop\RogueKillerX64.exe Mode : Scan -- Date : 01/20/2017 22:49:42 (Duration : 00:52:04) ¤¤¤ Processes : 0 ¤¤¤ ¤¤¤ Registry : 2 ¤¤¤ [PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Found [PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Found ¤¤¤ Tasks : 0 ¤¤¤ ¤¤¤ Files : 2 ¤¤¤ [PUP.HackTool][Folder] C:\Windows\KMSServerService -> Found [Tr.Gen0][File] C:\Users\PC-ABDERRAHMEN\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe -> Found ¤¤¤ WMI : 0 ¤¤¤ ¤¤¤ Hosts File : 0 ¤¤¤ ¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤ ¤¤¤ Web browsers : 2 ¤¤¤ [PUP.Gen0][Chrome:Addon] Default : SafeBrowse [obkfjhifkbhimlocpddgamonjihinpak] -> Found [PUM.HomePage][Chrome:Config] Default [SecurePrefs] : session.startup_urls [http://public-box.ru/start] -> Found ¤¤¤ MBR Check : ¤¤¤ +++++ PhysicalDrive0: ST1000LM024 HN-M101MBB +++++ --- User --- [MBR] 692ba48fb1e6b790d2410aec4919bf48 [BSP] 519d09c4812b82b0b18bc34acb434474 : Windows Vista/7/8 MBR Code Partition table: 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 500 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1026048 | Size: 163368 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 335603712 | Size: 489999 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 3 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1339121664 | Size: 300000 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] User = LL1 ... OK User = LL2 ... OK