RogueKiller V12.9.6.0 (x64) [Jan 30 2017] (Premium) by Adlice Software mail : http://www.adlice.com/contact/ Feedback : http://forum.adlice.com Website : http://www.adlice.com/download/roguekiller/ Blog : http://www.adlice.com Operating System : Windows 7 (6.1.7600) 64 bits version Started in : Normal mode User : Cosmin [Administrator] Started from : C:\Program Files\RogueKiller\RogueKiller64.exe Mode : Delete -- Date : 02/03/2017 20:19:25 (Duration : 00:59:55) ¤¤¤ Processes : 0 ¤¤¤ ¤¤¤ Registry : 0 ¤¤¤ ¤¤¤ Tasks : 0 ¤¤¤ ¤¤¤ Files : 13 ¤¤¤ [Tr.Gen0][File] C:\Users\Cosmin\AppData\Roaming\uTorrent\updates\3.4.5_41073\utorrentie.exe -> Deleted [Tr.Gen0][File] C:\Users\Cosmin\AppData\Roaming\uTorrent\updates\3.4.5_41162\utorrentie.exe -> Deleted [Tr.Gen0][File] C:\Users\Cosmin\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe -> Deleted [Tr.Gen0][File] C:\Users\Cosmin\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe -> Deleted [Tr.Gen0][File] C:\Users\Cosmin\AppData\Roaming\uTorrent\updates\3.4.5_41865\utorrentie.exe -> Deleted [Tr.Gen0][File] C:\Users\Cosmin\AppData\Roaming\uTorrent\updates\3.4.6_42094\utorrentie.exe -> Deleted [Tr.Gen0][File] C:\Users\Cosmin\AppData\Roaming\uTorrent\updates\3.4.7_42330\utorrentie.exe -> Deleted [Tr.Gen0][File] C:\Users\Cosmin\AppData\Roaming\uTorrent\updates\3.4.8_42449\utorrentie.exe -> Deleted [Tr.Gen0][File] C:\Users\Cosmin\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe -> Deleted [Tr.Gen0][File] C:\Users\Cosmin\AppData\Roaming\uTorrent\updates\3.4.9_42606\utorrentie.exe -> Deleted [Tr.Gen0][File] C:\Users\Cosmin\AppData\Roaming\uTorrent\updates\3.4.9_42923\utorrentie.exe -> Deleted [Tr.Gen0][File] C:\Users\Cosmin\AppData\Roaming\uTorrent\updates\3.4.9_42973\utorrentie.exe -> Deleted [Tr.Gen0][File] C:\Users\Cosmin\AppData\Roaming\uTorrent\updates\3.4.9_43085\utorrentie.exe -> Removed at reboot [5] ¤¤¤ WMI : 0 ¤¤¤ ¤¤¤ Hosts File : 0 ¤¤¤ ¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤ ¤¤¤ Web browsers : 4 ¤¤¤ [PUM.HomePage][Chrome:Config] Default [SecurePrefs] : homepage [search.mpc.am] -> Deleted [PUM.HomePage][Chrome:Config] Default [SecurePrefs] : session.startup_urls [search.mpc.am] -> Deleted [PUM.SearchPage][Chrome:Config] Default [SecurePrefs] : default_search_provider_data.template_url_data.keyword [feed.sonic-search.com__] -> Deleted [PUM.SearchPage][Chrome:Config] Default [SecurePrefs] : default_search_provider_data.template_url_data.url [http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWudxax0QU9mw3fRjPVcv-fuddlNhEQpilZJ_aAeB5mN1t48xnQ--DeinSjy5Q5GN941Mz-cTeb-JLGkus4xadyv5LCAAztyfUmMhbPqIYd42gwMDe2AruxkEYDvDs2Ot5Ahq1N8T1CLynFhKqfaYByPxIig,,&q={searchTerms}] -> Deleted ¤¤¤ MBR Check : ¤¤¤ +++++ PhysicalDrive0: WDC WD5000AAKX-003CA0 ATA Device +++++ --- User --- [MBR] 9aa86df773117778ed1842a08e593f87 [BSP] cdafa94f2ba57d3e203ee7da4ec352ef : Windows Vista/7/8|VT.Unknown MBR Code Partition table: 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 99900 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 204802048 | Size: 376938 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] User = LL1 ... OK User = LL2 ... OK