RogueKiller V7.3.2 [03/20/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: dreamcatcher [Admin rights]
Mode: Scan – Date: 03/25/2012 01:20:14
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 4 ¤¤¤
[BLACKLIST DLL] HKUS\S-1-5-19[…]\Run : Update (rundll32.exe “C:\Windows\system32\config\systemprofile\AppData\Roaming\Adobe\Adobe\yvfpemrj.dll”,DllRegisterServer) → FOUND
[BLACKLIST DLL] HKUS\S-1-5-20[…]\Run : Update (rundll32.exe “C:\Windows\system32\config\systemprofile\AppData\Roaming\Adobe\Adobe\yvfpemrj.dll”,DllRegisterServer) → FOUND
[HJ] HKLM[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) → FOUND
[HJ] HKLM[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) → FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
::1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: SAMSUNG HM250JI +++++
— User —
[MBR] 06e36294547fc5d19bc009fd8a79f9e5
[BSP] 74f57324e4dc5ad9a725bf116130038a : HP tatooed MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 229985 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 471009735 | Size: 8487 Mo
2 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 488392065 | Size: 2 Mo
User = LL1 … OK!
User = LL2 … OK!
Finished : << RKreport[1].txt >>
RKreport[1].txt
RogueKiller V7.3.2 [03/20/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: dreamcatcher [Admin rights]
Mode: Remove – Date: 03/25/2012 01:22:40
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 4 ¤¤¤
[BLACKLIST DLL] HKUS\S-1-5-19[…]\Run : Update (rundll32.exe “C:\Windows\system32\config\systemprofile\AppData\Roaming\Adobe\Adobe\yvfpemrj.dll”,DllRegisterServer) → DELETED
[BLACKLIST DLL] HKUS\S-1-5-20[…]\Run : Update (rundll32.exe “C:\Windows\system32\config\systemprofile\AppData\Roaming\Adobe\Adobe\yvfpemrj.dll”,DllRegisterServer) → DELETED
[HJ] HKLM[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) → REPLACED (0)
[HJ] HKLM[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) → REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
::1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: SAMSUNG HM250JI +++++
— User —
[MBR] 06e36294547fc5d19bc009fd8a79f9e5
[BSP] 74f57324e4dc5ad9a725bf116130038a : HP tatooed MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 229985 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 471009735 | Size: 8487 Mo
2 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 488392065 | Size: 2 Mo
User = LL1 … OK!
User = LL2 … OK!
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
RogueKiller V7.3.2 [03/20/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: dreamcatcher [Admin rights]
Mode: Shortcuts HJfix – Date: 03/25/2012 01:27:53
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ File attributes restored: ¤¤¤
Desktop: Success 1 / Fail 0
Quick launch: Success 0 / Fail 0
Programs: Success 20 / Fail 0
Start menu: Success 1 / Fail 0
User folder: Success 105 / Fail 0
My documents: Success 0 / Fail 0
My favorites: Success 0 / Fail 0
My pictures: Success 0 / Fail 0
My music: Success 0 / Fail 0
My videos: Success 0 / Fail 0
Local drives: Success 317 / Fail 0
Backup: [NOT FOUND]
Drives:
[C:] \Device\HarddiskVolume1 – 0x3 → Restored
[D:] \Device\HarddiskVolume2 – 0x3 → Restored
¤¤¤ Infection : ¤¤¤
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt