RogueKiller V7.1.0 [02/15/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
http://www.geekstogo.com/forum/files/file/413-roguekiller/Blog:
http://tigzyrk.blogspot.comOperating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: Danielle [Admin rights]
Mode: Scan -- Date: 02/17/2012 21:35:49
¤¤¤ Bad processes: 3 ¤¤¤
[SUSP PATH] uiqkhfhg.exe -- C:\Users\Danielle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\uiqkhfhg.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- C:\Windows\SysWOW64\svchost.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- C:\Windows\SysWOW64\svchost.exe -> KILLED [TermProc]
¤¤¤ Registry Entries: 9 ¤¤¤
[SUSP PATH] HKCU\[...]\Run : UiqKhfhg (C:\Users\Danielle\AppData\Local\mcyuwfbs\uiqkhfhg.exe) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-2152382239-2671259734-3952804028-1000[...]\Run : UiqKhfhg (C:\Users\Danielle\AppData\Local\mcyuwfbs\uiqkhfhg.exe) -> FOUND
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (127.0.0.1:8080) -> FOUND
[DNS] HKLM\[...]\ControlSet001\Parameters\Interfaces\{1110752A-7E96-4F3A-978A-8401E5161ECC} : NameServer (88.82.13.12 88.82.13.12) -> FOUND
[DNS] HKLM\[...]\ControlSet001\Parameters\Interfaces\{1CF4B797-729F-4F25-872B-25359B77683F} : NameServer (88.82.13.44 88.82.13.44) -> FOUND
[DNS] HKLM\[...]\ControlSet001\Parameters\Interfaces\{985B41EC-C0A4-4FDA-B231-13F3ACE1F4B4} : NameServer (88.82.13.60 88.82.13.60) -> FOUND
[DNS] HKLM\[...]\ControlSet002\Parameters\Interfaces\{1110752A-7E96-4F3A-978A-8401E5161ECC} : NameServer (88.82.13.12 88.82.13.12) -> FOUND
[DNS] HKLM\[...]\ControlSet002\Parameters\Interfaces\{1CF4B797-729F-4F25-872B-25359B77683F} : NameServer (88.82.13.44 88.82.13.44) -> FOUND
[DNS] HKLM\[...]\ControlSet002\Parameters\Interfaces\{985B41EC-C0A4-4FDA-B231-13F3ACE1F4B4} : NameServer (88.82.13.60 88.82.13.60) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: WDC WD5000BPVT-16HXZT3 +++++
--- User ---
[MBR] b28dc35bad206a93c21870ba0e8dc846
[BSP] cfca259660fd8215548c6b815c439749 : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 2117 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 4339712 | Size: 474820 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[1].txt >>
RKreport[1].txt