RogueKiller V8.8.7 [Feb 11 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : Porew [Admin rights]
Mode : Scan -- Date : 02/13/2014 23:53:34
| ARK || FAK || MBR |
¤¤¤ Bad processes : 3 ¤¤¤
[SUSP PATH] UnsignedThemesSvc.exe -- C:\Windows\UnsignedThemesSvc.exe [7] -> KILLED [TermProc]
[SUSP PATH][DLL] explorer.exe -- C:\Users\Porew\AppData\Roaming\Copy\overlay\CopyShExt.dll [x] -> UNLOADED
[SUSP PATH][DLL] explorer.exe -- C:\Users\Porew\AppData\Roaming\Copy\overlay\Brt.dll [x] -> UNLOADED
[SUSP PATH] CopyAgent.exe -- C:\Users\Porew\AppData\Roaming\Copy\CopyAgent.exe [7] -> KILLED [TermProc]
¤¤¤ Registry Entries : 12 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : Copy ("C:\Users\Porew\AppData\Roaming\Copy\CopyAgent.exe" [7]) -> FOUND
[RUN][SUSP PATH] HKCU\[...]\Run : 37wanホ葫 ("C:\Users\Porew\AppData\Roaming\37wan\wz\wz.exe" /autorun [x]) -> FOUND
[RUN][SUSP PATH] HKCU\[...]\Run : websuns4 ("C:\ProgramData\suns4\89AM005Y" [x]) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-2480959248-112055760-2502070270-1001\[...]\Run : Copy ("C:\Users\Porew\AppData\Roaming\Copy\CopyAgent.exe" [7]) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-2480959248-112055760-2502070270-1001\[...]\Run : 37wanホ葫 ("C:\Users\Porew\AppData\Roaming\37wan\wz\wz.exe" /autorun [x]) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-2480959248-112055760-2502070270-1001\[...]\Run : websuns4 ("C:\ProgramData\suns4\89AM005Y" [x]) -> FOUND
[HJ POL][PUM] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
[HJ POL][PUM] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> FOUND
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Scheduled tasks : 0 ¤¤¤
¤¤¤ Startup Entries : 0 ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
¤¤¤ External Hives: ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) WDC WD5000AADS-00S9B0 ATA Device +++++
--- User ---
[MBR] db4fc93eb935bc2a186c8378019ca14c
[BSP] c565a66beeec48d6ee4cac02a5387a30 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476929 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) WDC WD3200AAKS-00B3A0 ATA Device +++++
--- User ---
[MBR] a91ef942f8e39d4cb6c465f4cfa0bf4b
[BSP] dbb4ef9907f757e4b216a99d73f75686 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 305242 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[0]_S_02132014_235334.txt >>
RogueKiller V8.8.7 [Feb 11 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : Porew [Admin rights]
Mode : Remove -- Date : 02/13/2014 23:54:02
| ARK || FAK || MBR |
¤¤¤ Bad processes : 3 ¤¤¤
[SUSP PATH] UnsignedThemesSvc.exe -- C:\Windows\UnsignedThemesSvc.exe [7] -> KILLED [TermProc]
[SUSP PATH][DLL] explorer.exe -- C:\Users\Porew\AppData\Roaming\Copy\overlay\CopyShExt.dll [x] -> UNLOADED
[SUSP PATH][DLL] explorer.exe -- C:\Users\Porew\AppData\Roaming\Copy\overlay\Brt.dll [x] -> UNLOADED
[SUSP PATH] CopyAgent.exe -- C:\Users\Porew\AppData\Roaming\Copy\CopyAgent.exe [7] -> KILLED [TermProc]
¤¤¤ Registry Entries : 12 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : Copy ("C:\Users\Porew\AppData\Roaming\Copy\CopyAgent.exe" [7]) -> DELETED
[RUN][SUSP PATH] HKCU\[...]\Run : 37wanホ葫 ("C:\Users\Porew\AppData\Roaming\37wan\wz\wz.exe" /autorun [x]) -> DELETED
[RUN][SUSP PATH] HKCU\[...]\Run : websuns4 ("C:\ProgramData\suns4\89AM005Y" [x]) -> DELETED
[RUN][SUSP PATH] HKUS\S-1-5-21-2480959248-112055760-2502070270-1001\[...]\Run : Copy ("C:\Users\Porew\AppData\Roaming\Copy\CopyAgent.exe" [7]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2480959248-112055760-2502070270-1001\[...]\Run : 37wanホ葫 ("C:\Users\Porew\AppData\Roaming\37wan\wz\wz.exe" /autorun [x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2480959248-112055760-2502070270-1001\[...]\Run : websuns4 ("C:\ProgramData\suns4\89AM005Y" [x]) -> [0x2] The system cannot find the file specified.
[HJ POL][PUM] HKLM\[...]\System : DisableRegistryTools (0) -> DELETED
[HJ POL][PUM] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED (2)
[HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> REPLACED (1)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Scheduled tasks : 0 ¤¤¤
¤¤¤ Startup Entries : 0 ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
¤¤¤ External Hives: ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) WDC WD5000AADS-00S9B0 ATA Device +++++
--- User ---
[MBR] db4fc93eb935bc2a186c8378019ca14c
[BSP] c565a66beeec48d6ee4cac02a5387a30 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476929 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) WDC WD3200AAKS-00B3A0 ATA Device +++++
--- User ---
[MBR] a91ef942f8e39d4cb6c465f4cfa0bf4b
[BSP] dbb4ef9907f757e4b216a99d73f75686 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 305242 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[0]_D_02132014_235402.txt >>
RKreport[0]_S_02132014_235334.txt
RogueKiller V8.8.7 [Feb 11 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : Porew [Admin rights]
Mode : Shortcuts HJfix -- Date : 02/13/2014 23:54:25
| ARK || FAK || MBR |
¤¤¤ Bad processes : 3 ¤¤¤
[SUSP PATH] UnsignedThemesSvc.exe -- C:\Windows\UnsignedThemesSvc.exe [7] -> KILLED [TermProc]
[SUSP PATH][DLL] explorer.exe -- C:\Users\Porew\AppData\Roaming\Copy\overlay\CopyShExt.dll [x] -> UNLOADED
[SUSP PATH][DLL] explorer.exe -- C:\Users\Porew\AppData\Roaming\Copy\overlay\Brt.dll [x] -> UNLOADED
[SUSP PATH] CopyAgent.exe -- C:\Users\Porew\AppData\Roaming\Copy\CopyAgent.exe [7] -> KILLED [TermProc]
¤¤¤ Driver : [LOADED] ¤¤¤
¤¤¤ External Hives: ¤¤¤
¤¤¤ File attributes restored: ¤¤¤
Desktop: Success 0 / Fail 0
Quick launch: Success 0 / Fail 0
Programs: Success 0 / Fail 0
Start menu: Success 0 / Fail 0
User folder: Success 0 / Fail 0
My documents: Success 0 / Fail 0
My favorites: Success 0 / Fail 0
My pictures: Success 0 / Fail 0
My music: Success 0 / Fail 0
My videos: Success 0 / Fail 0
Local drives: Success 12 / Fail 4
Backup: [NOT FOUND]
Drives:
[C:] \Device\HarddiskVolume1 -- 0x3 --> Restored
[D:] \Device\HarddiskVolume2 -- 0x3 --> Restored
[E:] \Device\CdRom0 -- 0x5 --> Skipped
[F:] \Device\CdRom1 -- 0x5 --> Skipped
¤¤¤ Infection : ¤¤¤
Finished : << RKreport[0]_SC_02132014_235425.txt >>
RKreport[0]_D_02132014_235402.txt;RKreport[0]_S_02132014_235334.txt