I did not get an "ACCEPT" box when I ran Roguekiller
RogueKiller V9.2.9.0 [Jul 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : https://www.adlice.c...es/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User : Joe Blow [Admin rights]
Mode : Scan -- Date : 09/05/2014 13:21:18
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 17 ¤¤¤
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aswMBR -> FOUND
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aswVmm -> FOUND
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\aswMBR -> FOUND
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\aswVmm -> FOUND
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 192.168.0.1 205.171.2.25 -> FOUND
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 192.168.0.1 205.171.2.25 -> FOUND
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 192.168.0.1 205.171.2.25 -> FOUND
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 192.168.0.1 205.171.2.25 -> FOUND
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{133E1BE7-4823-45B8-A4D6-09AE514650DC} | DhcpNameServer : 192.168.0.1 205.171.2.25 -> FOUND
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{133E1BE7-4823-45B8-A4D6-09AE514650DC} | DhcpNameServer : 192.168.0.1 205.171.2.25 -> FOUND
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{133E1BE7-4823-45B8-A4D6-09AE514650DC} | DhcpNameServer : 192.168.0.1 205.171.2.25 -> FOUND
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{133E1BE7-4823-45B8-A4D6-09AE514650DC} | DhcpNameServer : 192.168.0.1 205.171.2.25 -> FOUND
[PUM.StartMenu] HKEY_USERS\S-1-5-21-2291903390-3433162778-840360825-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowPrinters : 0 -> FOUND
[PUM.StartMenu] HKEY_USERS\S-1-5-21-2291903390-3433162778-840360825-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 0 -> FOUND
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> FOUND
[Rans.Gendarm] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\winmgmt\Parameters | ServiceDll : C:\DOCUME~1\ALLUSE~1\APPLIC~1\50BC232.cpp -> FOUND
[PUM.SearchPage] HKEY_USERS\S-1-5-21-2291903390-3433162778-840360825-1006\Software\Microsoft\Internet Explorer\Main | Search Page : http://rd.yahoo.com/...//www.yahoo.com -> FOUND
¤¤¤ Scheduled tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ HOSTS File : 1 ¤¤¤
[C:\WINDOWS\System32\drivers\etc\hosts] 127.0.0.1 localhost
¤¤¤ Antirootkit : 44 (Driver: LOADED) ¤¤¤
[SSDT:Addr(Hook.SSDT)] NtAlertResumeThread[12] : Unknown @ 0x87057f38
[SSDT:Addr(Hook.SSDT)] NtAlertThread[13] : Unknown @ 0x87057fd0
[SSDT:Addr(Hook.SSDT)] NtAllocateVirtualMemory[17] : Unknown @ 0x86d5e3c0
[SSDT:Addr(Hook.SSDT)] NtAssignProcessToJobObject[19] : Unknown @ 0x86f43458
[SSDT:Addr(Hook.SSDT)] NtConnectPort[31] : Unknown @ 0x8714e1f8
[SSDT:Addr(Hook.SSDT)] NtCreateMutant[43] : Unknown @ 0x870bd4a8
[SSDT:Addr(Hook.SSDT)] NtCreateSymbolicLinkObject[52] : Unknown @ 0x86f43308
[SSDT:Addr(Hook.SSDT)] NtCreateThread[53] : Unknown @ 0x86e98da8
[SSDT:Addr(Hook.SSDT)] NtDebugActiveProcess[57] : Unknown @ 0x87073448
[SSDT:Addr(Hook.SSDT)] NtDuplicateObject[68] : Unknown @ 0x870955b8
[SSDT:Addr(Hook.SSDT)] NtFreeVirtualMemory[83] : Unknown @ 0x870cbbe0
[SSDT:Addr(Hook.SSDT)] NtImpersonateAnonymousToken[89] : Unknown @ 0x87057e08
[SSDT:Addr(Hook.SSDT)] NtImpersonateThread[91] : Unknown @ 0x87057ea0
[SSDT:Addr(Hook.SSDT)] NtLoadDriver[97] : Unknown @ 0x8716adf0
[SSDT:Addr(Hook.SSDT)] NtMapViewOfSection[108] : Unknown @ 0x870cbb28
[SSDT:Addr(Hook.SSDT)] NtOpenEvent[114] : Unknown @ 0x870bd410
[SSDT:Addr(Hook.SSDT)] NtOpenProcess[122] : Unknown @ 0x86f3cbb0
[SSDT:Addr(Hook.SSDT)] NtOpenProcessToken[123] : Unknown @ 0x87095520
[SSDT:Addr(Hook.SSDT)] NtOpenSection[125] : Unknown @ 0x87073598
[SSDT:Addr(Hook.SSDT)] NtOpenThread[128] : Unknown @ 0x86f3cb28
[SSDT:Addr(Hook.SSDT)] NtProtectVirtualMemory[137] : Unknown @ 0x86f433b0
[SSDT:Addr(Hook.SSDT)] NtQueueApcThread[180] : Unknown @ 0x8704d890
[SSDT:Addr(Hook.SSDT)] NtResumeThread[206] : Unknown @ 0x86eb6e80
[SSDT:Addr(Hook.SSDT)] NtSetContextThread[213] : Unknown @ 0x87084460
[SSDT:Addr(Hook.SSDT)] NtSetInformationProcess[228] : Unknown @ 0x870844f8
[SSDT:Addr(Hook.SSDT)] NtSetSystemInformation[240] : Unknown @ 0x870734e0
[SSDT:Addr(Hook.SSDT)] NtSuspendProcess[253] : Unknown @ 0x870bd378
[SSDT:Addr(Hook.SSDT)] NtSuspendThread[254] : Unknown @ 0x86eb6f18
[SSDT:Addr(Hook.SSDT)] NtTerminateProcess[257] : Unknown @ 0x870bf310
[SSDT:Addr(Hook.SSDT)] NtTerminateThread[258] : Unknown @ 0x86eb6f90
[SSDT:Addr(Hook.SSDT)] NtUnmapViewOfSection[267] : Unknown @ 0x870845a0
[SSDT:Addr(Hook.SSDT)] NtWriteVirtualMemory[277] : Unknown @ 0x86d5e318
[ShwSSDT:Addr(Hook.Shadow)] NtUserAttachThreadInput[307] : Unknown @ 0x870c1ac0
[ShwSSDT:Addr(Hook.Shadow)] NtUserGetAsyncKeyState[383] : Unknown @ 0x870c7ae0
[ShwSSDT:Addr(Hook.Shadow)] NtUserGetKeyboardState[414] : Unknown @ 0x86d697b0
[ShwSSDT:Addr(Hook.Shadow)] NtUserGetKeyState[416] : Unknown @ 0x870c7b58
[ShwSSDT:Addr(Hook.Shadow)] NtUserGetRawInputData[428] : Unknown @ 0x870c1a38
[ShwSSDT:Addr(Hook.Shadow)] NtUserMessageCall[460] : Unknown @ 0x86eff288
[ShwSSDT:Addr(Hook.Shadow)] NtUserPostMessage[475] : Unknown @ 0x86d69728
[ShwSSDT:Addr(Hook.Shadow)] NtUserPostThreadMessage[476] : Unknown @ 0x86eff310
[ShwSSDT:Addr(Hook.Shadow)] NtUserSetWindowsHookEx[549] : Unknown @ 0x86f37290
[ShwSSDT:Addr(Hook.Shadow)] NtUserSetWinEventHook[552] : Unknown @ 0x86d6b8a0
[Filter(Kernel.Filter)] \Driver\atapi @ \Device\CdRom1 : \Driver\redbook @ Unknown (\SystemRoot\System32\DRIVERS\redbook.sys)
[Filter(Kernel.Filter)] \Driver\atapi @ \Device\CdRom0 : \Driver\redbook @ Unknown (\SystemRoot\System32\DRIVERS\redbook.sys)
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: SAMSUNG SV1204H +++++
--- User ---
[MBR] f805a109462a5da52bf7725f32d6a765
[BSP] 44e76c70a7a409e06dba851ad28fef86 : Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 114485 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_SCN_09052014_073613.log - RKreport_SCN_09052014_091353.log