RogueKiller V12.11.1.0 (x64) [Jun 4 2017] (Free) by Adlice Software
mail : Support Form | Contact • Adlice Software
Feedback : https://forum.adlice.com
Website : Free Virus Cleaner | RogueKiller AntiMalware • Adlice Software
Blog : http://www.adlice.com
Operating System : Windows 10 (10.0.15063) 64 bits version
Started in : Normal mode
User : Doneff Family [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Delete – Date : 06/09/2017 20:48:23 (Duration : 00:19:18)
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 3 ¤¤¤
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\0 234331496953170mcinstcleanup (C:\WINDOWS\TEMP\023433~1.EXE -cleanup -nolog) → Deleted
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-113026621-1705679920-3439515112-1001\Software\Microsoft\Internet Explorer\Main | Start Page : MSN → Replaced ( MSN )
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-113026621-1705679920-3439515112-1001\Software\Microsoft\Internet Explorer\Main | Start Page : MSN → Replaced ( MSN )
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 1 ¤¤¤
[Tr.Gen][Folder] C:\Program Files\update → Removed at reboot [91]
[Tr.Gen][File] C:\Program Files\update\msvcm90.dll → Deleted
[Tr.Gen][File] C:\Program Files\update\msvcp90.dll → Deleted
[Tr.Gen][File] C:\Program Files\update\msvcr90.dll → Deleted
[Tr.Gen][File] C:\Program Files\update\reaper.dll → Deleted
[Tr.Gen][File] C:\Program Files\update\run.bat → Deleted
[Tr.Gen][File] C:\Program Files\update\ua.log → Removed at reboot [20]
[Tr.Gen][File] C:\Program Files\update\UpdateAgent.exe → Removed at reboot [5]
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 2 ¤¤¤
[PUM.HomePage][Chrome:Config] Default [SecurePrefs] : homepage [ http://www.4loot.com/ ] → Deleted
[PUM.HomePage][Chrome:Config] Profile 1 [SecurePrefs] : session.startup_urls [ http://www.forsyth.cc/library/|http://co-davidson-nc.beta.libguides.com/lexingtonpubliclibrary ] → Deleted
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST1000DM003-1ER162 +++++
— User —
[MBR] ce72b05d37d96c5a7c152999e6eaedf1
[BSP] 62b7f321b219208eac246c5e77b206b7 : Empty|VT.Unknown MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] EFI system partition | Offset (sectors): 2048 | Size: 260 MB
1 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 534528 | Size: 128 MB
2 - Basic data partition | Offset (sectors): 796672 | Size: 921260 MB
3 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 1887537152 | Size: 1000 MB
4 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 1889585152 | Size: 30720 MB
5 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 1952499712 | Size: 500 MB
User = LL1 … OK
User = LL2 … OK
+++++ PhysicalDrive1: SAMSUNG SV0602H USB Device +++++
— User —
[MBR] d6f4c328bfe13e036b6e0982f8a5c63f
[BSP] a41170e66910ca5b7ad7aff948443128 : Unknown|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 57275 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 … OK
Error reading LL2 MBR! ([32] The request is not supported. )
+++++ PhysicalDrive2: Generic STORAGE DEVICE USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )
mail : Support Form | Contact • Adlice Software
Feedback : https://forum.adlice.com
Website : Free Virus Cleaner | RogueKiller AntiMalware • Adlice Software
Blog : http://www.adlice.com
Operating System : Windows 10 (10.0.15063) 64 bits version
Started in : Normal mode
User : Doneff Family [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Delete – Date : 06/09/2017 20:48:23 (Duration : 00:19:18)
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 3 ¤¤¤
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\0 234331496953170mcinstcleanup (C:\WINDOWS\TEMP\023433~1.EXE -cleanup -nolog) → Deleted
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-113026621-1705679920-3439515112-1001\Software\Microsoft\Internet Explorer\Main | Start Page : MSN → Replaced ( MSN )
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-113026621-1705679920-3439515112-1001\Software\Microsoft\Internet Explorer\Main | Start Page : MSN → Replaced ( MSN )
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 1 ¤¤¤
[Tr.Gen][Folder] C:\Program Files\update → Removed at reboot [91]
[Tr.Gen][File] C:\Program Files\update\msvcm90.dll → Deleted
[Tr.Gen][File] C:\Program Files\update\msvcp90.dll → Deleted
[Tr.Gen][File] C:\Program Files\update\msvcr90.dll → Deleted
[Tr.Gen][File] C:\Program Files\update\reaper.dll → Deleted
[Tr.Gen][File] C:\Program Files\update\run.bat → Deleted
[Tr.Gen][File] C:\Program Files\update\ua.log → Removed at reboot [20]
[Tr.Gen][File] C:\Program Files\update\UpdateAgent.exe → Removed at reboot [5]
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 2 ¤¤¤
[PUM.HomePage][Chrome:Config] Default [SecurePrefs] : homepage [ http://www.4loot.com/ ] → Deleted
[PUM.HomePage][Chrome:Config] Profile 1 [SecurePrefs] : session.startup_urls [ http://www.forsyth.cc/library/|http://co-davidson-nc.beta.libguides.com/lexingtonpubliclibrary ] → Deleted
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST1000DM003-1ER162 +++++
— User —
[MBR] ce72b05d37d96c5a7c152999e6eaedf1
[BSP] 62b7f321b219208eac246c5e77b206b7 : Empty|VT.Unknown MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] EFI system partition | Offset (sectors): 2048 | Size: 260 MB
1 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 534528 | Size: 128 MB
2 - Basic data partition | Offset (sectors): 796672 | Size: 921260 MB
3 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 1887537152 | Size: 1000 MB
4 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 1889585152 | Size: 30720 MB
5 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 1952499712 | Size: 500 MB
User = LL1 … OK
User = LL2 … OK
+++++ PhysicalDrive1: SAMSUNG SV0602H USB Device +++++
— User —
[MBR] d6f4c328bfe13e036b6e0982f8a5c63f
[BSP] a41170e66910ca5b7ad7aff948443128 : Unknown|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 57275 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 … OK
Error reading LL2 MBR! ([32] The request is not supported. )
+++++ PhysicalDrive2: Generic STORAGE DEVICE USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )
Comment