RogueKiller V7.6.5 [08/03/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
http://www.geekstogo...13-roguekiller/
Blog:
http://tigzyrk.blogspot.com
Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Safe mode with network support
User: 2plan [Admin rights]
Mode: Scan -- Date: 08/07/2012 14:35:27
¤¤¤ Bad processes: 2 ¤¤¤
[SUSP PATH] Z@!-60e13116-81c5-4932-8e6f-3cd7ba8aeff3.tmp -- C:\Users\2plan\AppData\Local\Temp\Z@!-60e13116-81c5-4932-8e6f-3cd7ba8aeff3.tmp -> UNLOADED
[SUSP PATH] bomgar-scc.exe -- C:\ProgramData\bomgar-scc-502112CE\bomgar-scc.exe -> KILLED [TermProc]
¤¤¤ Registry Entries: 11 ¤¤¤
[SUSP PATH] HKCU\[...]\Run : Bomgar Support Reconnect [1343914321] ("C:\ProgramData\bomgar-scc-501A8150\bomgar-scc.exe" -nomulti) -> FOUND
[SUSP PATH] HKCU\[...]\Run : Bomgar Support Reconnect [1344332667] ("C:\ProgramData\bomgar-scc-5020E37B\bomgar-scc.exe" -nomulti) -> FOUND
[SUSP PATH] HKCU\[...]\Run : Bomgar Support Reconnect [1344334573] ("C:\ProgramData\bomgar-scc-5020EAED\bomgar-scc.exe" -nomulti) -> FOUND
[SUSP PATH] HKCU\[...]\Run : Bomgar Support Reconnect [1344344782] ("C:\ProgramData\bomgar-scc-502112CE\bomgar-scc.exe" -nomulti) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-2029709861-1995564892-4082333619-1000[...]\Run : Bomgar Support Reconnect [1343914321] ("C:\ProgramData\bomgar-scc-501A8150\bomgar-scc.exe" -nomulti) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-2029709861-1995564892-4082333619-1000[...]\Run : Bomgar Support Reconnect [1344332667] ("C:\ProgramData\bomgar-scc-5020E37B\bomgar-scc.exe" -nomulti) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-2029709861-1995564892-4082333619-1000[...]\Run : Bomgar Support Reconnect [1344334573] ("C:\ProgramData\bomgar-scc-5020EAED\bomgar-scc.exe" -nomulti) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-2029709861-1995564892-4082333619-1000[...]\Run : Bomgar Support Reconnect [1344344782] ("C:\ProgramData\bomgar-scc-502112CE\bomgar-scc.exe" -nomulti) -> FOUND
[HJ] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
[ZeroAccess][FILE] @ : c:\windows\installer\{13ccfeca-99f4-c9c5-d3c1-9de09aff286a}\@ --> FOUND
[ZeroAccess][FOLDER] U : c:\windows\installer\{13ccfeca-99f4-c9c5-d3c1-9de09aff286a}\U --> FOUND
[ZeroAccess][FOLDER] L : c:\windows\installer\{13ccfeca-99f4-c9c5-d3c1-9de09aff286a}\L --> FOUND
[Susp.ASLR][ASLR WIPED-OFF] services.exe : c:\windows\system32\services.exe --> CANNOT FIX
[ZeroAccess][Sig found] services.exe : c:\windows\system32\services.exe --> CANNOT FIX
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ Infection : ZeroAccess ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
::1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS543216L9SA00 +++++
--- User ---
[MBR] 1f614e66d42a5e02aa4bbc8abbedf9d9
[BSP] 22b3c4b072d1fc340447b2b87917798e : MBR Code unknown
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 1500 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 3074048 | Size: 76313 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 159363072 | Size: 74812 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[1].txt >>
RKreport[1].txt
Please be aware that i am using Bomgar to connect to this machine as it is a remote machine. The services for this must stay running
Thank you