RogueKiller V12.12.19.0 (x64) [May 28 2018] (Premium) by Adlice Software
mail :
http://www.adlice.com/contact/
Feedback :
https://forum.adlice.com
Website :
http://www.adlice.com/download/roguekiller/
Blog :
http://www.adlice.com
Operating System : Windows 10 (10.0.17134) 64 bits version
Started in : Normal mode
User : su [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 05/30/2018 01:29:27 (Duration : 00:13:59)
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 4 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3166309138-43010382-2060014392-1001\Software\Microsoft\Windows\CurrentVersion\Run | 1Password : "C:\Users\su\AppData\Local\1password\app\7\1Password.exe" /silent [7] -> Found
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3166309138-43010382-2060014392-1001\Software\Microsoft\Windows\CurrentVersion\Run | 1Password : "C:\Users\su\AppData\Local\1password\app\7\1Password.exe" /silent [7] -> Found
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-3166309138-43010382-2060014392-1001\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve -> Found
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-3166309138-43010382-2060014392-1001\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve -> Found
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Hosts File : 0 [Too big!] ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 1 ¤¤¤
[PUM.SearchPage][Chrome:Config] Default [SecurePrefs] : default_search_provider_data.template_url_data.keyword [
https://google.com.vn] -> Found
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST4000DM000-1F2168 +++++
--- User ---
[MBR] bdbf642f7815e1d104249319214743bd
[BSP] 32468b9bbceed235b53e6e1f43cc2026 : Windows Vista/7/8 MBR Code
Partition table:
0 - Basic data partition | Offset (sectors): 264192 | Size: 3815318 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: WDC WD10EZEX-07M2NA1 +++++
--- User ---
[MBR] 6f55a60693a1c7accad56a8e9314b89e
[BSP] e98a4e0a9d09745e7e06b13ce90d9b34 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive2: SAMSUNG MZVKW512HMJP-00000 +++++
--- User ---
[MBR] d842b42cf92bc1b7bc9065473ec2a0d4
[BSP] 402ae62735247d720795bdd9d76ad31c : Empty|VT.Unknown MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 499 MB
1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 1024000 | Size: 100 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 1228800 | Size: 16 MB
3 - Basic data partition | Offset (sectors): 1261568 | Size: 487770 MB
User = LL1 ... OK
Error reading LL2 MBR! ([1] Incorrect function. )