RogueKiller V7.3.1 [03/10/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog:
http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Milan [Admin rights]
Mode: Remove -- Date: 03/17/2012 19:57:03
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 9 ¤¤¤
[WallPP] HKCU\[...]\Desktop : Wallpaper () -> REPLACED (C:\Documents and Settings\Milan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp)
[HJ] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowUser (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyPics (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowMyMusic (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowSetProgramAccessAndDefaults (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
SSDT[47] : NtCreateProcess @ 0x805D11EC -> HOOKED (\SystemRoot\system32\drivers\SbFw.sys @ 0xACF0EE90)
SSDT[48] : NtCreateProcessEx @ 0x805D1136 -> HOOKED (\SystemRoot\system32\drivers\SbFw.sys @ 0xACF0ED9C)
SSDT[53] : NtCreateThread @ 0x805D0FD4 -> HOOKED (\SystemRoot\system32\drivers\SbFw.sys @ 0xACF0F3FC)
SSDT[62] : NtDeleteFile @ 0x80576C2C -> HOOKED (\SystemRoot\system32\drivers\SbFw.sys @ 0xACF10210)
SSDT[108] : NtMapViewOfSection @ 0x805B2006 -> HOOKED (\SystemRoot\system32\drivers\sbhips.sys @ 0xBA2FA168)
SSDT[119] : NtOpenKey @ 0x80624B58 -> HOOKED (\SystemRoot\system32\drivers\SbFw.sys @ 0xACF0C5CA)
SSDT[206] : NtResumeThread @ 0x805D4976 -> HOOKED (\SystemRoot\system32\drivers\SbFw.sys @ 0xACF0F4EC)
IRP[IRP_MJ_CREATE] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB9DFBB40)
IRP[IRP_MJ_CLOSE] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB9DFBB40)
IRP[IRP_MJ_DEVICE_CONTROL] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB9DFBB40)
IRP[IRP_MJ_SYSTEM_CONTROL] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB9DFBB40)
IRP[IRP_MJ_DEVICE_CHANGE] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xB9DFBB40)
¤¤¤ Infection : Root.MBR ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
ÿþ1
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: WDC WD6400AAKS-65A7B0 +++++
--- User ---
[MBR] 156d2503c9584741bf970d01f3212794
[BSP] 7b491a69e23846d8cc96cb347e578f08 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 610469 Mo
User = LL1 ... OK!
User != LL2 ... KO!
--- LL2 ---
[MBR] fdc10f6c984a9431f8ae874c3061acfb
[BSP] 7b491a69e23846d8cc96cb347e578f08 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 610469 Mo
1 - [ACTIVE] NTFS (0x17) [HIDDEN!] Offset (sectors): 1250242560 | Size: 10 Mo
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt