Operating System : Windows 10 (10.0.14393) 64 bits version
Started in : Normal mode
User : RAHOV [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 12/25/2016 04:46:27 (Duration : 00:24:45)
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 5 ¤¤¤
[PUP] (X64) HKEY_USERS\S-1-5-21-980923544-629423826-595731671-1001\Software\Tencent -> Found
[PUP] (X86) HKEY_USERS\S-1-5-21-980923544-629423826-595731671-1001\Software\Tencent -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\0285411482314602mcinstcleanup (C:\Windows\TEMP\028541~1.EXE -cleanup -nolog) -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 10.28.0.1 ([]) -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{5c560b14-243b-45ee-8815-384f651b0ec6} | DhcpNameServer : 10.28.0.1 ([]) -> Found
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 2 ¤¤¤
[PUP][Folder] C:\Users\RAHOV\AppData\Roaming\Tencent -> Found
[Tr.Generic][File] C:\Users\RAHOV\AppData\Roaming\uTorrent\updates\3.4.9_43085\utorrentie.exe -> Found
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MQ01ABF050 +++++
--- User ---
[MBR] 29702c8c9dfea5208b0651d0c74391e0
[BSP] 3e54df8b7bbbbb2b68953b22bb3c7864 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 500 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1026048 | Size: 476438 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
Started in : Normal mode
User : RAHOV [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 12/25/2016 04:46:27 (Duration : 00:24:45)
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 5 ¤¤¤
[PUP] (X64) HKEY_USERS\S-1-5-21-980923544-629423826-595731671-1001\Software\Tencent -> Found
[PUP] (X86) HKEY_USERS\S-1-5-21-980923544-629423826-595731671-1001\Software\Tencent -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\0285411482314602mcinstcleanup (C:\Windows\TEMP\028541~1.EXE -cleanup -nolog) -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 10.28.0.1 ([]) -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{5c560b14-243b-45ee-8815-384f651b0ec6} | DhcpNameServer : 10.28.0.1 ([]) -> Found
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 2 ¤¤¤
[PUP][Folder] C:\Users\RAHOV\AppData\Roaming\Tencent -> Found
[Tr.Generic][File] C:\Users\RAHOV\AppData\Roaming\uTorrent\updates\3.4.9_43085\utorrentie.exe -> Found
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MQ01ABF050 +++++
--- User ---
[MBR] 29702c8c9dfea5208b0651d0c74391e0
[BSP] 3e54df8b7bbbbb2b68953b22bb3c7864 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 500 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1026048 | Size: 476438 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK