RogueKiller V8.7.11 _x64_ [Nov 25 2013] by Tigzy
Operating System : Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User : XXX [Admin rights]
Mode : Remove -- Date : 12/05/2013 12:40:48
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 10 ¤¤¤
[HJ POL][PUM] HKLM\[...]\System : DisableRegistryTools (0) -> NON SELEZIONATO
[HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : DisableRegistryTools (0) -> NON SELEZIONATO
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> NON SELEZIONATO
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowRun (0) -> NON SELEZIONATO
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NON SELEZIONATO
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NON SELEZIONATO
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NON SELEZIONATO
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NON SELEZIONATO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NON SELEZIONATO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NON SELEZIONATO
¤¤¤ Le attività pianificate : 2 ¤¤¤
[V2][ROGUE ST] 4778 : wscript.exe - C:\Users\XXX\AppData\Local\Temp\launchie.vbs //B -> Cancellato
[V2][ROGUE ST] Plus-HD-2.2-firefoxinstaller : C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-firefoxinstaller.exe - /installxpi /agentregpath='Plus-HD-2.2' /extensionfilepath='C:\Program Files (x86)\Plus-HD-2.2\33036.xpi' /appid=33036 /srcid='000126' /subid='0' /zdata='0' /bic=37F1D696F2B0429AABF867CC5379368AIE /verifier=154b7d064ebd07672aac44535a2d0b90 /installerversion=1_27_153 /installerfullversion=1.27.153.6 /installationtime=1373841972 /statsdomain=hxxp://stats.myserverstat.com /errorsdomain=hxxp://errors.myserverstat.com /waitforbrowser=300
/extensionid=4fdacf00-e9c4-4ad5-b4cf-bf ... a102a9.com /extensionversion=0.91 /prefsbranch=a4fdacf00e9c44ad5b4cfbf9800f184f63685711674e04973936f860cd2a102a9com33036 /updateurl=hxxps://w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/33036.rdf /allusers /allprofiles /externallog='' [x][x][x][x][x][x][x][x][x] -> Cancellato
¤¤¤ voci di avvio : 0 ¤¤¤
¤¤¤ I browser Web : 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤
¤¤¤ Extern Hives: ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤

%SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST3250318AS ATA Device +++++
--- User ---
[MBR] e46c10d441063b6b0eb1d2b30684b480
[BSP] 15cb3de73ea06e52aa242339fb0c3167 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 238456 Mo
1 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 488359936 | Size: 10 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) WDC WD5001AALS-00E3A0 ATA Device +++++
--- User ---
[MBR] e2cd4087aa4fae86f93467a1cb4cecb2
[BSP] 557f5765d6157bab9ce117296c0ce44e : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 476938 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[0]_D_12052013_124048.txt >>
RKreport[0]_S_12052013_114009.txt;RKreport[0]_S_12052013_123117.txt