RogueKiller V8.7.9 _x64_ [Nov 25 2013] od Tigzy mail : tigzyRKgmailcom Dodaj opinię : http://www.adlice.com/forum/ Strona internetowa : http://www.adlice.com/softwares/roguekiller/ Blog : http://tigzyrk.blogspot.com/ System Operacyjny : Windows 7 (6.1.7600 ) 64 bits version Uruchomiono z : Tryb normalny Użytkownik : LKS [Uprawnienia Administratora] Tryb : Usuń -- Data : 11/28/2013 16:56:23 | ARK || FAK || MBR | ¤¤¤ Szkodliwe procesy : 0 ¤¤¤ ¤¤¤ Wpisy w Rejestrze : 9 ¤¤¤ [HJ POL][PUM] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> PODMIENIONO (2) [HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> PODMIENIONO (1) [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : ConsentPromptBehaviorAdmin (0) -> PODMIENIONO (2) [HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : EnableLUA (0) -> PODMIENIONO (1) [HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> PODMIENIONO (1) [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> PODMIENIONO (0) [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> PODMIENIONO (0) [HJ DLL][SUSP PATH] HKLM\[...]\CS001\[...]\Parameters : ServiceDll (C:\PROGRA~3\jwwhqft.pss [x]) -> PODMIENIONO (%SystemRoot%\system32\wbem\WMIsvc.dll) [HJ DLL][SUSP PATH] HKLM\[...]\CS003\[...]\Parameters : ServiceDll (C:\PROGRA~3\jwwhqft.pss [x]) -> PODMIENIONO (%SystemRoot%\system32\wbem\WMIsvc.dll) ¤¤¤ Zaplanowane zadania : 0 ¤¤¤ ¤¤¤ Wpisy startowe : 0 ¤¤¤ ¤¤¤ przeglądarki internetowe : 0 ¤¤¤ ¤¤¤ Pliki / Foldery: ¤¤¤ ¤¤¤ Sterownik : [NIEZAŁADOWANY 0x0] ¤¤¤ ¤¤¤ Gałąź rejestru (offline): ¤¤¤ ¤¤¤ Infekcja : ¤¤¤ ¤¤¤ Plik HOSTS: ¤¤¤ --> %SystemRoot%\System32\drivers\etc\hosts ¤¤¤ Sprawdzenie MBR: ¤¤¤ +++++ PhysicalDrive0: ( @ ) +++++ --- User --- [MBR] d1815c23947fea48ffcf44a419b98ed8 [BSP] 7a0d422f2ee53d30d5f30aa2d4e09760 : Windows 7/8 MBR Code Partition table: 0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo 1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 51098 Mo 2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 104855552 | Size: 254044 Mo User = LL1 ... OK! User = LL2 ... OK! +++++ PhysicalDrive1: ( @ ) +++++ --- User --- [MBR] aeb68c04bf2664376e5a2d48d7b943cf [BSP] 8d3009dbaf67dc7beb9ee93b2dbf44e1 : Windows XP MBR Code Partition table: 0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 95385 Mo 1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 195350400 | Size: 858481 Mo User = LL1 ... OK! User = LL2 ... OK! +++++ PhysicalDrive2: ( @ ) +++++ --- User --- [MBR] 68f1bead75f10df1c88947dffa83bac0 [BSP] 1df3f192b0fe43c6aad55bc03259b813 : Windows 7/8 MBR Code Partition table: 0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 102400 Mo 1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 209717248 | Size: 256000 Mo 2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 734005248 | Size: 204800 Mo 3 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 1153435648 | Size: 390667 Mo User = LL1 ... OK! User = LL2 ... OK! +++++ PhysicalDrive3: ( @ ) +++++ --- User --- [MBR] 3be98d2db478336e8043cb34b65e33c0 [BSP] 9644f9cb5fee2a86bdac43411a0331df : MBR Code unknown Partition table: 0 - [XXXXXX] FAT32 (0x0b) [VISIBLE] Offset (sectors): 8064 | Size: 1958 Mo User = LL1 ... OK! Error reading LL2 MBR! ([0x32] ??danie nie jest obs?ugiwane. ) Zakończono : << RKreport[0]_D_11282013_165623.txt >> RKreport[0]_S_11282013_165611.txt