Did as instructed. Couple things...after I hit delete, the second item on the list didn't say "deleted", it said :error[2]. Also, system did not restart. And I had to hit "report" manually.
Here is the report:
RogueKiller V10.0.2.0 [Oct 16 2014] by Adlice Software
mail :
www.adlice.com/contact/Feedback :
forum.adlice.comWebsite :
www.adlice.com/softwares/roguekiller/Blog :
www.adlice.comOperating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Safe mode with network support
User : Dan [Administrator]
Mode : Delete -- Date : 10/19/2014 22:11:46
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 11 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-1279983707-131282063-3389478783-1000\Software\Microsoft\Windows\CurrentVersion\Run | dknumzkfvbn : regsvr32.exe /s "C:\Users\Dan\AppData\Local\{3B98C378-6899-4F12-8C04-8B82556E203E}\dknumzkfvbn.dll" [7][x][-] -> Deleted
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-1279983707-131282063-3389478783-1000\Software\Microsoft\Windows\CurrentVersion\Run | dknumzkfvbn : regsvr32.exe /s "C:\Users\Dan\AppData\Local\{3B98C378-6899-4F12-8C04-8B82556E203E}\dknumzkfvbn.dll" -> ERROR [2]
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PAExec -> Deleted
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PAExec -> Deleted
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PAExec -> Deleted
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1279983707-131282063-3389478783-1000\Software\Microsoft\Internet Explorer\Main | Start Page :
www.comcast.net/ -> Not selected
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1279983707-131282063-3389478783-1000\Software\Microsoft\Internet Explorer\Main | Start Page :
www.comcast.net/ -> Not selected
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Not selected
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Not selected
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Not selected
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Not selected
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 0 [Too big!] ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000035f]) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD5000BEVT-60A0RT0 +++++
--- User ---
[MBR] e22ccaab23dff29fe13806a26a14f594
[BSP] f548284d067438a7441a59b4e71e8056 : Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 199 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 409600 | Size: 459217 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 940886016 | Size: 17419 MB
3 - [XXXXXX] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 976560128 | Size: 103 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: SD Card +++++
--- User ---
[MBR] 8a4a3f84a9eda68451f8bdccda84c484
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - [XXXXXX] FAT32 (0xb) [VISIBLE] Offset (sectors): 8192 | Size: 7576 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] The request is not supported. )
+++++ PhysicalDrive2: SanDisk Cruzer USB Device +++++
--- User ---
[MBR] 4a296257b22c19f9bfb72764b330eeb0
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - [XXXXXX] FAT32 (0xb) [VISIBLE] Offset (sectors): 44 | Size: 7655 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] The request is not supported. )
============================================
RKreport_SCN_10192014_193011.log