RogueKiller V8.1.1 [10/03/2012] by Tigzy mail: tigzyRKgmailcom Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/ Website: http://tigzy.geekstogo.com/roguekiller.php Blog: http://tigzyrk.blogspot.com Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version Started in : Normal mode User : Sebastian [Admin rights] Mode : Remove -- Date : 12/06/2012 12:50:26 ¤¤¤ Bad processes : 1 ¤¤¤ [SUSP PATH] kya.exe -- C:\Users\Sebastian\AppData\Local\kya.exe -> KILLED [TermProc] ¤¤¤ Registry Entries : 7 ¤¤¤ [Services][LOCK] HKLM\[...]\ControlSet001\Services\9a49435bf4aa1a0a -> DELETED [Services][LOCK] HKLM\[...]\ControlSet002\Services\9a49435bf4aa1a0a -> DELETED [HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED (2) [HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1) [SHELLSPWN] HKCU\[...]\command : ("C:\Users\Sebastian\AppData\Local\kya.exe" -a "%1" %*) -> REPLACED ("%1" %*) [FILEASSO] HKCR\[...].exe : (Oaf) -> REPLACED (exefile) [FILEASSO] HKLM\[...]\command : ("C:\Users\Sebastian\AppData\Local\kya.exe" -a "C:\Program Files (x86)\Internet Explorer\iexplore.exe") -> REPLACED ("C:\Program Files (x86)\Internet Explorer\iexplore.exe") ¤¤¤ Particular Files / Folders: ¤¤¤ ¤¤¤ Driver : [NOT LOADED] ¤¤¤ ¤¤¤ HOSTS File: ¤¤¤ --> C:\Windows\system32\drivers\etc\hosts ¤¤¤ MBR Check: ¤¤¤ +++++ PhysicalDrive0: ST9500325AS +++++ --- User --- [MBR] eae375182cf0f41236f26227643c6a74 [BSP] 7087c23d7853a72da84b815d2f9bfdd5 : Windows 7 MBR Code Partition table: 0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo 1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 476838 Mo User = LL1 ... OK! User = LL2 ... OK! Finished : << RKreport[2].txt >> RKreport[1].txt ; RKreport[2].txt