RogueKiller V12.6.4.0 (x64) [Sep 26 2016] (Free) door Adlice Software mail : http://www.adlice.com/contact/ Feedback : http://forum.adlice.com Website : http://www.adlice.com/download/roguekiller/ Blog : http://www.adlice.com Besturingssysteem : Windows 10 (10.0.10586) 64 bits version Gestart in : Normale mode Gebruiker : Jasper [Administrator] Started from : C:\Program Files\RogueKiller\RogueKiller64.exe Mode : Scan -- Datum : 09/30/2016 08:19:04 (Duration : 00:26:14) ¤¤¤ Processen : 2 ¤¤¤ [Suspicious.Path|VT.ADWARE/Mutabaha.uvnih] UvConverter.exe(2004) -- C:\ProgramData\UvConverter\UvConverter.exe[7] -> Gevonden [Suspicious.Path|VT.ADWARE/Mutabaha.uvnih] (SVC) UvConverter -- "C:\ProgramData\UvConverter\UvConverter.exe" {2C8E8C85-942B-451C-8243-97A089265577}[x] -> Gevonden ¤¤¤ Register : 37 ¤¤¤ [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484} (C:\Program Files\Reimage\Reimage Repair\REI_Axcontrol.dll) -> Gevonden [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB} (C:\Program Files\Reimage\Reimage Repair\REI_Axcontrol.dll) -> Gevonden [PUP] (X64) HKEY_LOCAL_MACHINE\Software\Reimage -> Gevonden [PUP] (X64) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\AutoTime -> Gevonden [PUP] (X64) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Installer -> Gevonden [PUP] (X64) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Reimage -> Gevonden [PUP] (X86) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\AutoTime -> Gevonden [PUP] (X86) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Installer -> Gevonden [PUP] (X86) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Reimage -> Gevonden [Suspicious.Path|VT.ADWARE/Mutabaha.uvnih] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UvConverter ("C:\ProgramData\UvConverter\UvConverter.exe" {2C8E8C85-942B-451C-8243-97A089265577}) -> Gevonden [Suspicious.Path|VT.ADWARE/Mutabaha.uvnih] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\UvConverter ("C:\ProgramData\UvConverter\UvConverter.exe" {2C8E8C85-942B-451C-8243-97A089265577}) -> Gevonden [PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.mylucky123.com/?type=hp&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden [PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.mylucky123.com/?type=hp&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.mylucky123.com/?type=hp&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.mylucky123.com/?type=hp&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden [PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://www.mylucky123.com/?type=hp&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden [PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://www.mylucky123.com/?type=hp&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://www.mylucky123.com/?type=hp&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://www.mylucky123.com/?type=hp&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden [PUM.SearchPage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.mylucky123.com/search/?type=ds&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626&q={searchTerms} -> Gevonden [PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.mylucky123.com/search/?type=ds&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626&q={searchTerms} -> Gevonden [PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.mylucky123.com/search/?type=ds&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626&q={searchTerms} -> Gevonden [PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.mylucky123.com/search/?type=ds&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626&q={searchTerms} -> Gevonden [PUM.SearchPage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Search_URL : http://www.mylucky123.com/search/?type=ds&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626&q={searchTerms} -> Gevonden [PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Search_URL : http://www.mylucky123.com/search/?type=ds&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626&q={searchTerms} -> Gevonden [PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Microsoft\Internet Explorer\Main | Default_Search_URL : http://www.mylucky123.com/search/?type=ds&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626&q={searchTerms} -> Gevonden [PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Microsoft\Internet Explorer\Main | Default_Search_URL : http://www.mylucky123.com/search/?type=ds&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626&q={searchTerms} -> Gevonden [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 192.168.1.254 213.75.63.75 213.75.63.76 ([-][Netherlands][-]) -> Gevonden [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 192.168.1.254 213.75.63.75 213.75.63.76 ([-][Netherlands][-]) -> Gevonden [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1e350320-181f-4b08-aad2-ba1e47e5903e} | DhcpNameServer : 192.168.1.254 213.75.63.75 213.75.63.76 ([-][Netherlands][-]) -> Gevonden [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{1e350320-181f-4b08-aad2-ba1e47e5903e} | DhcpNameServer : 192.168.1.254 213.75.63.75 213.75.63.76 ([-][Netherlands][-]) -> Gevonden [PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Gevonden [PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 0 -> Gevonden [PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Gevonden [PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3280333162-937765043-293338858-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 0 -> Gevonden [HJ.Browser] (X64) HKEY_LOCAL_MACHINE\Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command | (default) : C:\Program Files\Internet Explorer\iexplore.exe http://www.mylucky123.com/?type=sc&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden [HJ.Browser] (X86) HKEY_LOCAL_MACHINE\Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command | (default) : C:\Program Files\Internet Explorer\iexplore.exe http://www.mylucky123.com/?type=sc&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden ¤¤¤ Taken : 0 ¤¤¤ ¤¤¤ Bestanden : 6 ¤¤¤ [Hj.Shortcut][Bestand] C:\Users\Public\Desktop\Mozilla Firefox.lnk [LNK@] C:\PROGRA~2\MOZILL~1\firefox.exe http://www.mylucky123.com/?type=sc&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden [Hj.Shortcut][Bestand] C:\Users\Jasper\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [LNK@] C:\PROGRA~1\INTERN~1\iexplore.exe http://www.mylucky123.com/?type=sc&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden [Hj.Shortcut][Bestand] C:\Users\Jasper\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk [LNK@] C:\PROGRA~2\MOZILL~1\firefox.exe http://www.mylucky123.com/?type=sc&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden [Hj.Shortcut][Bestand] C:\Users\Jasper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk [LNK@] C:\PROGRA~1\INTERN~1\iexplore.exe http://www.mylucky123.com/?type=sc&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden [Hj.Shortcut][Bestand] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [LNK@] C:\PROGRA~2\MOZILL~1\firefox.exe http://www.mylucky123.com/?type=sc&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden [Hj.Shortcut][Bestand] C:\Users\Jasper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk [LNK@] C:\PROGRA~1\INTERN~1\iexplore.exe http://www.mylucky123.com/?type=sc&ts=1474619787&z=bb26d53921c5665e36d695egbz2m7z8q2g4tbmbbcb&from=che0812&uid=SAMSUNGXHD502HJ_S20BJ90ZA31626 -> Gevonden ¤¤¤ WMI : 0 ¤¤¤ ¤¤¤ Host-bestand : 0 ¤¤¤ ¤¤¤ Antirootkit : 0 (Driver: Geladen) ¤¤¤ ¤¤¤ Web Browsers : 0 ¤¤¤ ¤¤¤ MBR Check : ¤¤¤ +++++ PhysicalDrive0: SAMSUNG HD502HJ ATA Device +++++ --- User --- [MBR] 5caeaf20c337eab23a7a2ee22f2c7a8b [BSP] dec2ebfcbb2bf51820bf6a2eda524aa6 : Windows Vista/7/8|VT.Unknown MBR Code Partition table: 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 51428 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 2 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 105531392 | Size: 450 MB 3 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 106452992 | Size: 424960 MB User = LL1 ... OK User = LL2 ... OK +++++ PhysicalDrive1: SAMSUNG HD103SJ ATA Device +++++ --- User --- [MBR] 65d2a63e26bfd60f29cf9d3bf73dcd47 [BSP] 8eab4d8d4821cba46a72b324421f65e5 : Unknown|VT.Unknown MBR Code Partition table: 1 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 2048 | Size: 953867 MB User = LL1 ... OK User = LL2 ... OK +++++ PhysicalDrive2: Generic- Compact Flash USB Device +++++ Error reading User MBR! ([15] Het apparaat is niet klaar. ) Error reading LL1 MBR! NOT VALID! Error reading LL2 MBR! ([32] De aanvraag wordt niet ondersteund. ) +++++ PhysicalDrive3: Generic- SM/xD-Picture USB Device +++++ Error reading User MBR! ([15] Het apparaat is niet klaar. ) Error reading LL1 MBR! NOT VALID! Error reading LL2 MBR! ([32] De aanvraag wordt niet ondersteund. ) +++++ PhysicalDrive4: Generic- SD/MMC USB Device +++++ Error reading User MBR! ([15] Het apparaat is niet klaar. ) Error reading LL1 MBR! NOT VALID! Error reading LL2 MBR! ([32] De aanvraag wordt niet ondersteund. ) +++++ PhysicalDrive5: Generic- MS/MS-Pro USB Device +++++ Error reading User MBR! ([15] Het apparaat is niet klaar. ) Error reading LL1 MBR! NOT VALID! Error reading LL2 MBR! ([32] De aanvraag wordt niet ondersteund. )