Rooter.exe (v1.0.2) by Eric_71
.
The token does not have the SeDebugPrivilege privilege ! (error:1300)
Can not acquire SeDebugPrivilege !
Please run the tool as administrator ...
Windows 7 Home Edition (6.1.7601) Service Pack 1
[32_bits] - AMD64 Family 16 Model 6 Stepping 3, AuthenticAMD
.
Error OpenService (wscsvc) : 6
Error OpenSCManager : 5
Error OpenService (MpsSvc) : 6
Windows Defender -> Enabled
User Account Control (UAC) -> Enabled
.
Internet Explorer 9.0.8112.16421
.
C:\ [Fixed-NTFS] .. ( Total:283 Go - Free:209 Go )
D:\ [CD_Rom]
.
Scan : 20:51.43
Path : C:\Users\ShamRocks\Downloads\Rooter.exe
User : ShamRocks ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
Locked System (4)
Locked smss.exe (272)
Locked csrss.exe (388)
Locked wininit.exe (456)
Locked csrss.exe (488)
Locked services.exe (520)
Locked lsass.exe (540)
Locked lsm.exe (548)
Locked winlogon.exe (608)
Locked svchost.exe (700)
Locked svchost.exe (780)
Locked atiesrxx.exe (828)
Locked svchost.exe (904)
Locked svchost.exe (948)
Locked svchost.exe (996)
Locked svchost.exe (296)
Locked DockLogin.exe (796)
Locked svchost.exe (1028)
Locked atieclxx.exe (1132)
Locked spoolsv.exe (1332)
Locked svchost.exe (1368)
Locked armsvc.exe (1456)
Locked AERTSr64.exe (1500)
Locked mbamscheduler.exe (1548)
Locked mbamservice.exe (1588)
Locked SymcPCCULaunchSvc.exe (1616)
Locked svchost.exe (1752)
Locked svchost.exe (1784)
Locked WLIDSVC.EXE (1828)
Locked YahooAUService.exe (2016)
Locked SDWinSec.exe (1008)
Locked WLIDSVCM.EXE (1652)
Locked svchost.exe (2376)
Locked svchost.exe (2860)
Locked sprtsvc.exe (2088)
Locked wmpnetwk.exe (772)
Locked SearchIndexer.exe (660)
______
? (3260)
______ C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (3352)
______
? (3416)
______
? (3424)
______
? (3080)
______
? (2476)
______
? (3524)
______
? (3672)
______ C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (3932)
______ C:\Program Files (x86)\Your Own Screensaver\ScreenUpdate.exe (4020)
______ C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (3520)
______ C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe (3836)
______ C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (3712)
______ C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe (888)
Locked ApMsgFwd.exe (3864)
______
? (3644)
______
? (3440)
______
? (3664)
Locked svchost.exe (3576)
Locked dllhost.exe (4516)
______ C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe (4116)
______ C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (4508)
______ C:\Program Files (x86)\Windows Live\Mail\wlmail.exe (4300)
Locked audiodg.exe (4488)
______
? (4732)
______ C:\Program Files (x86)\Your Own Screensaver\servlnk.exe (2556)
______
? (4460)
Locked msiexec.exe (4164)
Locked VSSVC.exe (2940)
Locked svchost.exe (2076)
______
? (5240)
Locked WmiPrvSE.exe (1108)
______ C:\Program Files (x86)\Internet Explorer\iexplore.exe (5524)
______ C:\Program Files (x86)\Internet Explorer\iexplore.exe (5660)
______ C:\Program Files (x86)\Internet Explorer\iexplore.exe (4692)
______
? (5988)
Locked SearchFilterHost.exe (5312)
Locked SearchProtocolHost.exe (3772)
______ C:\Users\ShamRocks\Downloads\Rooter.exe (1816)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 (Start_Offset:1048576 | Length:104857600)
\Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:105906176 | Length:15728640000)
\Device\Harddisk0\Partition3 (Start_Offset:15834546176 | Length:304237338624)
.
----------------------\\ Scheduled Tasks
.
C:\Windows\Tasks\Adobe Flash Player Updater.job
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2943743425-2902513885-2954712797-1000Core.job
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2943743425-2902513885-2954712797-1000UA.job
C:\Windows\Tasks\ParetoLogic Registration3.job
C:\Windows\Tasks\ParetoLogic Update Version3 Startup Task.job
C:\Windows\Tasks\ParetoLogic Update Version3.job
C:\Windows\Tasks\RegCure Pro.job
C:\Windows\Tasks\SA.DAT
C:\Windows\Tasks\SCHEDLGU.TXT
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
----------------------\\ Scan completed at 20:51.46
.
C:\Rooter$\Rooter_2.txt - (27/11/2012 | 20:51.46)