For some reason, the attachments are not visible. :huh:
Those reports are not that long. Please post them in your reply.
I see, I'll try again, but I will copy and paste too
RogueKiller V8.5.2 [Feb 23 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback :
RogueKiller - Geeks to Go Forums
Website :
Download RogueKiller (Official website)
Blog :
Operating System : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User : MA [Admin rights]
Mode : Scan -- Date : 02/28/2013 00:44:59
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 21 ¤¤¤
[RUN][HJNAME] HKLM\[...]\Run : services (C:\Windows\System32\service\services.exe) [-] -> FOUND
[SHELL][HJNAME] HKCU\[...]\Winlogon : Shell (Explorer.exe, C:\Program Files\Microsoft Office\OFFICE11\services.exe) [x] -> FOUND
[SHELL][HJNAME] HKUS\S-1-5-21-916480305-4116812250-1633305016-1002[...]\Winlogon : Shell (Explorer.exe, C:\Program Files\Microsoft Office\OFFICE11\services.exe) [x] -> FOUND
[IFEO] HKLM\[...]\Acha.exe : Debugger (cmd.exe /c del) -> FOUND
[IFEO] HKLM\[...]\AmyMastura.exe : Debugger (cmd.exe /c del) -> FOUND
[IFEO] HKLM\[...]\BabyRina.exe : Debugger (cmd.exe /c del) -> FOUND
[IFEO] HKLM\[...]\cscript.exe : Debugger (rundll32.exe) -> FOUND
[IFEO] HKLM\[...]\csrsz.exe : Debugger (cmd.exe /c del) -> FOUND
[IFEO] HKLM\[...]\lsasc.exe : Debugger (cmd.exe /c del) -> FOUND
[IFEO] HKLM\[...]\registry.exe : Debugger (cmd.exe /c del) -> FOUND
[IFEO] HKLM\[...]\SMSSS.exe : Debugger (cmd.exe /c del) -> FOUND
[IFEO] HKLM\[...]\wscript.exe : Debugger (rundll32.exe) -> FOUND
[HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
[HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> FOUND
[HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> FOUND
[HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowRun (0) -> FOUND
[HJ DESK] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MK1637GSX +++++
--- User ---
[MBR] b739d36b56c616b76179169ecf90415f
[BSP] 72792323cfdb9207152184d81c488be0 : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 7737 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 15847424 | Size: 144888 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive1: ST9250410AS +++++
--- User ---
[MBR] 056071b24f7a67e0fc429ce4ab4e6818
[BSP] a5f700b9f108fb7c4b640dfc5601ee5c : MBR Code unknown
Partition table:
0 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 16065 | Size: 238464 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[1]_S_02282013_02d0044.txt >>
Farbar Service Scanner Version: 20-02-2013
Ran by MA (administrator) on 28-02-2013 at 00:50:41
Running from "D:\Internet\SoftwareDownLoad\WindowsVista-Security Sevice Center Can't be Started"
Windows Vista (TM) Home Premium Service Pack 2 (X86)
Boot Mode: Normal
Internet Services:
Connection Status:
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
Firewall Disabled Policy:
System Restore:
System Restore Disabled Policy:
Security Center:
wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is set to Disabled. The default start type is Auto.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.
Checking LEGACY_wscsvc: ATTENTION!=====> Unable to open LEGACY_wscsvc\0000 registry key. The key does not exist.
Windows Update:
Windows Autoupdate Disabled Policy:
Windows Defender:
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Disabled. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.
Windows Defender Disabled Policy:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
Other Services:
File Check:
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcsvc.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll => MD5 is legit
C:\Windows\system32\qmgr.dll => MD5 is legit
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\system32\ipnathlp.dll => MD5 is legit
C:\Windows\system32\iphlpsvc.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
**** End of log ****