_______________________________________________________________________________
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxSsVcZo93mDB3F8_v3WIoWxQQZYjCLQUzezOpHcUNOR3s9XYvuDn2fw-pbF66HqO2cAvk_RYvb-62tIk26ybaALSFuMspmg5i7NIgJ-izV2NLs9bjzEuDtXLyaIqHIe-eH3rIEAukPQs/s1600/rktigzy.gif) |
RogueKiller |
¤¤¤ Bad processes: 1 ¤¤¤
[SUSP PATH] 529C538A0010DF0D672037BFD151FC4E.exe -- C:\Documents and Settings\All Users\Application Data\529C538A0010DF0D672037BFD151FC4E\529C538A0010DF0D672037BFD151FC4E.exe -> KILLED [TermProc]
¤¤¤ Registry Entries: 4 ¤¤¤
[SUSP PATH] HKCU\[...]\RunOnce : 529C538A0010DF0D672037BFD151FC4E (C:\Documents and Settings\All Users\Application Data\529C538A0010DF0D672037BFD151FC4E\529C538A0010DF0D672037BFD151FC4E.exe) -> FOUND
[SUSP PATH] HKUS\S-1-5-21-1454471165-492894223-854245398-1003[...]\RunOnce : 529C538A0010DF0D672037BFD151FC4E (C:\Documents and Settings\All Users\Application Data\529C538A0010DF0D672037BFD151FC4E\529C538A0010DF0D672037BFD151FC4E.exe) -> FOUND
_________________________________________________________________________________
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKnXDxi1v5unAZQfvo0FXXSEzfoxZ5gpXmHlTmX-oUX244b36udHJF2JFRVkTckhuV-qZ_No98Fm0UkC8PlbCeDq6VZmqC2U3TtIlFE4KT57pBi5zf0ygtW_GihfRpHurNOBYv6TcuoBg/s1600/mbam.gif) |
MBAM |
Registry Keys Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
Live Security Platinum (Trojan.LameShield) -> Quarantined and deleted successfully.
Registry Values Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce|
529C538A0010DF0D672037BFD151FC4E (Trojan.LameShield) -> Data: C:\Documents and Settings\All Users\Application Data\529C538A0010DF0D672037BFD151FC4E\529C538A0010DF0D672037BFD151FC4E.exe -> Quarantined and deleted successfully.
Files Detected: 2
C:\Documents and Settings\All Users\Application Data\529C538A0010DF0D672037BFD151FC4E\
529C538A0010DF0D672037BFD151FC4E.exe (Trojan.LameShield) -> Quarantined and deleted successfully.
C:\Documents and Settings\thisisu\Desktop\
Live Security Platinum.lnk (Rogue.LiveSecurityPlatinum) -> Quarantined and deleted successfully.
_________________________________________________________________________________
Other traces:
Folder: C:\Documents and Settings\All Users\Application Data\
529C538A0010DF0D672037BFD151FC4E
Contains this file:
529C538A0010DF0D672037BFD151FC4E (no extension | 848 bytes)
Delete entire folder...
_________________________________________________________________________________