{"id":10040,"date":"2021-12-05T02:48:01","date_gmt":"2021-12-05T02:48:01","guid":{"rendered":"https:\/\/lgildv5i97.onrocket.site\/answers\/?post_type=question&#038;p=10040"},"modified":"2021-12-05T02:48:28","modified_gmt":"2021-12-05T02:48:28","slug":"solved-ran-rogue-killer-and-found-pickerhost-exe","status":"publish","type":"question","link":"https:\/\/computing.net\/answers\/security\/ran-rogue-killer-and-found-pickerhostexe\/40739.html","title":{"rendered":"Solved Ran Rogue Killer And Found Pickerhost.exe"},"content":{"rendered":"<p>Ran Rogue Killer and Found Pickerhost.exe. Here are the logs. Should I be worried?<\/p>\n<p>RogueKiller Anti-Malware V13.1.4.0 (x64) [Feb 4 2019] (Free) by Adlice Software<br \/>\nmail : <a href=\"https:\/\/web.archive.org\/web\/20210119031151\/https:\/\/adlice.com\/contact\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/adlice.com\/contact\/<\/a><br \/>\nWebsite : <a href=\"https:\/\/web.archive.org\/web\/20210119031151\/https:\/\/adlice.com\/download\/roguekiller\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/adlice.com\/download\/rogueki&#8230;<\/a><br \/>\nOperating System : Windows 10 (10.0.17134) 64 bits<br \/>\nStarted in : Normal mode<br \/>\nUser : Bangk [Administrator]<br \/>\nStarted from : C:\\Program Files\\RogueKiller\\RogueKiller64.exe<br \/>\nSignatures : 20190204_072850, Driver : Loaded<br \/>\nMode : Standard Scan, Scan &#8212; Date : 2019\/02\/04 15:17:31 (Duration : 00:18:36)<br \/>\nSwitches : -refid 3<\/p>\n<p>\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4 Processes \u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4<br \/>\n[Proc.Hidden (Malicious)] PickerHost.exe (14324) &#8212; C:\\Windows\\System32\\PickerHost.exe -&gt; Found<\/p>\n<p>\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4 Process Modules \u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4<\/p>\n<p>\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4 Services \u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4<\/p>\n<p>\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4 Tasks \u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4<\/p>\n<p>\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4 Registry \u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4<\/p>\n<p>\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4 WMI \u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4<\/p>\n<p>\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4 Hosts File \u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4<\/p>\n<p>\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4 Files \u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4<\/p>\n<p>\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4 Web browsers \u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4\u00a4<\/p>\n<p># &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n# Malwarebytes AdwCleaner 7.2.7.0<br \/>\n# &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n# Build: 01-30-2019<br \/>\n# Database: 2019-01-31.3 (Cloud)<br \/>\n# Support: <a href=\"https:\/\/web.archive.org\/web\/20210119031151\/https:\/\/www.malwarebytes.com\/support\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/www.malwarebytes.com\/support<\/a><br \/>\n#<br \/>\n# &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n# Mode: Scan<br \/>\n# &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n# Start: 02-04-2019<br \/>\n# Duration: 00:00:36<br \/>\n# OS: Windows 10 Home<br \/>\n# Scanned: 31793<br \/>\n# Detected: 0<\/p>\n<p>***** [ Services ] *****<\/p>\n<p>No malicious services found.<\/p>\n<p>***** [ Folders ] *****<\/p>\n<p>No malicious folders found.<\/p>\n<p>***** [ Files ] *****<\/p>\n<p>No malicious files found.<\/p>\n<p>***** [ DLL ] *****<\/p>\n<p>No malicious DLLs found.<\/p>\n<p>***** [ WMI ] *****<\/p>\n<p>No malicious WMI found.<\/p>\n<p>***** [ Shortcuts ] *****<\/p>\n<p>No malicious shortcuts found.<\/p>\n<p>***** [ Tasks ] *****<\/p>\n<p>No malicious tasks found.<\/p>\n<p>***** [ Registry ] *****<\/p>\n<p>No malicious registry entries found.<\/p>\n<p>***** [ Chromium (and derivatives) ] *****<\/p>\n<p>No malicious Chromium entries found.<\/p>\n<p>***** [ Chromium URLs ] *****<\/p>\n<p>No malicious Chromium URLs found.<\/p>\n<p>***** [ Firefox (and derivatives) ] *****<\/p>\n<p>No malicious Firefox entries found.<\/p>\n<p>***** [ Firefox URLs ] *****<\/p>\n<p>No malicious Firefox URLs found.<\/p>\n<p>&nbsp;<\/p>\n<p>########## EOF &#8211; C:\\AdwCleaner\\Logs\\AdwCleaner[S00].txt ##########<\/p>\n<p>#<br \/>\n# &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n# Mode: Clean<br \/>\n# &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n# Start: 02-04-2019<br \/>\n# Duration: 00:00:10<br \/>\n# OS: Windows 10 Home<br \/>\n# Cleaned: 0<br \/>\n# Failed: 0<\/p>\n<p>***** [ Services ] *****<\/p>\n<p>No malicious services cleaned.<\/p>\n<p>***** [ Folders ] *****<\/p>\n<p>No malicious folders cleaned.<\/p>\n<p>***** [ Files ] *****<\/p>\n<p>No malicious files cleaned.<\/p>\n<p>***** [ DLL ] *****<\/p>\n<p>No malicious DLLs cleaned.<\/p>\n<p>***** [ WMI ] *****<\/p>\n<p>No malicious WMI cleaned.<\/p>\n<p>***** [ Shortcuts ] *****<\/p>\n<p>No malicious shortcuts cleaned.<\/p>\n<p>***** [ Tasks ] *****<\/p>\n<p>No malicious tasks cleaned.<\/p>\n<p>***** [ Registry ] *****<\/p>\n<p>No malicious registry entries cleaned.<\/p>\n<p>***** [ Chromium (and derivatives) ] *****<\/p>\n<p>No malicious Chromium entries cleaned.<\/p>\n<p>***** [ Chromium URLs ] *****<\/p>\n<p>No malicious Chromium URLs cleaned.<\/p>\n<p>***** [ Firefox (and derivatives) ] *****<\/p>\n<p>No malicious Firefox entries cleaned.<\/p>\n<p>***** [ Firefox URLs ] *****<\/p>\n<p>No malicious Firefox URLs cleaned.<\/p>\n<p>*************************<\/p>\n<p>[+] Delete Tracing Keys<br \/>\n[+] Reset Winsock<\/p>\n<p>*************************<\/p>\n<p>AdwCleaner[S00].txt &#8211; [1250 octets] &#8211; [04\/02\/2019 15:52:26]<\/p>\n<p>########## EOF &#8211; C:\\AdwCleaner\\Logs\\AdwCleaner[C00].txt ##########<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"iawp_total_views":1},"question-category":[56],"question_tags":[],"class_list":["post-10040","question","type-question","status-publish","hentry","question-category-security"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question\/10040","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question"}],"about":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/types\/question"}],"author":[{"embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/comments?post=10040"}],"wp:attachment":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/media?parent=10040"}],"wp:term":[{"taxonomy":"question-category","embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question-category?post=10040"},{"taxonomy":"question_tags","embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question_tags?post=10040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}