You are on page 1of 2

Rkill 2.6.0 by Lawrence Abrams (Grinler) http://www.bleepingcomputer.com/ Copyright 2008-2013 BleepingComputer.

com More Information about Rkill can be found at this link: http://www.bleepingcomputer.com/forums/topic308364.html Program started at: 08/11/2013 12:48:39 AM in x86 mode. Windows Version: Microsoft Windows XP Service Pack 3 Checking for Windows services to stop: * No malware services found to stop. Checking for processes to terminate: * Your %Temp% folder is set to C:\Windows\Temp, which can be dangerous. Skippin g termination for this folder. * No malware processes found to kill. Checking Registry for malware related settings: * No issues found in the Registry. Resetting .EXE, .COM, & .BAT associations in the Windows Registry. Performing miscellaneous checks: * Windows Firewall Disabled [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolic y\StandardProfile] "EnableFirewall" = dword:00000000 * Reparse Point/Junctions Found (Most likely legitimate)! * C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4 .0.0.0__b03f5f7f11d50a3a => C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f 5f7f11d50a3a_4.0.0.0_x-ww_29b51492 [Dir] * C:\WINDOWS\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler\v4 .0_4.0.0.0__31bf3856ad364e35 => C:\WINDOWS\WinSxS\MSIL_Microsoft.Workflow.Compil er_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5 [Dir] Checking Windows Service Integrity: * NtmsSvc [Missing Service] * wscsvc [Missing Service] * Alerter [Missing ImagePath] * ERSvc [Missing ImagePath] * Messenger [Missing ImagePath] Searching for Missing Digital Signatures: * C:\WINDOWS\System32\mspmsnsv.dll : 27.136 : 05/11/2008 01:28 PM : c51b4a5c05a 5475708e3c81c7765b71d [NoSig] * C:\WINDOWS\System32\UxTheme.dll : 220.160 : 05/11/2008 01:29 PM : 60ec27b523f 189f955af4819cc392914 [NoSig] * C:\WINDOWS\System32\winlogon.exe : 497.664 : 01/09/2011 06:34 PM : 6be1d553cb

3551dc17692747d0c24aee [NoSig] +-> C:\WINDOWS\system32\dllcache\winlogon.exe : 497.664 : 01/09/2011 06:34 PM : 6be1d553cb3551dc17692747d0c24aee [Pos Repl] Checking HOSTS File: * HOSTS file entries found: 127.0.0.1 localhost

Program finished at: 08/11/2013 12:50:02 AM Execution time: 0 hours(s), 1 minute(s), and 23 seconds(s)

You might also like