Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rkill 2.4.7 by Lawrence Abrams (Grinler)
- http://www.bleepingcomputer.com/
- Copyright 2008-2013 BleepingComputer.com
- More Information about Rkill can be found at this link:
- http://www.bleepingcomputer.com/forums/topic308364.html
- Program started at: 02/21/2013 10:00:16 AM in x64 mode.
- Windows Version: Windows 7 Enterprise
- Checking for Windows services to stop:
- * No malware services found to stop.
- Checking for processes to terminate:
- * No malware processes found to kill.
- Possibly Patched Files.
- * C:\Windows\system32\winlogon.exe
- * C:\Windows\system32\winlogon.exe
- Checking Registry for malware related settings:
- * No issues found in the Registry.
- Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
- Performing miscellaneous checks:
- * No issues found.
- Checking Windows Service Integrity:
- * No issues found.
- Searching for Missing Digital Signatures:
- * C:\Windows\System32\user32.dll [NoSig]
- +-> C:\Windows\SysWOW64\user32.dll : 833 024 : 11/20/2012 11:46 PM : 167001177321d292ede6941f4cb8c140 [Pos Repl]
- +-> C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll : 1 008 640 : 07/14/2009 00:41 AM : 72d7b3ea16946e8f0cf7458150031cc6 [Pos Repl]
- +-> C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll : 833 024 : 07/14/2009 00:11 AM : e8b0ffc209e504cb7e79fc24e6c085f0 [Pos Repl]
- * C:\Windows\System32\winlogon.exe [NoSig]
- +-> C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe : 389 120 : 07/14/2009 00:39 AM : 132328df455b0028f13bf0abee51a63a [Pos Repl]
- +-> C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe : 389 632 : 10/28/2009 00:24 AM : da3e2a6fa9660cc75b471530ce88453a [Pos Repl]
- +-> C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe : 389 632 : 10/28/2009 00:01 AM : a93d41a4d4b0d91c072d11dd8af266de [Pos Repl]
- Checking HOSTS File:
- * No issues found.
- Program finished at: 02/21/2013 10:01:23 AM
- Execution time: 0 hours(s), 1 minute(s), and 6 seconds(s)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement