Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rkill 2.6.2 by Lawrence Abrams (Grinler)
- http://www.bleepingcomputer.com/
- Copyright 2008-2013 BleepingComputer.com
- More Information about Rkill can be found at this link:
- http://www.bleepingcomputer.com/forums/topic308364.html
- Program started at: 10/17/2013 08:17:12 PM in x64 mode.
- Windows Version: Windows 7 Home Premium Service Pack 1
- Checking for Windows services to stop:
- * No malware services found to stop.
- Checking for processes to terminate:
- * No malware processes found to kill.
- Checking Registry for malware related settings:
- * Explorer Policy Removed: NoActiveDesktopChanges [HKLM]
- Backup Registry file created at:
- C:\Users\Caleb's Computer\Desktop\rkill\rkill-10-17-2013-08-17-16.reg
- Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
- Performing miscellaneous checks:
- * Modified HKCU\...\Winlogon: [Shell] => C:\Users\Caleb's Computer\AppData\Roaming\dlc.xmm,explorer.exe
- * Windows Defender Disabled
- [HKLM\SOFTWARE\Microsoft\Windows Defender]
- "DisableAntiSpyware" = dword:00000001
- * Reparse Point/Junctions Found (These may be legitimate)!
- * C:\Windows\winsxs\amd64_security-malware-windows-defender-events_31bf3856ad364e35_6.1.7600.16385_none_118cf1dcd54a3dea\MpEvMsg.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MpAsDesc.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MpCmdRun.exe => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MpOAV.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MpRTP.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MSASCui.exe => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MsMpCom.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MsMpLics.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MsMpRes.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.18170_none_b59db7296f030a55\MpAsDesc.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.18170_none_b59db7296f030a55\MpClient.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.18170_none_b59db7296f030a55\MpCmdRun.exe => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.18170_none_b59db7296f030a55\MpCommu.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.18170_none_b59db7296f030a55\MpOAV.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.18170_none_b59db7296f030a55\MpRTP.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.18170_none_b59db7296f030a55\MpSvc.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.18170_none_b59db7296f030a55\MSASCui.exe => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.18170_none_b59db7296f030a55\MsMpCom.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.18170_none_b59db7296f030a55\MsMpLics.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.18170_none_b59db7296f030a55\MsMpRes.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.22341_none_b648c5e888076cca\MpAsDesc.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.22341_none_b648c5e888076cca\MpCmdRun.exe => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.22341_none_b648c5e888076cca\MpOAV.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.22341_none_b648c5e888076cca\MpRTP.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.22341_none_b648c5e888076cca\MSASCui.exe => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.22341_none_b648c5e888076cca\MsMpCom.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.22341_none_b648c5e888076cca\MsMpLics.dll => <Unknown Target> [File]
- * C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.22341_none_b648c5e888076cca\MsMpRes.dll => <Unknown Target> [File]
- Checking Windows Service Integrity:
- * Windows Firewall Authorization Driver (mpsdrv) is not Running.
- Startup Type set to: Manual
- * BFE [Missing Service]
- * iphlpsvc [Missing Service]
- * MpsSvc [Missing Service]
- * PcaSvc [Missing Service]
- * PolicyAgent [Missing Service]
- * RemoteAccess [Missing Service]
- * WinDefend [Missing Service]
- * wscsvc [Missing Service]
- * SharedAccess [Missing ImagePath]
- Searching for Missing Digital Signatures:
- * No issues found.
- Checking HOSTS File:
- * No issues found.
- Program finished at: 10/17/2013 08:18:30 PM
- Execution time: 0 hours(s), 1 minute(s), and 17 seconds(s)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement