Rkill 2.3.3 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 08/27/2012 01:58:52 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1
Checking for Windows services to stop.
* No malware services found to stop.
Checking for processes to terminate.
* No malware processes found to kill.
Checking Registry for malware related settings.
* Explorer Policy Removed: NoActiveDesktopChanges [HKLM]
Backup Registry file created at:
C:\Users\Owner\Desktop\rkill\rkill-08-27-2012-01-59-17.reg
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks.
* SMTMP folder detected. Please see this link for more information:
http://www.bleepingcomputer.com/forums/topic405109.html
* ALERT: ZEROACCESS rootkit symptoms found!
* HKEY_CLASSES_ROOT\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32 [ZA Reg Hijack]
* C:\Users\Owner\AppData\Local\{cdd5370d-fae6-5b1b-7be1-1157b62c9d34}\ [ZA Dir]
* C:\Users\Owner\AppData\Local\{cdd5370d-fae6-5b1b-7be1-1157b62c9d34}\@ [ZA File]
* C:\Users\Owner\AppData\Local\{cdd5370d-fae6-5b1b-7be1-1157b62c9d34}\L\ [ZA Dir]
* C:\Users\Owner\AppData\Local\{cdd5370d-fae6-5b1b-7be1-1157b62c9d34}\L\00000004.@ [ZA File]
* C:\Users\Owner\AppData\Local\{cdd5370d-fae6-5b1b-7be1-1157b62c9d34}\U\ [ZA Dir]
* C:\Users\Owner\AppData\Local\{cdd5370d-fae6-5b1b-7be1-1157b62c9d34}\U\00000008.@ [ZA File]
* C:\Windows\installer\{cdd5370d-fae6-5b1b-7be1-1157b62c9d34}\ [ZA Dir]
* C:\Windows\installer\{cdd5370d-fae6-5b1b-7be1-1157b62c9d34}\@ [ZA File]
* C:\Windows\installer\{cdd5370d-fae6-5b1b-7be1-1157b62c9d34}\L\ [ZA Dir]
* C:\Windows\installer\{cdd5370d-fae6-5b1b-7be1-1157b62c9d34}\L\00000004.@ [ZA File]
* C:\Windows\installer\{cdd5370d-fae6-5b1b-7be1-1157b62c9d34}\L\1afb2d56 [ZA File]
* C:\Windows\installer\{cdd5370d-fae6-5b1b-7be1-1157b62c9d34}\U\ [ZA Dir]
* C:\Windows\installer\{cdd5370d-fae6-5b1b-7be1-1157b62c9d34}\U\00000004.@ [ZA File]
* C:\Windows\installer\{cdd5370d-fae6-5b1b-7be1-1157b62c9d34}\U\80000000.@ [ZA File]
* C:\Windows\installer\{cdd5370d-fae6-5b1b-7be1-1157b62c9d34}\U\80000064.@ [ZA File]
* C:\Windows\assembly\GAC_32\Desktop.ini [ZA File]
* C:\Windows\assembly\GAC_64\Desktop.ini [ZA File]
Checking Windows Service Integrity:
* Windows Firewall Authorization Driver (mpsdrv) is not Running.
Startup Type set to: Manual
* AppMgmt [Missing Service]
* BFE [Missing Service]
* CscService [Missing Service]
* iphlpsvc [Missing Service]
* MpsSvc [Missing Service]
* PeerDistSvc [Missing Service]
* UmRdpService [Missing Service]
* WinDefend [Missing Service]
* wscsvc [Missing Service]
* SharedAccess [Missing ImagePath]
Searching for Missing Digital Signatures:
* No issues found.
Program finished at: 08/27/2012 01:59:28 PM
Execution time: 0 hours(s), 0 minute(s), and 36 seconds(s)