RKILL LOG
Rkill 2.3.3 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 08/28/2012 10:32:43 PM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 3
Checking for Windows services to stop.
* No malware services found to stop.
Checking for processes to terminate.
* C:\WINDOWS\System32\WLTRYSVC.EXE (PID: 1456) [WD-HEUR]
* C:\WINDOWS\System32\bcmwltry.exe (PID: 1472) [WD-HEUR]
* C:\WINDOWS\system32\WLTRAY.exe (PID: 2196) [WD-HEUR]
3 proccesses terminated!
Checking Registry for malware related settings.
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
* HKCU\SOFTWARE\Classes\.exe "@" exists and is set to exefile!
* HKCU\SOFTWARE\Classes\.exe has been deleted!
* HKCU\SOFTWARE\Classes\exefile has been deleted!
* HKLM\Software\Classes\.com "@" has been changed to ComFile!
* HKLM\Software\Classes\.com "@"was reset to comfile!
Performing miscellaneous checks.
* No issues found.
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
* C:\WINDOWS\System32\drivers\ntfs.sys [NoSig]
+-> C:\WINDOWS\$hf_mig$\KB930916\SP2QFE\ntfs.sys : 574,976 : 02/09/2007 00:23 AM : 05ab81909514bfd69cbb1f2c147cf6b9 [Pos Repl]
+-> C:\WINDOWS\$NtServicePackUninstall$\ntfs.sys : 574,464 : 02/09/2007 00:10 AM : 19a811ef5f1ed5c926a028ce107ff1af [Pos Repl]
+-> C:\WINDOWS\$NtUninstallKB930916$\ntfs.sys : 574,592 : 08/04/2004 00:00 AM : b78be402c3f63dd55521f73876951cdd [Pos Repl]
+-> C:\WINDOWS\ServicePackFiles\i386\ntfs.sys : 574,976 : 04/13/2008 03:15 PM : 78a08dd6a8d65e697c18e1db01c5cdca [Pos Repl]
+-> C:\WINDOWS\system32\dllcache\ntfs.sys : 574,976 : 04/13/2008 03:15 PM : 78a08dd6a8d65e697c18e1db01c5cdca [Pos Repl]
* C:\WINDOWS\System32\Drivers\tcpip.sys [NoSig]
+-> C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys : 360,832 : 10/30/2007 00:53 AM : 64798ecfa43d78c7178375fcdd16d8c8 [Pos Repl]
+-> C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys : 360,960 : 06/20/2008 00:44 AM : 744e57c99232201ae98c49168b918f48 [Pos Repl]
+-> C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys : 361,600 : 06/20/2008 00:51 AM : 9aefa14bd6b182d61e3119fa5f436d3d [Pos Repl]
+-> C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys : 361,600 : 06/20/2008 00:59 AM : ad978a1b783b5719720cff204b666c8e [Pos Repl]
+-> C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys : 360,320 : 06/20/2008 00:45 AM : 2a5554fc5b1e04e131230e3ce035c3f9 [Pos Repl]
+-> C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys : 359,040 : 08/04/2004 00:00 AM : 9f4b36614a0fc234525ba224957de55c [Pos Repl]
+-> C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys : 361,344 : 04/13/2008 03:20 PM : 93ea8d04ec73a85db02eb8805988f733 [Pos Repl]
+-> C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys : 360,064 : 10/30/2007 01:20 PM : 90caff4b094573449a0872a0f919b178 [Pos Repl]
+-> C:\WINDOWS\ServicePackFiles\i386\tcpip.sys : 361,344 : 04/13/2008 03:20 PM : 93ea8d04ec73a85db02eb8805988f733 [Pos Repl]
+-> C:\WINDOWS\system32\dllcache\tcpip.sys : 361,600 : 06/20/2008 03:51 AM : 9aefa14bd6b182d61e3119fa5f436d3d [Pos Repl]
* C:\WINDOWS\System32\winlogon.exe [NoSig]
+-> C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe : 502,272 : 08/04/2004 01:00 AM : 01c3346c241652f43aed8e2149881bfe [Pos Repl]
+-> C:\WINDOWS\ServicePackFiles\i386\winlogon.exe : 507,904 : 04/13/2008 08:12 PM : ed0ef0a136dec83df69f04118870003e [Pos Repl]
+-> C:\WINDOWS\system32\dllcache\winlogon.exe : 507,904 : 01/21/2011 08:00 AM : 3f061815a6754c0a1c9bf3d78a14bb54 [Pos Repl]
* C:\WINDOWS\explorer.exe [NoSig]
+-> C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe : 1,033,216 : 06/13/2007 00:26 AM : 7712df0cdde3a5ac89843e61cd5b3658 [Pos Repl]
+-> C:\WINDOWS\$NtServicePackUninstall$\explorer.exe : 1,033,216 : 06/13/2007 01:23 AM : 97bd6515465659ff8f3b7be375b2ea87 [Pos Repl]
+-> C:\WINDOWS\$NtUninstallKB938828$\explorer.exe : 1,032,192 : 08/04/2004 01:00 AM : a0732187050030ae399b241436565e64 [Pos Repl]
+-> C:\WINDOWS\ServicePackFiles\i386\explorer.exe : 1,033,728 : 04/13/2008 08:12 PM : 12896823fb95bfb3dc9b46bcaedc9923 [Pos Repl]
+-> C:\WINDOWS\system32\dllcache\explorer.exe : 1,033,728 : 01/21/2011 08:01 AM : eaf851a4387da45e9ac48c89fae16a6c [Pos Repl]
Program finished at: 08/28/2012 10:36:24 PM
Execution time: 0 hours(s), 3 minute(s), and 41 seconds(s)