Rkill 2.2.1 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 08/17/2012 12:16:09 PM in x64 mode.
Windows Version: Windows 7
Checking for Windows services to stop.
* No malware services found to stop.
Checking for processes to terminate.
* No malware processes found to kill.
Possibly Patched Files.
* C:\Windows\system32\services.exe
Checking Registry for malware related settings.
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks.
* ALERT: ZEROACCESS rootkit symptoms found!
* HKEY_CLASSES_ROOT\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32 [ZA Reg Hijack]
* C:\Users\User\AppData\Local\{10aa7b84-659b-5752-e27e-4d545101a798}\ [ZA Dir]
* C:\Users\User\AppData\Local\{10aa7b84-659b-5752-e27e-4d545101a798}\@ [ZA File]
* C:\Users\User\AppData\Local\{10aa7b84-659b-5752-e27e-4d545101a798}\L\ [ZA Dir]
* C:\Users\User\AppData\Local\{10aa7b84-659b-5752-e27e-4d545101a798}\L\00000004.@ [ZA File]
* C:\Users\User\AppData\Local\{10aa7b84-659b-5752-e27e-4d545101a798}\n [ZA File]
* C:\Users\User\AppData\Local\{10aa7b84-659b-5752-e27e-4d545101a798}\U\ [ZA Dir]
* C:\Users\User\AppData\Local\{10aa7b84-659b-5752-e27e-4d545101a798}\U\00000004.@ [ZA File]
* C:\Users\User\AppData\Local\{10aa7b84-659b-5752-e27e-4d545101a798}\U\00000008.@ [ZA File]
* C:\Users\User\AppData\Local\{10aa7b84-659b-5752-e27e-4d545101a798}\U\000000cb.@ [ZA File]
* C:\Users\User\AppData\Local\{10aa7b84-659b-5752-e27e-4d545101a798}\U\80000000.@ [ZA File]
* C:\Users\User\AppData\Local\{10aa7b84-659b-5752-e27e-4d545101a798}\U\80000032.@ [ZA File]
* C:\Users\User\AppData\Local\{10aa7b84-659b-5752-e27e-4d545101a798}\U\80000064.@ [ZA File]
* C:\Windows\installer\{10aa7b84-659b-5752-e27e-4d545101a798}\ [ZA Dir]
* C:\Windows\installer\{10aa7b84-659b-5752-e27e-4d545101a798}\@ [ZA File]
* C:\Windows\installer\{10aa7b84-659b-5752-e27e-4d545101a798}\L\ [ZA Dir]
* C:\Windows\installer\{10aa7b84-659b-5752-e27e-4d545101a798}\L\00000004.@ [ZA File]
* C:\Windows\installer\{10aa7b84-659b-5752-e27e-4d545101a798}\L\201d3dde [ZA File]
* C:\Windows\installer\{10aa7b84-659b-5752-e27e-4d545101a798}\n [ZA File]
* C:\Windows\installer\{10aa7b84-659b-5752-e27e-4d545101a798}\U\ [ZA Dir]
* C:\Windows\installer\{10aa7b84-659b-5752-e27e-4d545101a798}\U\00000004.@ [ZA File]
* C:\Windows\installer\{10aa7b84-659b-5752-e27e-4d545101a798}\U\00000008.@ [ZA File]
* C:\Windows\installer\{10aa7b84-659b-5752-e27e-4d545101a798}\U\000000cb.@ [ZA File]
* C:\Windows\installer\{10aa7b84-659b-5752-e27e-4d545101a798}\U\80000000.@ [ZA File]
* C:\Windows\installer\{10aa7b84-659b-5752-e27e-4d545101a798}\U\80000032.@ [ZA File]
* C:\Windows\installer\{10aa7b84-659b-5752-e27e-4d545101a798}\U\80000064.@ [ZA File]
* C:\Windows\assembly\GAC_32\Desktop.ini [ZA File]
* C:\Windows\assembly\GAC_64\Desktop.ini [ZA File]
Checking Windows Service Integrity:
* BFE [Missing Service]
* BITS [Missing Service]
* iphlpsvc [Missing Service]
* MpsSvc [Missing Service]
* WatAdminSvc [Missing Service]
* WinDefend [Missing Service]
* wscsvc [Missing Service]
* wuauserv [Missing Service]
* SharedAccess [Missing ImagePath]
Searching for Missing Digital Signatures:
* C:\Windows\System32\services.exe [NoSig]
+-> C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe : 328,704 : 07/13/2009 09:39 PM : 24acb7e5be595468e3b9aa488b9b4fcb [Pos Repl]
Program finished at: 08/17/2012 12:16:12 PM
Execution time: 0 hours(s), 0 minute(s), and 2 seconds(s)