cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

ÿþRkill 2.7.0 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2015 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 04/29/2015 04:50:46 PM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 2

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* C:\WINDOWS\system32\HPZipm12.exe (PID: 320) [WD-HEUR]

1 proccess terminated!

Checking Registry for malware related settings:

* agentsvr.exe debugger. [IFEO Debugger Deleted]
* avp.exe debugger. [IFEO Debugger Deleted]
* ccSvcHst.exe debugger. [IFEO Debugger Deleted]
* hijackthis.exe debugger. [IFEO Debugger Deleted]
* scan32.exe debugger. [IFEO Debugger Deleted]
* symlcsvc.exe debugger. [IFEO Debugger Deleted]

Backup Registry file created at:
C:\Documents and Settings\ayoub\Bureau\rkill\rkill-04-29-2015-04-51-06.reg

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* No issues found.

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* HOSTS file entries found:

127.0.0.1 www.360.cn
127.0.0.1 www.360safe.cn
127.0.0.1 www.360safe.com
127.0.0.1 www.chinakv.com
127.0.0.1 www.rising.com.cn
127.0.0.1 rising.com.cn
127.0.0.1 dl.jiangmin.com
127.0.0.1 jiangmin.com
127.0.0.1 www.jiangmin.com
127.0.0.1 www.duba.net
127.0.0.1 www.eset.com.cn
127.0.0.1 www.nod32.com
127.0.0.1 shadu.duba.net
127.0.0.1 union.kingsoft.com
127.0.0.1 www.kaspersky.com.cn
127.0.0.1 kaspersky.com.cn
127.0.0.1 virustotal.com
127.0.0.1 virscan.org
127.0.0.1 www.virscan.org
127.0.0.1 www.kaspersky.com

20 out of 30 HOSTS entries shown.
Please review HOSTS file for further entries.

Program finished at: 04/29/2015 04:52:04 PM
Execution time: 0 hours(s), 1 minute(s), and 18 seconds(s)

Publicité


Signaler le contenu de ce document

Publicité