Format du document : text/plain


ÿþRkill 2.8.3 by Lawrence Abrams (Grinler)
Copyright 2008-2016 BleepingComputer.com
More Information about Rkill can be found at this link:

Program started at: 02/21/2016 09:41:15 PM in x86 mode.
Windows Version: Windows 10 Pro

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* C:\Windows\PromptService.exe (PID: 6772) [WD-HEUR]
* C:\Users\SAMIR\AppData\Roaming\uTorrent\updates\3.4.5_41712\utorrentie.exe (PID: 8080) [UP-HEUR]
* C:\Users\SAMIR\AppData\Roaming\uTorrent\updates\3.4.5_41712\utorrentie.exe (PID: 7008) [UP-HEUR]

3 proccesses terminated!

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* Windows Defender Disabled

[HKLM\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware" = dword:00000001

Checking Windows Service Integrity:

* b06bdrv [Missing Service]
* ebdrv [Missing Service]
* fcvsc [Missing Service]
* HdAudAddService [Missing Service]
* HyperVideo [Missing Service]
* iaLPSSi_GPIO [Missing Service]
* iaLPSSi_I2C [Missing Service]
* ibbus [Missing Service]
* ksthunk [Missing Service]
* mlx4_bus [Missing Service]
* ndfltr [Missing Service]
* netvsc [Missing Service]
* PerfHost [Missing Service]
* vpci [Missing Service]
* wfpcapture [Missing Service]
* WinMad [Missing Service]
* WinVerbs [Missing Service]

* CompositeBus => \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_x86_dd1d60cd48926252\CompositeBus.sys [Incorrect ImagePath]
* NetTcpPortSharing => %systemroot%\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [Incorrect ImagePath]
* NgcSvc => %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted [Incorrect ImagePath]
* swenum => \SystemRoot\System32\drivers\swenum.sys [Incorrect ImagePath]

* PrintNotify => C:\WINDOWS\system32\spool\drivers\W32X86\3\PrintConfig.dll [Incorrect ServiceDLL]

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* HOSTS file entries found: localhost
::1 localhost # fix for traceroute and netstat display anomaly tracking.opencandy.com.s3.amazonaws.com media.opencandy.com cdn.opencandy.com tracking.opencandy.com api.opencandy.com api.recommendedsw.com installer.betterinstaller.com installer.filebulldog.com d3oxtn1x3b8d7i.cloudfront.net inno.bisrv.com nsis.bisrv.com cdn.file2desktop.com cdn.goateastcach.us cdn.guttastatdk.us cdn.inskinmedia.com cdn.insta.oibundles2.com cdn.insta.playbryte.com

20 out of 37 HOSTS entries shown.
Please review HOSTS file for further entries.

Program finished at: 02/21/2016 09:42:48 PM
Execution time: 0 hours(s), 1 minute(s), and 33 seconds(s)


Signaler le contenu de ce document