rkill log
Rkill 2.6.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 04/09/2014 11:55:11 AM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 3
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* System Restore Disabled
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = dword:00000001
* ALERT: ZEROACCESS rootkit symptoms found!
* C:\Recycler\S-1-5-18\$a1d0c5961d66e3a4bb4dbce057b0ee27\ [ZA Dir]
* C:\Recycler\S-1-5-18\$a1d0c5961d66e3a4bb4dbce057b0ee27\@ [ZA File]
* C:\Recycler\S-1-5-18\$a1d0c5961d66e3a4bb4dbce057b0ee27\L\ [ZA Dir]
* C:\Recycler\S-1-5-18\$a1d0c5961d66e3a4bb4dbce057b0ee27\U\ [ZA Dir]
* C:\Recycler\S-1-5-18\$a1d0c5961d66e3a4bb4dbce057b0ee27\U\00000001.@ [ZA File]
* C:\RECYCLER\S-1-5-21-2420282109-1773090242-3309790634-1007\$a1d0c5961d66e3a4bb4dbce057b0ee27\ [ZA Dir]
* C:\RECYCLER\S-1-5-21-2420282109-1773090242-3309790634-1007\$a1d0c5961d66e3a4bb4dbce057b0ee27\@ [ZA File]
* C:\RECYCLER\S-1-5-21-2420282109-1773090242-3309790634-1007\$a1d0c5961d66e3a4bb4dbce057b0ee27\L\ [ZA Dir]
* C:\RECYCLER\S-1-5-21-2420282109-1773090242-3309790634-1007\$a1d0c5961d66e3a4bb4dbce057b0ee27\U\ [ZA Dir]
* Reparse Point/Junctions Found (Most likely legitimate)!
* C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a => C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492 [Dir]
* C:\WINDOWS\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler\v4.0_4.0.0.0__31bf3856ad364e35 => C:\WINDOWS\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5 [Dir]
Checking Windows Service Integrity:
* System Restore Service (srservice) is not Running.
Startup Type set to: Automatic
* System Restore Filter Driver (sr) is not Running.
Startup Type set to: Disabled
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
Program finished at: 04/09/2014 11:57:14 AM
Execution time: 0 hours(s), 2 minute(s), and 3 seconds(s)