Windows Version: Microsoft Windows XP Service Pack 3
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\WINDOWS\system32\crypserv.exe (PID: 800) [WD-HEUR]
1 proccess terminated!
Checking Registry for malware related settings:
* Advanced Explorer Setting Removed: HideIcons [HKCU]
Backup Registry file created at:
C:\Documents and Settings\llllllllllllllllllll\Desktop\rkill\rkill-09-15-2012-06-07-10.reg
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* Windows Firewall Disabled
[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = dword:00000000
Checking Windows Service Integrity:
* DNS Client (Dnscache) is not Running.
Startup Type set to: Disabled
* Alerter [Missing Service]
* Browser [Missing Service]
* LanmanServer [Missing Service]
* lanmanworkstation [Missing Service]
* Messenger [Missing Service]
* Netlogon [Missing Service]
* NtLmSsp [Missing Service]
* RpcLocator [Missing Service]
* NetBIOS [Missing Service]
* Srv [Missing Service]
* HidServ [Missing ImagePath]
* atapi [Missing ImagePath]
* RpcSs => %SystemRoot%\system32\svchost.exe -k rpcss [Incorrect ImagePath]
Searching for Missing Digital Signatures:
* No issues found.
Program finished at: 09/15/2012 06:07:55 PM
Execution time: 0 hours(s), 0 minute(s), and 52 seconds(s)