تقرير
Rkill 2.7.0 by Lawrence Abrams (Grinler)
Copyright 2008-2015 BleepingComputer.com
More Information about Rkill can be found at this link:
Program started at: 01/08/2015 06:26:02 PM in x86 mode.
Windows Version: Windows 7 Ultimate Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Possibly Patched Files.
* C:\Windows\system32\winlogon.exe
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
* C:\Windows\System32\user32.dll : 812,032 : 11/19/2010 10:21 PM : cf97d64d7ec169c53c93b0a192218b29 [NoSig]
+-> C:\Windows\KJ\Pirate\P\SysWOW64P\user32.dll : 833,024 : 11/19/2010 10:08 PM : 5e0db2d8b2750543cd2ebb9ea8e6cdd3 [Pos Repl]
+-> C:\Windows\KJ\Pirate\P\x64P\user32.dll : 1,008,128 : 11/19/2010 11:27 PM : fe70103391a64039a921dbfff9c7ab1b [Pos Repl]
+-> C:\Windows\KJ\Pirate\P\x86P\user32.dll : 811,520 : 11/19/2010 10:21 PM : f1dd3acaee5e6b4bbc69bc6df75cef66 [Pos Repl]
+-> C:\Windows\KJ\Pirate\T\SysWOW64T\user32.dll : 833,024 : 11/19/2010 10:08 PM : 5e0db2d8b2750543cd2ebb9ea8e6cdd3 [Pos Repl]
+-> C:\Windows\KJ\Pirate\T\x64T\user32.dll : 1,008,640 : 01/16/2011 02:01 AM : 0b864e15a0badff0e7bb8b59009fddcf [Pos Repl]
+-> C:\Windows\KJ\Pirate\T\x86T\user32.dll : 812,032 : 11/19/2010 10:21 PM : cf97d64d7ec169c53c93b0a192218b29 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll : 811,520 : 11/20/2010 11:29 PM : f1dd3acaee5e6b4bbc69bc6df75cef66 [Pos Repl]
* C:\Windows\System32\winlogon.exe : 285,696 : 11/19/2010 10:17 PM : c3eb9ea34ebe459f13f3f890f56ce72a [NoSig]
+-> C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe : 286,720 : 11/20/2010 11:29 PM : 6d13e1406f50c66e2a95d97f22c47560 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18409_none_71da23b23327143c\winlogon.exe : 304,128 : 03/04/2014 11:17 AM : 998507b046ba314ce8245364c686fa67 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18540_none_71a5e34e334f9d18\winlogon.exe : 304,128 : 07/17/2014 03:39 AM : 52449fd429d6053b78ae564def303870 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22616_none_7255f1994c4f8119\winlogon.exe : 304,640 : 03/04/2014 12:39 AM : d53972f87d850cd2eb4b29b60cafdd77 [Pos Repl]
+-> C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22750_none_7224b2134c7555fa\winlogon.exe : 304,640 : 07/16/2014 04:56 AM : 4f37b93c14aee313bec52a23afb15c2e [Pos Repl]
Checking HOSTS File:
* No issues found.
Program finished at: 01/08/2015 06:27:48 PM
Execution time: 0 hours(s), 1 minute(s), and 46 seconds(s)