Rkill 2.6.5 by Lawrence Abrams (Grinler) http://www.bleepingcomputer.com/ Copyright 2008-2014 BleepingComputer.com More Information about Rkill can be found at this link: http://www.bleepingcomputer.com/forums/topic308364.html Program started at: 02/20/2014 01:27:54 AM in x86 mode. (Safe Mode) Windows Version: Windows 7 Ultimate Service Pack 1 Checking for Windows services to stop: * No malware services found to stop. Checking for processes to terminate: * No malware processes found to kill. Checking Registry for malware related settings: * No issues found in the Registry. Backup Registry file created at: C:\Users\blade\Desktop\rkill\rkill-02-20-2014-01-27-54.reg Resetting .EXE, .COM, & .BAT associations in the Windows Registry. Performing miscellaneous checks: * System Restore Disabled [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = dword:00000001 Checking Windows Service Integrity: * (BFE) is not Running. Startup Type set to: * (CryptSvc) is not Running. Startup Type set to: * (Dhcp) is not Running. Startup Type set to: * (Dnscache) is not Running. Startup Type set to: * (EventSystem) is not Running. Startup Type set to: * (MpsSvc) is not Running. Startup Type set to: * (Netman) is not Running. Startup Type set to: * (PlugPlay) is not Running. Startup Type set to: * (RpcSs) is not Running. Startup Type set to: * (WinDefend) is not Running. Startup Type set to: * (Winmgmt) is not Running. Startup Type set to: * (wscsvc) is not Running. Startup Type set to: * (wuauserv) is not Running. Startup Type set to: * (AFD) is not Running. Startup Type set to: * (mpsdrv) is not Running. Startup Type set to: * (NetBT) is not Running. Startup Type set to: * (nsiproxy) is not Running. Startup Type set to: * (Tcpip) is not Running. Startup Type set to: * (tdx) is not Running. Startup Type set to: * lmhosts [Missing Parameters Key] * NlaSvc [Missing Parameters Key] * nsi [Missing Parameters Key] Searching for Missing Digital Signatures: * No issues found. Checking HOSTS File: * Cannot edit the HOSTS file. * Permissions could not be fixed. Use Hosts-perm.bat to fix permissions: http://www.bleepingcomputer.com/download/hosts-permbat/ * HOSTS file entries found: 127.0.0.1 localhost ::1 localhost 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1001namen.com 127.0.0.1 1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 20 out of 14885 HOSTS entries shown. Please review HOSTS file for further entries. Program finished at: 02/20/2014 01:29:40 AM Execution time: 0 hours(s), 1 minute(s), and 45 seconds(s)