This is the RKill log from 09/10/14;
Rkill 2.6.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 02/09/2014 09:58:49 PM in x86 mode.
Windows Version: Windows Vista (TM) Home Basic Service Pack 2
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* Windows Firewall Disabled
[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = dword:00000000
* ALERT: ZEROACCESS rootkit symptoms found!
* C:\Users\Bev\AppData\Local\{2ee9930a-52c8-0f2f-2ea3-d7c248d7e63d}\ [ZA Dir]
* C:\Users\Bev\AppData\Local\{2ee9930a-52c8-0f2f-2ea3-d7c248d7e63d}\L\ [ZA Dir]
* C:\Users\Bev\AppData\Local\{2ee9930a-52c8-0f2f-2ea3-d7c248d7e63d}\U\ [ZA Dir]
Checking Windows Service Integrity:
* Windows Defender (WinDefend) is not Running.
Startup Type set to: Manual
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
Program finished at: 02/09/2014 09:59:45 PM
Execution time: 0 hours(s), 0 minute(s), and 56 seconds(s)

