Very nice. I use Rkill and Malwarebytes a lot for my work.
You should do this in safemode, not too hard to get in there.
Disable antivirus, or do it in safemode.
Some antivirus will detect Rkill as virus but I assure you, its not.
Also Silent, check out Emsisoft's Emergency Kit.
Amazing Portable antivirus scanner, has like 99.8% detection I believe.
Alright, and Dillpill, rkill might be detected as virus, but it's not. Try adding an exception to it on your anti-virus
Anyways I finished my scan and it picked up 3 viruses. Here's the log: Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org (http://www.malwarebytes.org)
Database version: 6443
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
2011-04-25 21:12:16
mbam-log-2011-04-25 (21-12-16).txt
Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 895149
Time elapsed: 2 hour(s), 13 minute(s), 57 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\Mathieu\AppData\Local\mdx.exe" -a "C:\Program Files (x86)\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\Mathieu\AppData\Local\mdx.exe" -a "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\Mathieu\AppData\Local\mdx.exe" -a "C:\Program Files (x86)\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
My log...
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org (http://www.malwarebytes.org)
Database version: 6449
Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514
4/26/2011 5:07:20 PM
mbam-log-2011-04-26 (17-07-12).txt
Scan type: Full scan (C:\|)
Objects scanned: 503959
Time elapsed: 1 hour(s), 35 minute(s), 35 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BLOCK_READER (Trojan.LdPinch) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\block_reader\DisplayName (Trojan.LdPinch) -> Value: DisplayName -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\program files (x86)\activision\modern warfare 2\bootstrap\iw4mp.exe (Trojan.MSIL.ND2) -> No action taken.
c:\program files (x86)\multi password recovery\MPR.exe (PUP.PasswordView) -> No action taken.
c:\Users\Gary\downloads\aiw-37a-10802\iw4mp.exe (Trojan.MSIL.ND2) -> No action taken.
c:\Users\Gary\downloads\call of duty4-razor1911+keygen and crack\rzr-cod4.exe (Trojan.Agent.CK) -> No action taken.
c:\program files (x86)\multi password recovery\block_reader.sys (Trojan.LdPinch) -> No action taken.
Some of the files are not actually malware, they're just some pingaz stuff ;)
Oh okay, that's totally norm- wait, what. OMFG HOLY SHIT SWEET JESUS
Eh, it's like guys watching lesbian pronz, the only problem was of the age ._.