Rkill 2.9.1 by Lawrence Abrams (Grinler) http://www.bleepingcomputer.com/ Copyright 2008-2020 BleepingComputer.com More Information about Rkill can be found at this link: http://www.bleepingcomputer.com/forums/topic308364.html Program started at: 03/19/2020 06:14:13 PM in x64 mode. Windows Version: Windows 10 Pro Checking for Windows services to stop: * No malware services found to stop. Checking for processes to terminate: * No malware processes found to kill. Checking Registry for malware related settings: * No issues found in the Registry. Resetting .EXE, .COM, & .BAT associations in the Windows Registry. Performing miscellaneous checks: * Reparse Point/Junctions Found (Most likely legitimate)! * C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 => C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\INetCache\IE [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Local\Dane aplikacji => C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Local [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Local\Historia => C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Local\Microsoft\Windows\History [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 => C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Local\Microsoft\Windows\INetCache\IE [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Local\Microsoft\Windows\Temporary Internet Files => C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Local\Microsoft\Windows\INetCache [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Local\Tymczasowe pliki internetowe => C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Local\Microsoft\Windows\INetCache [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Roaming\Microsoft\Windows\Start Menu\Programy => C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\Cookies => C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Local\Microsoft\Windows\INetCookies [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\Dane aplikacji => C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Roaming [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\Documents\Moja muzyka => C:\Windows\ServiceProfiles\MSSQLSERVER\Music [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\Documents\Moje obrazy => C:\Windows\ServiceProfiles\MSSQLSERVER\Pictures [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\Documents\Moje wideo => C:\Windows\ServiceProfiles\MSSQLSERVER\Videos [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\Menu Start => C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Roaming\Microsoft\Windows\Start Menu [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\Moje dokumenty => C:\Windows\ServiceProfiles\MSSQLSERVER\Documents [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\NetHood => C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Roaming\Microsoft\Windows\Network Shortcuts [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\PrintHood => C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Roaming\Microsoft\Windows\Printer Shortcuts [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\Recent => C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Roaming\Microsoft\Windows\Recent [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\SendTo => C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Roaming\Microsoft\Windows\SendTo [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\Szablony => C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Roaming\Microsoft\Windows\Templates [Dir] * C:\Windows\ServiceProfiles\MSSQLSERVER\Ustawienia lokalne => C:\Windows\ServiceProfiles\MSSQLSERVER\AppData\Local [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Local\Dane aplikacji => C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Local [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Local\Historia => C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Local\Microsoft\Windows\History [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 => C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Local\Microsoft\Windows\INetCache\IE [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Local\Microsoft\Windows\Temporary Internet Files => C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Local\Microsoft\Windows\INetCache [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Local\Tymczasowe pliki internetowe => C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Local\Microsoft\Windows\INetCache [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Roaming\Microsoft\Windows\Start Menu\Programy => C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\Cookies => C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Local\Microsoft\Windows\INetCookies [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\Dane aplikacji => C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Roaming [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\Documents\Moja muzyka => C:\Windows\ServiceProfiles\SQLTELEMETRY\Music [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\Documents\Moje obrazy => C:\Windows\ServiceProfiles\SQLTELEMETRY\Pictures [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\Documents\Moje wideo => C:\Windows\ServiceProfiles\SQLTELEMETRY\Videos [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\Menu Start => C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Roaming\Microsoft\Windows\Start Menu [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\Moje dokumenty => C:\Windows\ServiceProfiles\SQLTELEMETRY\Documents [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\NetHood => C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Roaming\Microsoft\Windows\Network Shortcuts [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\PrintHood => C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Roaming\Microsoft\Windows\Printer Shortcuts [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\Recent => C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Roaming\Microsoft\Windows\Recent [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\SendTo => C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Roaming\Microsoft\Windows\SendTo [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\Szablony => C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Roaming\Microsoft\Windows\Templates [Dir] * C:\Windows\ServiceProfiles\SQLTELEMETRY\Ustawienia lokalne => C:\Windows\ServiceProfiles\SQLTELEMETRY\AppData\Local [Dir] Searching for Missing Digital Signatures: * No issues found. Checking HOSTS File: * No issues found. Program finished at: 03/19/2020 06:14:42 PM Execution time: 0 hours(s), 0 minute(s), and 28 seconds(s)