I'm currently having an issue with internet explorer. AnytimeI got to google or yahoo search and type in something to search bar it keeps redirecting me to different websites. I have ran malware bytes and also superanti spyware nothing is detected. I have attached the hijack this log file. If you can let me know what I should get rid of thank you.
Run a MS config, startup, Â disable all, reboot. Check for the issue. if it goes away, you have something in your startup that's hijacking your PC. If it doesnt. What website is it sending you to?
RohitBagchi
Hey there,
You seem to have inadvertently installed some malware. Hope your virus protection is upto par. In any case, to recover normal functioning, follow the steps detailed here :
are u in a domain environment if so may be your network admin implement policy to redirect you. If this is not the case check with any other browser like firefox, opera or safari. Run combo fix on your system. Run Super antispyware and most of all restore your system to the previous restore date when it was working fine.
msconfig is completly cleaned out restarted computer, Also cleaned my host file. Ran antimalware bytes, superantispyware, adware, spyware doctor nothing they find nothing infected in the system. I have a feeling its is these 4 items.
Though I don't know if its safe to remove these items coul somebody shed some light on the subject to see if that is whats causing my problem. thank you
OxygenITSolutions
Try Winpatrol. It will tell you what starts when IE opens. A great troubleshooting software, I have used it for many years.
*******You'll want to export the registry keys before you delete them  just in case*******
Im about 99% sure the baahzri.dll is whats killing your box. Boot to safe mode, regedit, edit, find  baahzri.dll in your entire regisrty , delete the dll registry entry that points to baahzri.dll. Also search for the shhrubob.exe in your registry,
also go to a command prompt. Change to C:\DOCUME~1\SHIRLE~1.RAN\LOCALS~1\Temp\
do a attrib -a *.*
dir
delete *.*
Y
reboot
I'm also about 99% sure that is whats causing the issue. If it help what happens is when you got to type in to go to a website it will come up and say website found then it will pause then at the bottom it will say redirecting then it just brings up random websites that have nothing to do with what I'm looking for. I've googled both of those programs nothing comes up whats the best way to save everything before I delete it.
Marcus Capps
You can create a restore point in safemode.
jrvzoom
try downloading mozilla firefox from another computer, install it on your computer, and then while in it go to http://onecare.live.com/site/en-us/default.htm and run a full scan. It will go for a couple of hours, this spyware/virus/etc. remover is updated daily and does a pretty good job for a lot of things.
Sounds like the TDSS rootkit. Â Hitman Pro claims to be able to remove it.
optoma
HitmanPro(as mentioned) is fairly good at detecting patched system files and does replace it, if found. Just make note of what it detects(just in case!)
u know i had an desktop that was severely infected with trojans and spyware here is what i did
booted system in "safe mode with command prompt" installed two programs spybot search and destroy and avira antivirus and great thing is they are both free run both software"s own scans cleaned all infections then went to msconfig-->startup deleted all unnecessary entries there.
 after that i run an chkdsk(scandisk) command on all partitions like this chkdsk e: on system drive which is C: it scanned the system on boot this made file system performance better.If u have time run Disk Defragmentation also from system tools.
and at last resort just change yours browser also IE is know as an weak browser shift to opera.
You are correct in believing those four HijackThis entries are the reason but unfortunately HJT will be unable to remove them....particularly this one>
O20 - Winlogon Notify: ttdxvxio - C:\WINDOWS\SYSTEM32\baahzri.dll
ComboFix may well resolve the problem(as already suggested), but before running it in Normal mode, please ensure you disable realtime Anti-virus &Â Anti-spyware scanners.
Also it may be necessary to rename ComboFix.exe (to Combo-Fix.exe for example), before saving it to your desktop. Â If you have difficulties downloading it, try downloading to another machine, then into a USB memory stick or CD. Â Rename it and carry to the infected machine, then try this key combination to reach a Run box>
Windows Logo+R: Run dialog box
As mentioned by others on this post run combofix from bleeping computers
this WILL fix your problem
thinktechsolutions
ASKER
Here is the combo log file. I also ran the tddskiller first then combo fix here is what it has
ComboFix 10-02-20.03 - shirley 02/20/2010 Â 19:51:40.1.2 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.3070.2119 [GMT -5:00]
Running from: c:\documents and settings\Shirley.RANDAZZOBUILDER\Desktop\ComboFix.exe
AV: Symantec Endpoint Protection *On-access scanning disabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
.
(((((((((((((((((((((((((((((((((((((((  Other Deletions  )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\awiqoboxebo.dll
c:\windows\system32\11478.exe
c:\windows\system32\15724.exe
c:\windows\system32\16827.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\23281.exe
c:\windows\system32\24464.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\28145.exe
c:\windows\system32\29358.exe
c:\windows\system32\2995.exe
c:\windows\system32\491.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\9961.exe
c:\windows\system32\baahzri.dll
c:\windows\system32\drivers\1028_DELL_XPS_Dell DM061 Â Â Â Â Â Â Â Â Â .MRK
c:\windows\system32\drivers\DELL_XPS_Dell DM061 Â Â Â Â Â Â Â Â Â .MRK
c:\windows\system32\drivers\qwtvbgie.sys
c:\windows\system32\drivers\vhuynune.sys
c:\windows\system32\kanxfeyw.dll
c:\windows\system32\nfr.assembly
c:\windows\system32\nfr.gpref
c:\windows\system32\ywvkhkw.dll
c:\windows\Tasks\At1.job
c:\windows\Tasks\bchimykr.job
.
(((((((((((((((((((((((((((((((((((((((  Drivers/Services  )))))))))))))))))))))))))))))))))))))))))))))))))
.
((((((((((((((((((((((((( Â Files Created from 2010-01-21 to 2010-02-21 Â )))))))))))))))))))))))))))))))
.
2010-02-21 01:16 . 2010-02-21 01:16 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\windows\LastGood
2010-02-19 16:14 . 2010-02-19 15:25 Â Â Â Â Â 15880 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\lsdelete.exe
2010-02-19 15:23 . 2010-02-19 15:23 Â Â Â Â Â -------- Â Â Â Â Â dc-h--w- Â Â Â Â Â c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-02-19 15:23 . 2010-02-04 15:53 Â Â Â Â Â 2954656 Â Â Â Â Â -c--a-w- Â Â Â Â Â c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-02-19 15:23 . 2010-02-19 15:25 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\documents and settings\All Users\Application Data\Lavasoft
2010-02-19 15:23 . 2010-02-19 15:23 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\program files\Lavasoft
2010-02-18 05:52 . 2010-02-18 05:52 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2010-02-18 05:51 . 2010-02-18 05:50 Â Â Â Â Â 38784 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\documents and settings\Shirley.RANDAZZOBUILDER\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-18 05:51 . 2010-02-18 05:50 Â Â Â Â Â 38784 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-18 05:51 . 2010-02-18 05:51 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\program files\Common Files\Adobe AIR
2010-02-18 05:49 . 2010-02-18 05:49 Â Â Â Â Â 86016 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-02-18 05:48 . 2010-02-18 06:30 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\documents and settings\All Users\Application Data\NOS
2010-02-17 13:54 . 2007-07-04 00:59 Â Â Â Â Â 86824 Â Â Â Â Â ----a-r- Â Â Â Â Â c:\windows\system32\drivers\sscdserd.sys
2010-02-17 13:54 . 2007-07-04 00:58 Â Â Â Â Â 106792 Â Â Â Â Â ----a-r- Â Â Â Â Â c:\windows\system32\drivers\sscdmdm.sys
2010-02-17 13:54 . 2007-07-04 00:57 Â Â Â Â Â 11944 Â Â Â Â Â ----a-r- Â Â Â Â Â c:\windows\system32\drivers\sscdmdfl.sys
2010-02-17 13:54 . 2007-07-04 00:56 Â Â Â Â Â 9256 Â Â Â Â Â ----a-r- Â Â Â Â Â c:\windows\system32\drivers\sscdcmnt.sys
2010-02-17 13:54 . 2007-07-04 00:56 Â Â Â Â Â 9256 Â Â Â Â Â ----a-r- Â Â Â Â Â c:\windows\system32\drivers\sscdcm.sys
2010-02-17 13:54 . 2007-07-04 01:00 Â Â Â Â Â 9256 Â Â Â Â Â ----a-r- Â Â Â Â Â c:\windows\system32\drivers\sscdwhnt.sys
2010-02-17 13:54 . 2007-07-04 01:00 Â Â Â Â Â 9256 Â Â Â Â Â ----a-r- Â Â Â Â Â c:\windows\system32\drivers\sscdwh.sys
2010-02-17 13:54 . 2007-07-04 00:54 Â Â Â Â Â 80552 Â Â Â Â Â ----a-r- Â Â Â Â Â c:\windows\system32\drivers\sscdbus.sys
2010-02-17 02:48 . 2010-02-17 02:48 Â Â Â Â Â 52224 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\documents and settings\Shirley.RANDAZZOBUILDER\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-02-17 02:48 . 2010-02-18 05:07 Â Â Â Â Â 117760 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\documents and settings\Shirley.RANDAZZOBUILDER\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-17 02:47 . 2010-02-17 02:47 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\program files\SUPERAntiSpyware
2010-02-17 02:47 . 2010-02-17 02:47 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\program files\Common Files\Wise Installation Wizard
2010-02-16 19:02 . 2008-04-13 19:45 Â Â Â Â Â 31744 Â Â Â Â Â -c--a-w- Â Â Â Â Â c:\windows\system32\dllcache\wceusbsh.sys
2010-02-16 19:02 . 2008-04-13 19:45 Â Â Â Â Â 31744 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\drivers\wceusbsh.sys
2010-02-16 16:37 . 2010-01-07 21:07 Â Â Â Â Â 38224 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-16 16:37 . 2010-01-07 21:07 Â Â Â Â Â 19160 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\drivers\mbam.sys
2010-02-15 12:34 . 2010-02-15 12:34 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\documents and settings\Shirley.RANDAZZOBUILDER\Local Settings\Application Data\{1DAF83B5-A7ED-4E13-859F-DDEC679E502E}
2010-02-10 13:18 . 2009-10-30 16:11 Â Â Â Â Â 233136 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\drivers\pctgntdi.sys
2010-02-10 13:18 . 2009-11-09 16:20 Â Â Â Â Â 207792 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\drivers\PCTCore.sys
2010-02-10 13:18 . 2009-10-06 21:31 Â Â Â Â Â 87784 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\drivers\PCTAppEvent.sys
2010-02-10 13:18 . 2009-09-03 14:45 Â Â Â Â Â 70408 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\drivers\pctplsg.sys
2010-02-10 13:18 . 2010-02-20 15:01 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\program files\Spyware Doctor
2010-02-10 13:18 . 2010-02-10 13:26 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\program files\Common Files\PC Tools
2010-02-10 13:18 . 2010-02-10 13:18 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\documents and settings\Shirley.RANDAZZOBUILDER\Application Data\PC Tools
2010-02-10 13:18 . 2010-02-10 13:18 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\documents and settings\All Users\Application Data\PC Tools
2010-02-10 13:17 . 2010-02-20 15:25 Â Â Â Â Â -------- Â Â Â Â Â d---a-w- Â Â Â Â Â c:\documents and settings\All Users\Application Data\TEMP
2010-02-10 03:36 . 2010-02-10 03:36 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-10 03:36 . 2010-02-17 02:47 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\documents and settings\Shirley.RANDAZZOBUILDER\Application Data\SUPERAntiSpyware.com
2010-02-02 12:52 . 2010-02-16 13:27 Â Â Â Â Â 0 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\Qqunadom.bin
2010-02-02 12:52 . 2010-02-16 22:18 Â Â Â Â Â 120 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\Lpawesugunep.dat
2010-01-23 17:48 . 2010-01-23 17:48 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\documents and settings\LocalService\Local Settings\Application Data\LogMeIn
2010-01-23 17:19 . 2010-01-23 17:19 Â Â Â Â Â 160288 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\drivers\afcdp.sys
2010-01-23 17:18 . 2010-01-23 17:18 Â Â Â Â Â 911680 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\drivers\tdrpm258.sys
2010-01-23 17:17 . 2010-01-23 17:17 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\program files\Acronis
.
((((((((((((((((((((((((((((((((((((((((  Find3M Report  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-21 01:11 . 2007-11-20 14:51 Â Â Â Â Â 12 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\bthservsdp.dat
2010-02-20 19:09 . 2007-12-20 14:12 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\documents and settings\All Users\Application Data\Google Updater
2010-02-20 15:39 . 2004-08-04 12:00 Â Â Â Â Â 96512 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\drivers\atapi.sys
2010-02-20 13:21 . 2009-09-09 22:27 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\program files\LogMeIn
2010-02-19 15:24 . 2007-04-02 10:31 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\program files\Google
2010-02-16 18:51 . 2009-01-28 21:32 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\program files\Malwarebytes' Anti-Malware
2010-02-04 15:53 . 2010-02-19 15:25 Â Â Â Â Â 64288 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\drivers\Lbd.sys
2010-01-23 18:31 . 2007-03-04 23:02 Â Â Â Â Â 2469216 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\AutoPartNt.exe
2010-01-23 17:19 . 2007-03-04 22:52 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\program files\Common Files\Acronis
2010-01-23 17:18 . 2007-03-04 22:52 Â Â Â Â Â 581984 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\drivers\timntr.sys
2010-01-23 17:18 . 2007-03-04 22:52 Â Â Â Â Â 158272 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\drivers\snapman.sys
2010-01-23 16:59 . 2008-01-29 18:45 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\program files\Desktop Alert
2010-01-12 22:27 . 2010-01-12 22:27 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\documents and settings\All Users\Application Data\LogMeIn
2010-01-07 01:03 . 2010-01-07 01:03 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\program files\WinSCP
2010-01-05 10:00 . 2004-08-04 12:00 Â Â Â Â Â 832512 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2009-08-29 19:45 Â Â Â Â Â 78336 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-04 12:00 Â Â Â Â Â 17408 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\corpol.dll
2010-01-01 05:00 . 2007-04-02 11:10 Â Â Â Â Â -------- Â Â Â Â Â d-----w- Â Â Â Â Â c:\program files\Belkin Bulldog Plus
2009-12-03 21:59 . 2008-07-21 16:48 Â Â Â Â Â 149768 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\drivers\WpsHelper.sys
.
(((((((((((((((((((((((((((((((((((((  Reg Loading Points  ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries &Â legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 Â Â Â Â Â 548352 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist Express Customer]
2009-11-19 02:30 Â Â Â Â Â 147832 Â Â Â Â Â ------w- Â Â Â Â Â c:\program files\Citrix\GoToAssist Express Customer\209\g2ax_winlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-09-29 00:34 Â Â Â Â Â 87352 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\LMIinit.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-12 02:16 Â Â Â Â Â 39792 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 00:12 Â Â Â Â Â 110592 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
2008-07-21 16:48 Â Â Â Â Â 115560 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ComponentsNatural]
2010-02-16 14:35 Â Â Â Â Â 128000 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Common Files\Microsoft Shared\PROOF\3082\msgr3esNatural.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 Â Â Â Â Â 15360 Â Â Â Â Â ------w- Â Â Â Â Â c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eFax 4.3]
2007-03-06 17:21 Â Â Â Â Â 116224 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\eFax Messenger 4.3\J2GDllCmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoToAssist Express Expert]
2009-11-22 21:42 Â Â Â Â Â 149368 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Citrix\GoToAssist Express Expert\209\g2ax_start.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
2002-03-18 11:00 Â Â Â Â Â 188416 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\spool\drivers\w32x86\3\hpztsb05.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InstallShieldObject]
2010-02-16 14:35 Â Â Â Â Â 128000 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Common Files\InstallShield\Professional\RunTime\ObjectInstallShield.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
2007-02-05 23:52 Â Â Â Â Â 849280 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Microsoft IntelliPoint\ipoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
2009-11-18 17:47 Â Â Â Â Â 1243088 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Spyware Doctor\pctsTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-08-12 11:30 Â Â Â Â Â 249856 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-08-12 11:30 Â Â Â Â Â 81920 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2008-03-30 14:36 Â Â Â Â Â 267048 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
2008-08-11 17:41 Â Â Â Â Â 63048 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\LogMeIn\x86\LogMeInSystray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MicrosoftMicrosoft2.05.50727.210.0507272100]
2010-02-16 14:35 Â Â Â Â Â 128000 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Common Files\Microsoft Shared\Help\2052\HXDSUIMicrosoft2.05.50727.210.0507272100.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msgr3esLanguage]
2010-02-16 14:35 Â Â Â Â Â 128000 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Common Files\Microsoft Shared\PROOF\3082\msgr3esNatural.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 Â Â Â Â Â 1695232 Â Â Â Â Â ------w- Â Â Â Â Â c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-06-16 15:39 Â Â Â Â Â 7323648 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeWPGIMP32]
2010-02-16 14:35 Â Â Â Â Â 128000 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Common Files\Microsoft Shared\GRPHFLT\jpegim32WPGIMP32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PICTIM32PICTIM32]
2010-02-16 14:35 Â Â Â Â Â 128000 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Common Files\Microsoft Shared\GRPHFLT\jpegim32WPGIMP32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-09-06 19:09 Â Â Â Â Â 413696 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2006-03-20 20:00 Â Â Â Â Â 282624 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\windows\stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SonicWALLNetExtender]
2008-01-16 23:51 Â Â Â Â Â 562608 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\SonicWALL\SSL-VPN\NetExtender\NEGui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StatusClient]
2002-12-16 20:51 Â Â Â Â Â 36864 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-02-22 08:25 Â Â Â Â Â 144784 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-08-21 15:40 Â Â Â Â Â 68856 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomcatStartup]
2003-04-01 00:28 Â Â Â Â Â 155648 Â Â Â Â Â ----a-w- Â Â Â Â Â c:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
10:31:49:427 4268 Â Â Â Â Â TDSS rootkit removing tool 2.2.4 Feb 15 2010 19:38:31
10:31:49:427 4268 Â Â Â Â Â ================================================================================
10:31:49:427 4268 Â Â Â Â Â SystemInfo:
10:31:49:427 4268 Â Â Â Â Â OS Version: 5.1.2600 ServicePack: 3.0
10:31:49:427 4268 Â Â Â Â Â Product type: Workstation
10:31:49:427 4268 Â Â Â Â Â ComputerName: RBDPC-1020
10:31:49:427 4268 Â Â Â Â Â UserName: shirley
10:31:49:427 4268 Â Â Â Â Â Windows directory: C:\WINDOWS
10:31:49:427 4268 Â Â Â Â Â Processor architecture: Intel x86
10:31:49:427 4268 Â Â Â Â Â Number of processors: 2
10:31:49:427 4268 Â Â Â Â Â Page size: 0x1000
10:31:49:442 4268 Â Â Â Â Â Boot type: Normal boot
10:31:49:442 4268 Â Â Â Â Â ================================================================================
10:31:49:442 4268 Â Â Â Â Â UnloadDriverW: NtUnloadDriver error 2
10:31:49:442 4268 Â Â Â Â Â ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
10:31:49:458 4268 Â Â Â Â Â MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
10:31:49:505 4268 Â Â Â Â Â UtilityInit: KLMD drop and load success
10:31:49:505 4268 Â Â Â Â Â KLMD_OpenDevice: Trying to open KLMD Device(KLMD201010)
10:31:49:505 4268 Â Â Â Â Â UtilityInit: KLMD open success
10:31:49:505 4268 Â Â Â Â Â UtilityInit: Initialize success
10:31:49:505 4268 Â Â Â Â Â
10:31:49:505 4268      Scanning      Services ...
10:31:49:505 4268 Â Â Â Â Â CreateRegParser: Registry parser init started
10:31:49:505 4268 Â Â Â Â Â DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
10:31:49:505 4268 Â Â Â Â Â CreateRegParser: DisableWow64Redirection error
10:31:49:505 4268 Â Â Â Â Â wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
10:31:49:505 4268 Â Â Â Â Â MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043
10:31:49:505 4268 Â Â Â Â Â wfopen_ex: MyNtCreateFileW error 32 (C0000043)
10:31:49:505 4268 Â Â Â Â Â wfopen_ex: Trying to KLMD file open
10:31:49:505 4268 Â Â Â Â Â KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system
10:31:49:505 4268 Â Â Â Â Â wfopen_ex: File opened ok (Flags 2)
10:31:49:505 4268 Â Â Â Â Â CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: CA49A8
10:31:49:505 4268 Â Â Â Â Â wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
10:31:49:505 4268 Â Â Â Â Â MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043
10:31:49:505 4268 Â Â Â Â Â wfopen_ex: MyNtCreateFileW error 32 (C0000043)
10:31:49:505 4268 Â Â Â Â Â wfopen_ex: Trying to KLMD file open
10:31:49:505 4268 Â Â Â Â Â KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software
10:31:49:505 4268 Â Â Â Â Â wfopen_ex: File opened ok (Flags 2)
10:31:49:505 4268 Â Â Â Â Â CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: CA4A50
10:31:49:505 4268 Â Â Â Â Â EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
10:31:49:505 4268 Â Â Â Â Â CreateRegParser: EnableWow64Redirection error
10:31:49:505 4268 Â Â Â Â Â CreateRegParser: RegParser init completed
10:31:50:130 4268 Â Â Â Â Â GetAdvancedServicesInfo: Raw services enum returned 390 services
10:31:50:130 4268 Â Â Â Â Â fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
10:31:50:130 4268 Â Â Â Â Â fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
10:31:50:130 4268 Â Â Â Â Â
10:31:50:130 4268      Scanning      Kernel memory ...
10:31:50:145 4268 Â Â Â Â Â KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 8AF37168
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: KLMD_GetDeviceObjectList returned 6 DevObjects
10:31:50:145 4268 Â Â Â Â Â
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: DEVICE_OBJECT: 8AEDB8A0
10:31:50:145 4268 Â Â Â Â Â KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AEDB8A0
10:31:50:145 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AEDB8A0[0x38]
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: DRIVER_OBJECT: 8AF37168
10:31:50:145 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AF37168[0xA8]
10:31:50:145 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0xE10232B8[0x18]
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE Â Â Â Â Â Â Â Â Â Â Â : BA8EEBB0
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE Â Â Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CLOSE Â Â Â Â Â Â Â Â Â Â Â : BA8EEBB0
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_READ Â Â Â Â Â Â Â Â Â Â Â Â : BA8E8D1F
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_WRITE Â Â Â Â Â Â Â Â Â Â Â : BA8E8D1F
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_INFORMATION Â Â Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_INFORMATION Â Â Â Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_EA Â Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_EA Â Â Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS Â Â Â Â Â Â Â : BA8E92E2
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL Â Â Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL Â Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DEVICE_CONTROL Â Â Â Â Â Â Â : BA8E93BB
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL Â Â : BA8ECF28
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SHUTDOWN Â Â Â Â Â Â Â Â Â Â : BA8E92E2
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_LOCK_CONTROL Â Â Â Â Â Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CLEANUP Â Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT Â Â Â Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_SECURITY Â Â Â Â Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_SECURITY Â Â Â Â Â Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_POWER Â Â Â Â Â Â Â Â Â Â Â : BA8EAC82
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL Â Â Â Â Â Â Â : BA8EF99E
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DEVICE_CHANGE Â Â Â Â Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_QUOTA Â Â Â Â Â Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_QUOTA Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:145 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver: Disk
10:31:50:145 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:145 4268 Â Â Â Â Â KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:161 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver: Disk
10:31:50:161 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:161 4268 Â Â Â Â Â KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:192 4268 Â Â Â Â Â TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
10:31:50:192 4268 Â Â Â Â Â
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: DEVICE_OBJECT: 8AEDBC68
10:31:50:192 4268 Â Â Â Â Â KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AEDBC68
10:31:50:192 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AEDBC68[0x38]
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: DRIVER_OBJECT: 8AF37168
10:31:50:192 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AF37168[0xA8]
10:31:50:192 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0xE10232B8[0x18]
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE Â Â Â Â Â Â Â Â Â Â Â : BA8EEBB0
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE Â Â Â Â Â : 804F4562
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CLOSE Â Â Â Â Â Â Â Â Â Â Â : BA8EEBB0
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_READ Â Â Â Â Â Â Â Â Â Â Â Â : BA8E8D1F
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_WRITE Â Â Â Â Â Â Â Â Â Â Â : BA8E8D1F
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_INFORMATION Â Â Â Â Â : 804F4562
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_INFORMATION Â Â Â Â Â Â : 804F4562
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_EA Â Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_EA Â Â Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS Â Â Â Â Â Â Â : BA8E92E2
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION Â Â : 804F4562
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION Â Â Â : 804F4562
10:31:50:192 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL Â Â Â Â Â : 804F4562
10:31:50:208 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL Â Â Â Â : 804F4562
10:31:50:208 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DEVICE_CONTROL Â Â Â Â Â Â Â : BA8E93BB
10:31:50:208 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL Â Â : BA8ECF28
10:31:50:208 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SHUTDOWN Â Â Â Â Â Â Â Â Â Â : BA8E92E2
10:31:50:208 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_LOCK_CONTROL Â Â Â Â Â Â Â Â : 804F4562
10:31:50:208 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CLEANUP Â Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:208 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT Â Â Â Â Â Â : 804F4562
10:31:50:208 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_SECURITY Â Â Â Â Â Â Â : 804F4562
10:31:50:208 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_SECURITY Â Â Â Â Â Â Â Â : 804F4562
10:31:50:208 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_POWER Â Â Â Â Â Â Â Â Â Â Â : BA8EAC82
10:31:50:208 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL Â Â Â Â Â Â Â : BA8EF99E
10:31:50:208 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DEVICE_CHANGE Â Â Â Â Â Â Â : 804F4562
10:31:50:208 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_QUOTA Â Â Â Â Â Â Â Â : 804F4562
10:31:50:208 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_QUOTA Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:208 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver: Disk
10:31:50:208 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:208 4268 Â Â Â Â Â KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:208 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver: Disk
10:31:50:208 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:208 4268 Â Â Â Â Â KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:224 4268 Â Â Â Â Â TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
10:31:50:224 4268 Â Â Â Â Â
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: DEVICE_OBJECT: 8AEF88A0
10:31:50:224 4268 Â Â Â Â Â KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AEF88A0
10:31:50:224 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AEF88A0[0x38]
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: DRIVER_OBJECT: 8AF37168
10:31:50:224 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AF37168[0xA8]
10:31:50:224 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0xE10232B8[0x18]
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE Â Â Â Â Â Â Â Â Â Â Â : BA8EEBB0
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE Â Â Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CLOSE Â Â Â Â Â Â Â Â Â Â Â : BA8EEBB0
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_READ Â Â Â Â Â Â Â Â Â Â Â Â : BA8E8D1F
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_WRITE Â Â Â Â Â Â Â Â Â Â Â : BA8E8D1F
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_INFORMATION Â Â Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_INFORMATION Â Â Â Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_EA Â Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_EA Â Â Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS Â Â Â Â Â Â Â : BA8E92E2
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL Â Â Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL Â Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DEVICE_CONTROL Â Â Â Â Â Â Â : BA8E93BB
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL Â Â : BA8ECF28
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SHUTDOWN Â Â Â Â Â Â Â Â Â Â : BA8E92E2
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_LOCK_CONTROL Â Â Â Â Â Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CLEANUP Â Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT Â Â Â Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_SECURITY Â Â Â Â Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_SECURITY Â Â Â Â Â Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_POWER Â Â Â Â Â Â Â Â Â Â Â : BA8EAC82
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL Â Â Â Â Â Â Â : BA8EF99E
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DEVICE_CHANGE Â Â Â Â Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_QUOTA Â Â Â Â Â Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_QUOTA Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:224 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver: Disk
10:31:50:224 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:224 4268 Â Â Â Â Â KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:224 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver: Disk
10:31:50:224 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:224 4268 Â Â Â Â Â KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:239 4268 Â Â Â Â Â TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
10:31:50:239 4268 Â Â Â Â Â
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: DEVICE_OBJECT: 8AEF8C68
10:31:50:239 4268 Â Â Â Â Â KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AEF8C68
10:31:50:239 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AEF8C68[0x38]
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: DRIVER_OBJECT: 8AF37168
10:31:50:239 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AF37168[0xA8]
10:31:50:239 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0xE10232B8[0x18]
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE Â Â Â Â Â Â Â Â Â Â Â : BA8EEBB0
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE Â Â Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CLOSE Â Â Â Â Â Â Â Â Â Â Â : BA8EEBB0
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_READ Â Â Â Â Â Â Â Â Â Â Â Â : BA8E8D1F
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_WRITE Â Â Â Â Â Â Â Â Â Â Â : BA8E8D1F
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_INFORMATION Â Â Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_INFORMATION Â Â Â Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_EA Â Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_EA Â Â Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS Â Â Â Â Â Â Â : BA8E92E2
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL Â Â Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL Â Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DEVICE_CONTROL Â Â Â Â Â Â Â : BA8E93BB
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL Â Â : BA8ECF28
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SHUTDOWN Â Â Â Â Â Â Â Â Â Â : BA8E92E2
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_LOCK_CONTROL Â Â Â Â Â Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CLEANUP Â Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT Â Â Â Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_SECURITY Â Â Â Â Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_SECURITY Â Â Â Â Â Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_POWER Â Â Â Â Â Â Â Â Â Â Â : BA8EAC82
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL Â Â Â Â Â Â Â : BA8EF99E
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DEVICE_CHANGE Â Â Â Â Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_QUOTA Â Â Â Â Â Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_QUOTA Â Â Â Â Â Â Â Â Â : 804F4562
10:31:50:239 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver: Disk
10:31:50:239 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:239 4268 Â Â Â Â Â KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:239 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver: Disk
10:31:50:239 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:239 4268 Â Â Â Â Â KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
10:31:50:255 4268 Â Â Â Â Â TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
10:31:50:255 4268 Â Â Â Â Â
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: DEVICE_OBJECT: 8AED5AB8
10:31:50:255 4268 Â Â Â Â Â KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AED5AB8
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: DEVICE_OBJECT: 8AED78D0
10:31:50:255 4268 Â Â Â Â Â KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AED78D0
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: DEVICE_OBJECT: 8AEEDD98
10:31:50:255 4268 Â Â Â Â Â KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AEEDD98
10:31:50:255 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AEEDD98[0x38]
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: DRIVER_OBJECT: 8AEE9F38
10:31:50:255 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AEE9F38[0xA8]
10:31:50:255 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0xE18349B8[0x1A]
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE Â Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CLOSE Â Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_READ Â Â Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_WRITE Â Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_INFORMATION Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_INFORMATION Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_EA Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_EA Â Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DEVICE_CONTROL Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SHUTDOWN Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_LOCK_CONTROL Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CLEANUP Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_SECURITY Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_SECURITY Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_POWER Â Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DEVICE_CHANGE Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_QUOTA Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_QUOTA Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:50:255 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver: atapi
10:31:50:255 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
10:31:50:255 4268 Â Â Â Â Â KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys
10:31:50:270 4268 Â Â Â Â Â DetectCureTDL3: All IRP handlers pointed to one addr: BA6F4B3A
10:31:50:270 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0xBA6F4B3A[0x400]
10:31:50:270 4268 Â Â Â Â Â TDL3_IrpHookDetect: TDL3 Stub signature found, trying to get hook true addr
10:31:50:270 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0xFFDF0308[0x4]
10:31:50:270 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AEE990C[0x4]
10:31:50:270 4268 Â Â Â Â Â TDL3_IrpHookDetect: New IrpHandler addr: 8AEBB8C8
10:31:50:270 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AEBB8C8[0x400]
10:31:50:270 4268 Â Â Â Â Â TDL3_IrpHookDetect: CheckParameters: 10, FFDF0308, 510, 134, 3, 120
10:31:50:270 4268 Â Â Â Â Â Driver "atapi" Irp handler infected by TDSS rootkit ... 10:31:50:270 4268 Â Â Â Â Â KLMD_WriteMem: Trying to WriteMemory 0x8AEBB94E[0xD]
10:31:50:270 4268 Â Â Â Â Â cured
10:31:50:270 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0xBA6F2864[0x400]
10:31:50:270 4268 Â Â Â Â Â TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
10:31:50:270 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver: atapi
10:31:50:270 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
10:31:50:270 4268 Â Â Â Â Â KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys
10:31:50:286 4268 Â Â Â Â Â TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Infected
10:31:50:286 4268 Â Â Â Â Â File C:\WINDOWS\system32\DRIVERS\atapi.sys infected by TDSS rootkit ... 10:31:50:286 4268 Â Â Â Â Â TDL3_FileCure: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
10:31:50:286 4268 Â Â Â Â Â ProcessDirEnumEx: FindFirstFile(C:\WINDOWS\system32\DriverStore\FileRepository\*) error 3
10:31:50:302 4268 Â Â Â Â Â CABFileCallback: Processing cab-file: C:\WINDOWS\Driver Cache\i386\driver.cab
10:31:50:380 4268 Â Â Â Â Â CABFileCallback: Processing cab-file: C:\WINDOWS\Driver Cache\i386\sp2.cab
10:31:50:427 4268 Â Â Â Â Â CABFileCallback: Processing cab-file: C:\WINDOWS\Driver Cache\i386\sp3.cab
10:31:50:427 4268 Â Â Â Â Â CabinetCallback: Backup candidate found: atapi.sys:96512, extracting..
10:31:50:458 4268 Â Â Â Â Â CabinetCallback: File extracted successfully: C:\DOCUME~1\SHIRLE~1.RAN\LOCALS~1\Temp\bckE4.tmp
10:31:50:458 4268 Â Â Â Â Â ValidateDriverFile: Stage 1 passed
10:31:50:458 4268 Â Â Â Â Â ValidateDriverFile: Stage 2 passed
10:31:50:536 4268 Â Â Â Â Â DigitalSignVerifyByHandle: Embedded DS result: 800B0100
10:31:51:020 4268 Â Â Â Â Â DigitalSignVerifyByHandle: Cat DS result: 00000000
10:31:51:020 4268 Â Â Â Â Â ValidateDriverFile: Stage 3 passed
10:31:51:036 4268 Â Â Â Â Â CabinetCallback: File validated successfully, restore information prepared
10:31:51:036 4268 Â Â Â Â Â FindDriverFileBackup: Backup copy found in cab-file
10:31:51:036 4268 Â Â Â Â Â TDL3_FileCure: Backup copy found, using it..
10:31:51:036 4268 Â Â Â Â Â TDL3_FileCure: Dumping cured buffer to file C:\WINDOWS\system32\drivers\tskE5.tmp
10:31:51:067 4268 Â Â Â Â Â TDL3_FileCure: New / Old Image paths: (system32\drivers\tskE5.tmp, system32\drivers\atapi.sys)
10:31:51:067 4268 Â Â Â Â Â TDL3_FileCure: KLMD jobs schedule success
10:31:51:067 4268 Â Â Â Â Â will be cured on next reboot
10:31:51:067 4268 Â Â Â Â Â
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: DEVICE_OBJECT: 8AF528F0
10:31:51:067 4268 Â Â Â Â Â KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AF528F0
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: DEVICE_OBJECT: 8AF4C020
10:31:51:067 4268 Â Â Â Â Â KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AF4C020
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: DEVICE_OBJECT: 8AEF2D98
10:31:51:067 4268 Â Â Â Â Â KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AEF2D98
10:31:51:067 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AEF2D98[0x38]
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: DRIVER_OBJECT: 8AEE9F38
10:31:51:067 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AEE9F38[0xA8]
10:31:51:067 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0xE18349B8[0x1A]
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE Â Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CLOSE Â Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_READ Â Â Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_WRITE Â Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_INFORMATION Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_INFORMATION Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_EA Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_EA Â Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DEVICE_CONTROL Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SHUTDOWN Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_LOCK_CONTROL Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CLEANUP Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_SECURITY Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_SECURITY Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_POWER Â Â Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_DEVICE_CHANGE Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_QUERY_QUOTA Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: IRP_MJ_SET_QUOTA Â Â Â Â Â Â Â Â Â : BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver: atapi
10:31:51:067 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\tskE5.tmp
10:31:51:067 4268 Â Â Â Â Â KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\tskE5.tmp
10:31:51:067 4268 Â Â Â Â Â DetectCureTDL3: All IRP handlers pointed to one addr: BA6F4B3A
10:31:51:067 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0xBA6F4B3A[0x400]
10:31:51:067 4268 Â Â Â Â Â TDL3_IrpHookDetect: TDL3 Stub signature found, trying to get hook true addr
10:31:51:067 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0xFFDF0308[0x4]
10:31:51:067 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AEE990C[0x4]
10:31:51:067 4268 Â Â Â Â Â TDL3_IrpHookDetect: New IrpHandler addr: 8AEBB8C8
10:31:51:067 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0x8AEBB8C8[0x400]
10:31:51:067 4268 Â Â Â Â Â TDL3_IrpHookDetect: TDL3 is already cured
10:31:51:067 4268 Â Â Â Â Â KLMD_ReadMem: Trying to ReadMemory 0xBA6F2864[0x400]
10:31:51:067 4268 Â Â Â Â Â TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
10:31:51:067 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver: atapi
10:31:51:067 4268 Â Â Â Â Â TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\tskE5.tmp
10:31:51:067 4268 Â Â Â Â Â KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\tskE5.tmp
10:31:51:083 4268 Â Â Â Â Â TDL3_FileDetect: C:\WINDOWS\system32\drivers\tskE5.tmp - Verdict: Clean
10:31:51:083 4268 Â Â Â Â Â UtilityBootReinit: Reboot required for cure complete..
10:31:51:083 4268 Â Â Â Â Â MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmdb.sys) returned status 00000000
10:31:51:099 4268 Â Â Â Â Â UtilityBootReinit: KLMD drop success
10:31:51:099 4268 Â Â Â Â Â KLMD_ApplyPendList: Pending buffer(265B_3650, 608) dropped successfully
10:31:51:099 4268 Â Â Â Â Â UtilityBootReinit: Cure on reboot scheduled successfully
10:31:51:099 4268 Â Â Â Â Â
10:31:51:099 4268 Â Â Â Â Â Completed
10:31:51:099 4268 Â Â Â Â Â
10:31:51:099 4268 Â Â Â Â Â Results:
10:31:51:099 4268 Â Â Â Â Â Memory objects infected / cured / cured on reboot: Â Â Â Â Â 1 / 1 / 0
10:31:51:099 4268 Â Â Â Â Â Registry objects infected / cured / cured on reboot: Â Â Â Â Â 0 / 0 / 0
10:31:51:099 4268 Â Â Â Â Â File objects infected / cured / cured on reboot: Â Â Â Â Â 1 / 0 / 1
10:31:51:099 4268 Â Â Â Â Â
10:31:51:099 4268 Â Â Â Â Â UnloadDriverW: NtUnloadDriver error 1
10:31:51:099 4268 Â Â Â Â Â KLMD_Unload: UnloadDriverW(klmd21) error 1
10:31:51:099 4268 Â Â Â Â Â MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
10:31:51:099 4268 Â Â Â Â Â UtilityDeinit: KLMD(ARK) unloaded successfully
thinktechsolutions
ASKER
Here is a new hijack this log as well
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:14:44 AM, on 2/21/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal
TDSSKiller found and cured a TDL3 rootkit(patched atapi.sys) that also caused search redirects.
If the redirect has stopped then all is well and the patched atapi driver was the culprit... if the problem persists then we need to run more tools and continue to troubleshoot.
Thank you so much so it was TDSSKiller that elminated the problem. Thank you for your help
rpggamergirl
Sorry, I didn't refresh the page and missed your post.
Hijackthis log looks clean... but a lot of nasties are now able to hide from its scan so a clean Hijackthis log doesn't necessarily mean a clean system.
Is the search still being redirected?
rpggamergirl
Ooops, again I missed reading a comment.
It's great to know that atapi.sys was the culprit and it's been taken care of.