Thanks again for your prompt response and continued assistance. Unfortunately, I did run into another issue while following your instructions. I was able to run Avenger, OTS, and TDSSKiller with no problems, however when I went to use Combofix all that would happen is a small status bar pops up in the middle of my desktop with the text "Combofix" and a blue progress bar that quickly fills. After that nothing happens at all. In task manager I can see the Combofix process close after the status bar disappears. The PC doesn't hang or anything else abnormal appears to happen, but its obvious Combofix isn't doing anything once the status bar finishes loading. Keep in mind I followed all instructions relating to Combofix, including renaming it to Combo-fix and disabling AVG, teatimer, and Zonealarm firewall. Anyway, here are the reults from the logs of the other 3 programs...Thanks again!
Avenger log:
Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.comPlatform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Driver "AdbUpd" deleted successfully.
File "c:\documents and settings\dave\desktop\your pc protector.lnk" deleted successfully.
File "c:\documents and settings\dave\local settings\application data\dcbc2a71-70d8-4dan-ehr8-e0d61dea3fdf.ini" deleted successfully.
File "c:\documents and settings\dave\local settings\application data\prvlcl.dat" deleted successfully.
File "c:\program files\adc32.dll" deleted successfully.
File "c:\program files\alggui.exe" deleted successfully.
File "c:\program files\nuar.old" deleted successfully.
File "c:\program files\svchost.exe" deleted successfully.
File "c:\program files\wp3.dat" deleted successfully.
File "c:\program files\wp4.dat" deleted successfully.
File "c:\program files\wpp.exe" deleted successfully.
File "c:\windows\kbozoquqisefa.bin" deleted successfully.
File "c:\windows\oxakada.dat" deleted successfully.
File "c:\windows\rasqervy.dll" deleted successfully.
File "c:\windows\sdfinacs.dll" deleted successfully.
File "c:\windows\sdfixwcs.dll" deleted successfully.
File "c:\windows\system32\cmd.exe" deleted successfully.
File "c:\windows\system32\command.com" deleted successfully.
Error: file "c:\windows\system32\dozibadi.dll" not found!
Deletion of file "c:\windows\system32\dozibadi.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\windows\system32\dozibadi.dll_old" not found!
Deletion of file "c:\windows\system32\dozibadi.dll_old" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
File "c:\windows\system32\fihisafu" deleted successfully.
File "c:\windows\system32\gudunowi.dll" deleted successfully.
File "c:\windows\system32\jasisaji.dll" deleted successfully.
File "c:\windows\system32\komeluwe.dll" deleted successfully.
File "c:\windows\system32\vusumuje.dll" deleted successfully.
File "c:\windows\system32\yuhoraki.dll" deleted successfully.
File "c:\windows\system32\zijofege.dll" deleted successfully.
File "c:\your pc protector.lnk" deleted successfully.
Folder "c:\program files\your pc protector" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
OTS log:
All Processes Killed
[Modules - Safe List]
[Win32 Services - Safe List]
Error: No service named AdbUpd was found to stop!
Unable to stop service AdbUpd!
File C:\Program Files\svchost.exe not found.
[Registry - Safe List]
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77DC0Baa-3235-4ba9-8BE8-aa9EB678FA02}\ not found.
File C:\Program Files\adc32.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\zuyalavaz not found.
File C:\WINDOWS\System32\dozibadi.DLL not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA2458 not found.
File C:\WINDOWS\System32\command.com not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA3992 not found.
File C:\WINDOWS\System32\command.com not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingA491 not found.
File C:\WINDOWS\System32\command.com not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC126 not found.
File C:\WINDOWS\System32\cmd.exe not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC2205 not found.
File C:\WINDOWS\System32\cmd.exe not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\\SpybotDeletingC6637 not found.
File C:\WINDOWS\System32\cmd.exe not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:jasisaji.dll c:\windows\system32\dozibadi.dll deleted successfully.
File C:\WINDOWS\System32\jasisaji.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\kekaterel not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{798ecf98-4c77-4aee-ab93-a417cc71dbce}\ not found.
File C:\WINDOWS\System32\dozibadi.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{798ecf98-4c77-4aee-ab93-a417cc71dbce} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{798ecf98-4c77-4aee-ab93-a417cc71dbce}\ not found.
File C:\WINDOWS\System32\dozibadi.dll not found.
[Registry - Additional Scans - Safe List]
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{77DC0BAA-3235-4BA9-8BE8-AA9EB678FA02}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77DC0BAA-3235-4BA9-8BE8-AA9EB678FA02}\ not found.
File C:\Program Files\adc32.dll not found.
[Files/Folders - Created Within 90 Days]
File C:\Program Files\adc32.dll not found!
File C:\Program Files\Your PC Protector not found!
File C:\Program Files\wpp.exe not found!
[Files/Folders - Modified Within 90 Days]
File C:\WINDOWS\System32\zijofege.dll not found!
File C:\WINDOWS\System32\dozibadi.dll_old not found!
File C:\WINDOWS\System32\yuhoraki.dll not found!
File C:\WINDOWS\System32\vusumuje.dll not found!
File C:\WINDOWS\System32\jasisaji.dll not found!
File C:\WINDOWS\System32\gudunowi.dll not found!
File C:\WINDOWS\System32\komeluwe.dll not found!
C:\WINDOWS\System32\fihisafu moved successfully.
File C:\Program Files\wp4.dat not found!
File C:\Program Files\wp3.dat not found!
File C:\Program Files\adc32.dll not found!
File C:\Program Files\alggui.exe not found!
File C:\Your PC Protector.lnk not found!
File C:\Documents and Settings\Dave\Local Settings\Application Data\prvlcl.dat not found!
File C:\Program Files\nuar.old not found!
File C:\Program Files\svchost.exe not found!
File C:\Documents and Settings\Dave\Desktop\Your PC Protector.lnk not found!
File C:\Program Files\wpp.exe not found!
File C:\Documents and Settings\Dave\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini not found!
File C:\WINDOWS\Kbozoquqisefa.bin not found!
File C:\WINDOWS\Oxakada.dat not found!
[Files - No Company Name]
File C:\WINDOWS\System32\zijofege.dll not found!
File C:\WINDOWS\System32\dozibadi.dll_old not found!
File C:\WINDOWS\System32\yuhoraki.dll not found!
File C:\WINDOWS\System32\vusumuje.dll not found!
File C:\WINDOWS\System32\jasisaji.dll not found!
File C:\WINDOWS\System32\gudunowi.dll not found!
File C:\WINDOWS\System32\komeluwe.dll not found!
File C:\WINDOWS\System32\fihisafu not found!
File C:\Your PC Protector.lnk not found!
File C:\Program Files\nuar.old not found!
File C:\Program Files\alggui.exe not found!
File C:\Program Files\svchost.exe not found!
File C:\Program Files\wp4.dat not found!
File C:\Program Files\wp3.dat not found!
File C:\Documents and Settings\Dave\Desktop\Your PC Protector.lnk not found!
File C:\WINDOWS\Oxakada.dat not found!
File C:\WINDOWS\Kbozoquqisefa.bin not found!
File C:\Documents and Settings\Dave\Local Settings\Application Data\prvlcl.dat not found!
File C:\WINDOWS\rasqervy.dll not found!
File C:\WINDOWS\sdfinacs.dll not found!
File C:\WINDOWS\sdfixwcs.dll not found!
[Alternate Data Streams]
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1 .
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34 .
[Empty Temp Folders]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: All Users
User: Dave
->Temp folder emptied: 2198679 bytes
->Temporary Internet Files folder emptied: 93291 bytes
->Java cache emptied: 1875835 bytes
->FireFox cache emptied: 36556707 bytes
->Opera cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 256 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 39.00 mb
Restore point Set: OTS Restore Point (64424509440)
< End of fix log >
OTS by OldTimer - Version 3.1.20.1 fix logfile created on 02082010_172738
Files\Folders moved on Reboot...
C:\Documents and Settings\Dave\Local Settings\Temp\~DF58A0.tmp moved successfully.
File\Folder C:\WINDOWS\temp\ZLT00215.TMP not found!
Registry entries deleted on Reboot...
TDSSKiller log:
17:36:41:953 6120 TDSS rootkit removing tool 2.2.3 Feb 4 2010 14:34:00
17:36:41:953 6120 ================================================================================
17:36:41:953 6120 SystemInfo:
17:36:41:953 6120 OS Version: 5.1.2600 ServicePack: 2.0
17:36:41:953 6120 Product type: Workstation
17:36:41:953 6120 ComputerName: YOUR-85A8F7B8EC
17:36:41:953 6120 UserName: Dave
17:36:41:953 6120 Windows directory: C:\WINDOWS
17:36:41:953 6120 Processor architecture: Intel x86
17:36:41:953 6120 Number of processors: 2
17:36:41:953 6120 Page size: 0x1000
17:36:41:953 6120 Boot type: Normal boot
17:36:41:953 6120 ================================================================================
17:36:41:953 6120 UnloadDriverW: NtUnloadDriver error 2
17:36:41:953 6120 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
17:36:41:984 6120 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
17:36:42:015 6120 UtilityInit: KLMD drop and load success
17:36:42:015 6120 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201010)
17:36:42:015 6120 UtilityInit: KLMD open success
17:36:42:015 6120 UtilityInit: Initialize success
17:36:42:015 6120
17:36:42:015 6120 Scanning Services ...
17:36:42:015 6120 CreateRegParser: Registry parser init started
17:36:42:015 6120 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
17:36:42:015 6120 CreateRegParser: DisableWow64Redirection error
17:36:42:015 6120 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
17:36:42:015 6120 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043
17:36:42:015 6120 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
17:36:42:015 6120 wfopen_ex: Trying to KLMD file open
17:36:42:015 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system
17:36:42:015 6120 wfopen_ex: File opened ok (Flags 2)
17:36:42:015 6120 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: C74AE8
17:36:42:015 6120 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
17:36:42:031 6120 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043
17:36:42:031 6120 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
17:36:42:031 6120 wfopen_ex: Trying to KLMD file open
17:36:42:031 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software
17:36:42:031 6120 wfopen_ex: File opened ok (Flags 2)
17:36:42:031 6120 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: C74B90
17:36:42:031 6120 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
17:36:42:031 6120 CreateRegParser: EnableWow64Redirection error
17:36:42:031 6120 CreateRegParser: RegParser init completed
17:36:42:640 6120 GetAdvancedServicesInfo: Raw services enum returned 380 services
17:36:42:640 6120 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
17:36:42:640 6120 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
17:36:42:640 6120
17:36:42:640 6120 Scanning Kernel memory ...
17:36:42:640 6120 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
17:36:42:640 6120 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 8ACD4A08
17:36:42:640 6120 DetectCureTDL3: KLMD_GetDeviceObjectList returned 16 DevObjects
17:36:42:640 6120
17:36:42:640 6120 DetectCureTDL3: DEVICE_OBJECT: 897A4030
17:36:42:640 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 897A4030
17:36:42:640 6120 KLMD_ReadMem: Trying to ReadMemory 0x897A4030[0x38]
17:36:42:640 6120 DetectCureTDL3: DRIVER_OBJECT: 8ACD4A08
17:36:42:640 6120 KLMD_ReadMem: Trying to ReadMemory 0x8ACD4A08[0xA8]
17:36:42:640 6120 KLMD_ReadMem: Trying to ReadMemory 0xE17223C8[0x18]
17:36:42:640 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
17:36:42:640 6120 DetectCureTDL3: IrpHandler (0) addr: B810EC30
17:36:42:640 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (2) addr: B810EC30
17:36:42:640 6120 DetectCureTDL3: IrpHandler (3) addr: B8108D9B
17:36:42:640 6120 DetectCureTDL3: IrpHandler (4) addr: B8108D9B
17:36:42:640 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (9) addr: B8109366
17:36:42:640 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (14) addr: B810944D
17:36:42:640 6120 DetectCureTDL3: IrpHandler (15) addr: B810CFC3
17:36:42:640 6120 DetectCureTDL3: IrpHandler (16) addr: B8109366
17:36:42:640 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (22) addr: B810AEF3
17:36:42:640 6120 DetectCureTDL3: IrpHandler (23) addr: B810FA24
17:36:42:640 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:640 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:640 6120 TDL3_FileDetect: Processing driver: Disk
17:36:42:640 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:640 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:703 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
17:36:42:703 6120
17:36:42:703 6120 DetectCureTDL3: DEVICE_OBJECT: 8957A030
17:36:42:703 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8957A030
17:36:42:703 6120 KLMD_ReadMem: Trying to ReadMemory 0x8957A030[0x38]
17:36:42:703 6120 DetectCureTDL3: DRIVER_OBJECT: 8ACD4A08
17:36:42:703 6120 KLMD_ReadMem: Trying to ReadMemory 0x8ACD4A08[0xA8]
17:36:42:703 6120 KLMD_ReadMem: Trying to ReadMemory 0xE17223C8[0x18]
17:36:42:703 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
17:36:42:703 6120 DetectCureTDL3: IrpHandler (0) addr: B810EC30
17:36:42:703 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (2) addr: B810EC30
17:36:42:703 6120 DetectCureTDL3: IrpHandler (3) addr: B8108D9B
17:36:42:703 6120 DetectCureTDL3: IrpHandler (4) addr: B8108D9B
17:36:42:703 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (9) addr: B8109366
17:36:42:703 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (14) addr: B810944D
17:36:42:703 6120 DetectCureTDL3: IrpHandler (15) addr: B810CFC3
17:36:42:703 6120 DetectCureTDL3: IrpHandler (16) addr: B8109366
17:36:42:703 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (22) addr: B810AEF3
17:36:42:703 6120 DetectCureTDL3: IrpHandler (23) addr: B810FA24
17:36:42:703 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:703 6120 TDL3_FileDetect: Processing driver: Disk
17:36:42:703 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:703 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:703 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
17:36:42:703 6120
17:36:42:703 6120 DetectCureTDL3: DEVICE_OBJECT: 8AACE030
17:36:42:703 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AACE030
17:36:42:703 6120 KLMD_ReadMem: Trying to ReadMemory 0x8AACE030[0x38]
17:36:42:703 6120 DetectCureTDL3: DRIVER_OBJECT: 8ACD4A08
17:36:42:703 6120 KLMD_ReadMem: Trying to ReadMemory 0x8ACD4A08[0xA8]
17:36:42:703 6120 KLMD_ReadMem: Trying to ReadMemory 0xE17223C8[0x18]
17:36:42:703 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
17:36:42:703 6120 DetectCureTDL3: IrpHandler (0) addr: B810EC30
17:36:42:703 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (2) addr: B810EC30
17:36:42:703 6120 DetectCureTDL3: IrpHandler (3) addr: B8108D9B
17:36:42:703 6120 DetectCureTDL3: IrpHandler (4) addr: B8108D9B
17:36:42:703 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (9) addr: B8109366
17:36:42:703 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (14) addr: B810944D
17:36:42:703 6120 DetectCureTDL3: IrpHandler (15) addr: B810CFC3
17:36:42:703 6120 DetectCureTDL3: IrpHandler (16) addr: B8109366
17:36:42:703 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (22) addr: B810AEF3
17:36:42:703 6120 DetectCureTDL3: IrpHandler (23) addr: B810FA24
17:36:42:703 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:703 6120 TDL3_FileDetect: Processing driver: Disk
17:36:42:703 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:703 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:703 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
17:36:42:703 6120
17:36:42:703 6120 DetectCureTDL3: DEVICE_OBJECT: 8AA1B210
17:36:42:703 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AA1B210
17:36:42:703 6120 KLMD_ReadMem: Trying to ReadMemory 0x8AA1B210[0x38]
17:36:42:703 6120 DetectCureTDL3: DRIVER_OBJECT: 8ACD4A08
17:36:42:703 6120 KLMD_ReadMem: Trying to ReadMemory 0x8ACD4A08[0xA8]
17:36:42:703 6120 KLMD_ReadMem: Trying to ReadMemory 0xE17223C8[0x18]
17:36:42:703 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
17:36:42:703 6120 DetectCureTDL3: IrpHandler (0) addr: B810EC30
17:36:42:703 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (2) addr: B810EC30
17:36:42:703 6120 DetectCureTDL3: IrpHandler (3) addr: B8108D9B
17:36:42:703 6120 DetectCureTDL3: IrpHandler (4) addr: B8108D9B
17:36:42:703 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (9) addr: B8109366
17:36:42:703 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (14) addr: B810944D
17:36:42:703 6120 DetectCureTDL3: IrpHandler (15) addr: B810CFC3
17:36:42:703 6120 DetectCureTDL3: IrpHandler (16) addr: B8109366
17:36:42:703 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (22) addr: B810AEF3
17:36:42:703 6120 DetectCureTDL3: IrpHandler (23) addr: B810FA24
17:36:42:703 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:703 6120 TDL3_FileDetect: Processing driver: Disk
17:36:42:703 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:703 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:703 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
17:36:42:703 6120
17:36:42:703 6120 DetectCureTDL3: DEVICE_OBJECT: 8AB3E8F0
17:36:42:703 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AB3E8F0
17:36:42:703 6120 KLMD_ReadMem: Trying to ReadMemory 0x8AB3E8F0[0x38]
17:36:42:703 6120 DetectCureTDL3: DRIVER_OBJECT: 8ACD4A08
17:36:42:703 6120 KLMD_ReadMem: Trying to ReadMemory 0x8ACD4A08[0xA8]
17:36:42:703 6120 KLMD_ReadMem: Trying to ReadMemory 0xE17223C8[0x18]
17:36:42:703 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
17:36:42:703 6120 DetectCureTDL3: IrpHandler (0) addr: B810EC30
17:36:42:703 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (2) addr: B810EC30
17:36:42:703 6120 DetectCureTDL3: IrpHandler (3) addr: B8108D9B
17:36:42:703 6120 DetectCureTDL3: IrpHandler (4) addr: B8108D9B
17:36:42:703 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (9) addr: B8109366
17:36:42:703 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (14) addr: B810944D
17:36:42:703 6120 DetectCureTDL3: IrpHandler (15) addr: B810CFC3
17:36:42:703 6120 DetectCureTDL3: IrpHandler (16) addr: B8109366
17:36:42:703 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (22) addr: B810AEF3
17:36:42:703 6120 DetectCureTDL3: IrpHandler (23) addr: B810FA24
17:36:42:703 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:703 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:703 6120 TDL3_FileDetect: Processing driver: Disk
17:36:42:703 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:703 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:718 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
17:36:42:718 6120
17:36:42:718 6120 DetectCureTDL3: DEVICE_OBJECT: 8AA03030
17:36:42:718 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AA03030
17:36:42:718 6120 KLMD_ReadMem: Trying to ReadMemory 0x8AA03030[0x38]
17:36:42:718 6120 DetectCureTDL3: DRIVER_OBJECT: 8ACD4A08
17:36:42:718 6120 KLMD_ReadMem: Trying to ReadMemory 0x8ACD4A08[0xA8]
17:36:42:718 6120 KLMD_ReadMem: Trying to ReadMemory 0xE17223C8[0x18]
17:36:42:718 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
17:36:42:718 6120 DetectCureTDL3: IrpHandler (0) addr: B810EC30
17:36:42:718 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (2) addr: B810EC30
17:36:42:718 6120 DetectCureTDL3: IrpHandler (3) addr: B8108D9B
17:36:42:718 6120 DetectCureTDL3: IrpHandler (4) addr: B8108D9B
17:36:42:718 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (9) addr: B8109366
17:36:42:718 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (14) addr: B810944D
17:36:42:718 6120 DetectCureTDL3: IrpHandler (15) addr: B810CFC3
17:36:42:718 6120 DetectCureTDL3: IrpHandler (16) addr: B8109366
17:36:42:718 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (22) addr: B810AEF3
17:36:42:718 6120 DetectCureTDL3: IrpHandler (23) addr: B810FA24
17:36:42:718 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:718 6120 TDL3_FileDetect: Processing driver: Disk
17:36:42:718 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:718 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:718 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
17:36:42:718 6120
17:36:42:718 6120 DetectCureTDL3: DEVICE_OBJECT: 8AA4F928
17:36:42:718 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AA4F928
17:36:42:718 6120 KLMD_ReadMem: Trying to ReadMemory 0x8AA4F928[0x38]
17:36:42:718 6120 DetectCureTDL3: DRIVER_OBJECT: 8ACD4A08
17:36:42:718 6120 KLMD_ReadMem: Trying to ReadMemory 0x8ACD4A08[0xA8]
17:36:42:718 6120 KLMD_ReadMem: Trying to ReadMemory 0xE17223C8[0x18]
17:36:42:718 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
17:36:42:718 6120 DetectCureTDL3: IrpHandler (0) addr: B810EC30
17:36:42:718 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (2) addr: B810EC30
17:36:42:718 6120 DetectCureTDL3: IrpHandler (3) addr: B8108D9B
17:36:42:718 6120 DetectCureTDL3: IrpHandler (4) addr: B8108D9B
17:36:42:718 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (9) addr: B8109366
17:36:42:718 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (14) addr: B810944D
17:36:42:718 6120 DetectCureTDL3: IrpHandler (15) addr: B810CFC3
17:36:42:718 6120 DetectCureTDL3: IrpHandler (16) addr: B8109366
17:36:42:718 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (22) addr: B810AEF3
17:36:42:718 6120 DetectCureTDL3: IrpHandler (23) addr: B810FA24
17:36:42:718 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:718 6120 TDL3_FileDetect: Processing driver: Disk
17:36:42:718 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:718 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:718 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
17:36:42:718 6120
17:36:42:718 6120 DetectCureTDL3: DEVICE_OBJECT: 8A9FFAB8
17:36:42:718 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A9FFAB8
17:36:42:718 6120 DetectCureTDL3: DEVICE_OBJECT: 896E2B48
17:36:42:718 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 896E2B48
17:36:42:718 6120 KLMD_ReadMem: Trying to ReadMemory 0x896E2B48[0x38]
17:36:42:718 6120 DetectCureTDL3: DRIVER_OBJECT: 8AA57930
17:36:42:718 6120 KLMD_ReadMem: Trying to ReadMemory 0x8AA57930[0xA8]
17:36:42:718 6120 KLMD_ReadMem: Trying to ReadMemory 0xE1D04458[0x1E]
17:36:42:718 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\usbstor, Driver Name: usbstor
17:36:42:718 6120 DetectCureTDL3: IrpHandler (0) addr: B838D218
17:36:42:718 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (2) addr: B838D218
17:36:42:718 6120 DetectCureTDL3: IrpHandler (3) addr: B838D23C
17:36:42:718 6120 DetectCureTDL3: IrpHandler (4) addr: B838D23C
17:36:42:718 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (9) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (14) addr: B838D180
17:36:42:718 6120 DetectCureTDL3: IrpHandler (15) addr: B83889E6
17:36:42:718 6120 DetectCureTDL3: IrpHandler (16) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (22) addr: B838C5F0
17:36:42:718 6120 DetectCureTDL3: IrpHandler (23) addr: B838AA6E
17:36:42:718 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:718 6120 KLMD_ReadMem: Trying to ReadMemory 0xB8389F26[0x400]
17:36:42:718 6120 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
17:36:42:718 6120 TDL3_FileDetect: Processing driver: usbstor
17:36:42:718 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:36:42:718 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:36:42:718 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
17:36:42:718 6120
17:36:42:718 6120 DetectCureTDL3: DEVICE_OBJECT: 8AA0CAB8
17:36:42:718 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AA0CAB8
17:36:42:718 6120 DetectCureTDL3: DEVICE_OBJECT: 896F2030
17:36:42:718 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 896F2030
17:36:42:718 6120 KLMD_ReadMem: Trying to ReadMemory 0x896F2030[0x38]
17:36:42:718 6120 DetectCureTDL3: DRIVER_OBJECT: 8AA57930
17:36:42:718 6120 KLMD_ReadMem: Trying to ReadMemory 0x8AA57930[0xA8]
17:36:42:718 6120 KLMD_ReadMem: Trying to ReadMemory 0xE1D04458[0x1E]
17:36:42:718 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\usbstor, Driver Name: usbstor
17:36:42:718 6120 DetectCureTDL3: IrpHandler (0) addr: B838D218
17:36:42:718 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (2) addr: B838D218
17:36:42:718 6120 DetectCureTDL3: IrpHandler (3) addr: B838D23C
17:36:42:718 6120 DetectCureTDL3: IrpHandler (4) addr: B838D23C
17:36:42:718 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (9) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (14) addr: B838D180
17:36:42:718 6120 DetectCureTDL3: IrpHandler (15) addr: B83889E6
17:36:42:718 6120 DetectCureTDL3: IrpHandler (16) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (22) addr: B838C5F0
17:36:42:718 6120 DetectCureTDL3: IrpHandler (23) addr: B838AA6E
17:36:42:718 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:718 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:718 6120 KLMD_ReadMem: Trying to ReadMemory 0xB8389F26[0x400]
17:36:42:718 6120 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
17:36:42:718 6120 TDL3_FileDetect: Processing driver: usbstor
17:36:42:718 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:36:42:718 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:36:42:718 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
17:36:42:718 6120
17:36:42:718 6120 DetectCureTDL3: DEVICE_OBJECT: 8950A030
17:36:42:718 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8950A030
17:36:42:718 6120 DetectCureTDL3: DEVICE_OBJECT: 896DF468
17:36:42:718 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 896DF468
17:36:42:718 6120 KLMD_ReadMem: Trying to ReadMemory 0x896DF468[0x38]
17:36:42:734 6120 DetectCureTDL3: DRIVER_OBJECT: 8AA57930
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0x8AA57930[0xA8]
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0xE1D04458[0x1E]
17:36:42:734 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\usbstor, Driver Name: usbstor
17:36:42:734 6120 DetectCureTDL3: IrpHandler (0) addr: B838D218
17:36:42:734 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (2) addr: B838D218
17:36:42:734 6120 DetectCureTDL3: IrpHandler (3) addr: B838D23C
17:36:42:734 6120 DetectCureTDL3: IrpHandler (4) addr: B838D23C
17:36:42:734 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (9) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (14) addr: B838D180
17:36:42:734 6120 DetectCureTDL3: IrpHandler (15) addr: B83889E6
17:36:42:734 6120 DetectCureTDL3: IrpHandler (16) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (22) addr: B838C5F0
17:36:42:734 6120 DetectCureTDL3: IrpHandler (23) addr: B838AA6E
17:36:42:734 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0xB8389F26[0x400]
17:36:42:734 6120 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
17:36:42:734 6120 TDL3_FileDetect: Processing driver: usbstor
17:36:42:734 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:36:42:734 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:36:42:734 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
17:36:42:734 6120
17:36:42:734 6120 DetectCureTDL3: DEVICE_OBJECT: 8AA0D660
17:36:42:734 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AA0D660
17:36:42:734 6120 DetectCureTDL3: DEVICE_OBJECT: 896EA370
17:36:42:734 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 896EA370
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0x896EA370[0x38]
17:36:42:734 6120 DetectCureTDL3: DRIVER_OBJECT: 8AA57930
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0x8AA57930[0xA8]
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0xE1D04458[0x1E]
17:36:42:734 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\usbstor, Driver Name: usbstor
17:36:42:734 6120 DetectCureTDL3: IrpHandler (0) addr: B838D218
17:36:42:734 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (2) addr: B838D218
17:36:42:734 6120 DetectCureTDL3: IrpHandler (3) addr: B838D23C
17:36:42:734 6120 DetectCureTDL3: IrpHandler (4) addr: B838D23C
17:36:42:734 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (9) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (14) addr: B838D180
17:36:42:734 6120 DetectCureTDL3: IrpHandler (15) addr: B83889E6
17:36:42:734 6120 DetectCureTDL3: IrpHandler (16) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (22) addr: B838C5F0
17:36:42:734 6120 DetectCureTDL3: IrpHandler (23) addr: B838AA6E
17:36:42:734 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0xB8389F26[0x400]
17:36:42:734 6120 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
17:36:42:734 6120 TDL3_FileDetect: Processing driver: usbstor
17:36:42:734 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:36:42:734 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:36:42:734 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
17:36:42:734 6120
17:36:42:734 6120 DetectCureTDL3: DEVICE_OBJECT: 8AAC0258
17:36:42:734 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AAC0258
17:36:42:734 6120 DetectCureTDL3: DEVICE_OBJECT: 897A6448
17:36:42:734 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 897A6448
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0x897A6448[0x38]
17:36:42:734 6120 DetectCureTDL3: DRIVER_OBJECT: 8AA57930
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0x8AA57930[0xA8]
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0xE1D04458[0x1E]
17:36:42:734 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\usbstor, Driver Name: usbstor
17:36:42:734 6120 DetectCureTDL3: IrpHandler (0) addr: B838D218
17:36:42:734 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (2) addr: B838D218
17:36:42:734 6120 DetectCureTDL3: IrpHandler (3) addr: B838D23C
17:36:42:734 6120 DetectCureTDL3: IrpHandler (4) addr: B838D23C
17:36:42:734 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (9) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (14) addr: B838D180
17:36:42:734 6120 DetectCureTDL3: IrpHandler (15) addr: B83889E6
17:36:42:734 6120 DetectCureTDL3: IrpHandler (16) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (22) addr: B838C5F0
17:36:42:734 6120 DetectCureTDL3: IrpHandler (23) addr: B838AA6E
17:36:42:734 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0xB8389F26[0x400]
17:36:42:734 6120 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
17:36:42:734 6120 TDL3_FileDetect: Processing driver: usbstor
17:36:42:734 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:36:42:734 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:36:42:734 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
17:36:42:734 6120
17:36:42:734 6120 DetectCureTDL3: DEVICE_OBJECT: 894D8778
17:36:42:734 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 894D8778
17:36:42:734 6120 DetectCureTDL3: DEVICE_OBJECT: 8973A868
17:36:42:734 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8973A868
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0x8973A868[0x38]
17:36:42:734 6120 DetectCureTDL3: DRIVER_OBJECT: 8AA57930
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0x8AA57930[0xA8]
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0xE1D04458[0x1E]
17:36:42:734 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\usbstor, Driver Name: usbstor
17:36:42:734 6120 DetectCureTDL3: IrpHandler (0) addr: B838D218
17:36:42:734 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (2) addr: B838D218
17:36:42:734 6120 DetectCureTDL3: IrpHandler (3) addr: B838D23C
17:36:42:734 6120 DetectCureTDL3: IrpHandler (4) addr: B838D23C
17:36:42:734 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (9) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (14) addr: B838D180
17:36:42:734 6120 DetectCureTDL3: IrpHandler (15) addr: B83889E6
17:36:42:734 6120 DetectCureTDL3: IrpHandler (16) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (22) addr: B838C5F0
17:36:42:734 6120 DetectCureTDL3: IrpHandler (23) addr: B838AA6E
17:36:42:734 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0xB8389F26[0x400]
17:36:42:734 6120 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
17:36:42:734 6120 TDL3_FileDetect: Processing driver: usbstor
17:36:42:734 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:36:42:734 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:36:42:734 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
17:36:42:734 6120
17:36:42:734 6120 DetectCureTDL3: DEVICE_OBJECT: 8AC42C68
17:36:42:734 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8AC42C68
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0x8AC42C68[0x38]
17:36:42:734 6120 DetectCureTDL3: DRIVER_OBJECT: 8ACD4A08
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0x8ACD4A08[0xA8]
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0xE17223C8[0x18]
17:36:42:734 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
17:36:42:734 6120 DetectCureTDL3: IrpHandler (0) addr: B810EC30
17:36:42:734 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (2) addr: B810EC30
17:36:42:734 6120 DetectCureTDL3: IrpHandler (3) addr: B8108D9B
17:36:42:734 6120 DetectCureTDL3: IrpHandler (4) addr: B8108D9B
17:36:42:734 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (9) addr: B8109366
17:36:42:734 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (14) addr: B810944D
17:36:42:734 6120 DetectCureTDL3: IrpHandler (15) addr: B810CFC3
17:36:42:734 6120 DetectCureTDL3: IrpHandler (16) addr: B8109366
17:36:42:734 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (22) addr: B810AEF3
17:36:42:734 6120 DetectCureTDL3: IrpHandler (23) addr: B810FA24
17:36:42:734 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:734 6120 TDL3_FileDetect: Processing driver: Disk
17:36:42:734 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:734 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:734 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
17:36:42:734 6120
17:36:42:734 6120 DetectCureTDL3: DEVICE_OBJECT: 8ACA99F0
17:36:42:734 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8ACA99F0
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0x8ACA99F0[0x38]
17:36:42:734 6120 DetectCureTDL3: DRIVER_OBJECT: 8ACD4A08
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0x8ACD4A08[0xA8]
17:36:42:734 6120 KLMD_ReadMem: Trying to ReadMemory 0xE17223C8[0x18]
17:36:42:734 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
17:36:42:734 6120 DetectCureTDL3: IrpHandler (0) addr: B810EC30
17:36:42:734 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:734 6120 DetectCureTDL3: IrpHandler (2) addr: B810EC30
17:36:42:750 6120 DetectCureTDL3: IrpHandler (3) addr: B8108D9B
17:36:42:750 6120 DetectCureTDL3: IrpHandler (4) addr: B8108D9B
17:36:42:750 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (9) addr: B8109366
17:36:42:750 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (14) addr: B810944D
17:36:42:750 6120 DetectCureTDL3: IrpHandler (15) addr: B810CFC3
17:36:42:750 6120 DetectCureTDL3: IrpHandler (16) addr: B8109366
17:36:42:750 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (22) addr: B810AEF3
17:36:42:750 6120 DetectCureTDL3: IrpHandler (23) addr: B810FA24
17:36:42:750 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:750 6120 TDL3_FileDetect: Processing driver: Disk
17:36:42:750 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:750 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
17:36:42:750 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
17:36:42:750 6120
17:36:42:750 6120 DetectCureTDL3: DEVICE_OBJECT: 8ACC9AB8
17:36:42:750 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8ACC9AB8
17:36:42:750 6120 DetectCureTDL3: DEVICE_OBJECT: 8ACAF9A0
17:36:42:750 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8ACAF9A0
17:36:42:750 6120 DetectCureTDL3: DEVICE_OBJECT: 8ACBBD98
17:36:42:750 6120 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8ACBBD98
17:36:42:750 6120 KLMD_ReadMem: Trying to ReadMemory 0x8ACBBD98[0x38]
17:36:42:750 6120 DetectCureTDL3: DRIVER_OBJECT: 8ACAE900
17:36:42:750 6120 KLMD_ReadMem: Trying to ReadMemory 0x8ACAE900[0xA8]
17:36:42:750 6120 KLMD_ReadMem: Trying to ReadMemory 0xE101D848[0x1A]
17:36:42:750 6120 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
17:36:42:750 6120 DetectCureTDL3: IrpHandler (0) addr: B7F15572
17:36:42:750 6120 DetectCureTDL3: IrpHandler (1) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (2) addr: B7F15572
17:36:42:750 6120 DetectCureTDL3: IrpHandler (3) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (4) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (5) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (6) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (7) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (8) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (9) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (10) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (11) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (12) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (13) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (14) addr: B7F15592
17:36:42:750 6120 DetectCureTDL3: IrpHandler (15) addr: B7F117B4
17:36:42:750 6120 DetectCureTDL3: IrpHandler (16) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (17) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (18) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (19) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (20) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (21) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (22) addr: B7F155BC
17:36:42:750 6120 DetectCureTDL3: IrpHandler (23) addr: B7F1C164
17:36:42:750 6120 DetectCureTDL3: IrpHandler (24) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (25) addr: 804F4476
17:36:42:750 6120 DetectCureTDL3: IrpHandler (26) addr: 804F4476
17:36:42:750 6120 KLMD_ReadMem: Trying to ReadMemory 0xB7F127C6[0x400]
17:36:42:750 6120 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
17:36:42:750 6120 TDL3_FileDetect: Processing driver: atapi
17:36:42:750 6120 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
17:36:42:750 6120 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys
17:36:42:859 6120 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Clean
17:36:42:859 6120
17:36:42:859 6120 Completed
17:36:42:859 6120
17:36:42:859 6120 Results:
17:36:42:859 6120 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
17:36:42:859 6120 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
17:36:42:859 6120 File objects infected / cured / cured on reboot: 0 / 0 / 0
17:36:42:859 6120
17:36:42:859 6120 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
17:36:42:859 6120 UtilityDeinit: KLMD(ARK) unloaded successfully