Posted 16 December 2009 - 11:41 PM
Quietman7
I am attempting to run the Kaspersky Online Virus Scanner.
At this point, it is still updating the database. In the meantime, here is the report.txt that was created by
TDSSKiller.exe running. As I told you, it found nothing, but maybe there's something in there that I missed.
Thanks again for all your help!
Host Name: RICHS64SCREAMER
OS Name: Microsoft® Windows® Server 2003 for Small Business Server
OS Version: 5.2.3790 Service Pack 2 Build 3790
OS Manufacturer: Microsoft Corporation
OS Configuration: Primary Domain Controller
OS Build Type: Uniprocessor Free
Registered Owner: Richard J. Viglienzoni
Registered Organization:
Product ID: 74995-066-1670106-42514
Original Install Date: 4/25/2005, 3:48:16 PM
System Up Time: 0 Days, 1 Hours, 15 Minutes, 33 Seconds
System Manufacturer: VIAK8M
System Model: AWRDACPI
System Type: X86-based PC
Processor(s): 1 Processor(s) Installed.
[01]: x86 Family 15 Model 12 Stepping 0 AuthenticAMD ~1999 Mhz
BIOS Version: VIAK8M - 42302e31
Windows Directory: C:\WINDOWS
System Directory: C:\WINDOWS\system32
Boot Device: \Device\HarddiskVolume1
System Locale: en-us;English (United States)
Input Locale: en-us;English (United States)
Time Zone: (GMT-08:00) Pacific Time (US & Canada)
Total Physical Memory: 1,022 MB
Available Physical Memory: 301 MB
Page File: Max Size: 1,701 MB
Page File: Available: 751 MB
Page File: In Use: 950 MB
Page File Location(s): C:\pagefile.sys
Domain: Viglienzoni.local
Logon Server: \\RICHS64SCREAMER
Hotfix(s): 292 Hotfix(s) Installed.
[01]: File 1
[02]: File 1
[03]: File 1
[04]: File 1
[05]: File 1
[06]: File 1
[07]: File 1
[08]: File 1
[09]: File 1
[10]: File 1
[11]: File 1
[12]: File 1
[13]: File 1
[14]: File 1
[15]: File 1
[16]: File 1
[17]: File 1
[18]: File 1
[19]: File 1
[20]: File 1
[21]: File 1
[22]: File 1
[23]: File 1
[24]: File 1
[25]: File 1
[26]: File 1
[27]: File 1
[28]: File 1
[29]: File 1
[30]: File 1
[31]: File 1
[32]: File 1
[33]: File 1
[34]: File 1
[35]: File 1
[36]: File 1
[37]: File 1
[38]: File 1
[39]: File 1
[40]: File 1
[41]: File 1
[42]: File 1
[43]: File 1
[44]: File 1
[45]: File 1
[46]: File 1
[47]: File 1
[48]: File 1
[49]: File 1
[50]: File 1
[51]: File 1
[52]: File 1
[53]: File 1
[54]: File 1
[55]: File 1
[56]: File 1
[57]: File 1
[58]: File 1
[59]: File 1
[60]: File 1
[61]: File 1
[62]: File 1
[63]: File 1
[64]: File 1
[65]: File 1
[66]: File 1
[67]: File 1
[68]: File 1
[69]: File 1
[70]: File 1
[71]: File 1
[72]: File 1
[73]: File 1
[74]: File 1
[75]: File 1
[76]: File 1
[77]: File 1
[78]: File 1
[79]: File 1
[80]: File 1
[81]: File 1
[82]: File 1
[83]: File 1
[84]: File 1
[85]: File 1
[86]: File 1
[87]: File 1
[88]: File 1
[89]: File 1
[90]: File 1
[91]: File 1
[92]: File 1
[93]: File 1
[94]: File 1
[95]: File 1
[96]: File 1
[97]: File 1
[98]: File 1
[99]: File 1
[100]: File 1
[101]: File 1
[102]: File 1
[103]: File 1
[104]: File 1
[105]: File 1
[106]: File 1
[107]: File 1
[108]: File 1
[109]: File 1
[110]: File 1
[111]: File 1
[112]: File 1
[113]: File 1
[114]: File 1
[115]: File 1
[116]: File 1
[117]: File 1
[118]: File 1
[119]: File 1
[120]: File 1
[121]: File 1
[122]: File 1
[123]: File 1
[124]: File 1
[125]: File 1
[126]: File 1
[127]: File 1
[128]: File 1
[129]: File 1
[130]: File 1
[131]: File 1
[132]: File 1
[133]: File 1
[134]: File 1
[135]: File 1
[136]: Q147222
[137]: KB867460 - QFE
[138]: KB886903 - QFE
[139]: KB933854 - QFE
[140]: KB953298 - QFE
[141]: SP1 - SP
[142]: KB870669
[143]: Q832483
[144]: Q927978
[145]: Q936181
[146]: Q954430
[147]: Q973688
[148]: IDNMitigationAPIs - Update
[149]: NLSDownlevelMapping - Update
[150]: Q828026
[151]: Q828026 - Update
[152]: KB925398_WMP64
[153]: KB917734_WMP9
[154]: KB885492 - Update
[155]: KB938127-IE7 - Update
[156]: KB942615-IE7 - Update
[157]: KB944533-IE7 - Update
[158]: KB947864-IE7 - Update
[159]: KB950759-IE7 - Update
[160]: KB953838-IE7 - Update
[161]: KB968220-IE8 - Update
[162]: KB969897-IE8 - Update
[163]: KB971961-IE8 - Update
[164]: KB972260-IE8 - Update
[165]: KB974455-IE8 - Update
[166]: KB976325-IE8 - Update
[167]: KB976749-IE8 - Update
[168]: KB914961 - Service Pack
[169]: KB923561 - Update
[170]: KB925876 - Update
[171]: KB925902 - Update
[172]: KB927891 - Update
[173]: KB929123 - Update
[174]: KB930178 - Update
[175]: KB931784 - Update
[176]: KB931836 - Update
[177]: KB932168 - Update
[178]: KB933729 - Update
[179]: KB933854 - Update
[180]: KB935839 - Update
[181]: KB935840 - Update
[182]: KB936021 - Update
[183]: KB936782 - Update
[184]: KB938127 - Update
[185]: KB938464 - Update
[186]: KB941202 - Update
[187]: KB941568 - Update
[188]: KB941569 - Update
[189]: KB941644 - Update
[190]: KB941672 - Update
[191]: KB941693 - Update
[192]: KB942763 - Update
[193]: KB942830 - Update
[194]: KB942831 - Update
[195]: KB942840 - Update
[196]: KB943055 - Update
[197]: KB943460 - Update
[198]: KB943484 - Update
[199]: KB943485 - Update
[200]: KB944533 - Update
[201]: KB944653 - Update
[202]: KB945553 - Update
[203]: KB946026 - Update
[204]: KB948496 - Update
[205]: KB948590 - Update
[206]: KB948745 - Update
[207]: KB948881 - Update
[208]: KB949014 - Update
[209]: KB950760 - Update
[210]: KB950762 - Update
[211]: KB950974 - Update
[212]: KB951066 - Update
[213]: KB951072-v2 - Update
[214]: KB951698 - Update
[215]: KB951746 - Update
[216]: KB951748 - Update
[217]: KB952004 - Update
[218]: KB952069 - Update
[219]: KB952954 - Update
[220]: KB953298 - Update
[221]: KB953839 - Update
[222]: KB954155 - Update
[223]: KB954211 - Update
[224]: KB954600 - Update
[225]: KB955069 - Update
[226]: KB955839 - Update
[227]: KB956391 - Update
[228]:
Network Card(s): 2 NIC(s) Installed.
[01]: Realtek RTL8139/810x Family Fast Ethernet NIC
Connection Name: Server Local Area Connection
DHCP Enabled: Yes
DHCP Server: 192.168.0.1
IP address(es)
[01]: 192.168.0.201
[02]: 1394 Net Adapter
Connection Name: 1394 Connection
DHCP Enabled: Yes
DHCP Server: N/A
IP address(es)
12:7:52:765 2388 ForceUnloadDriver: NtUnloadDriver error 2
12:7:52:765 2388 ForceUnloadDriver: NtUnloadDriver error 2
12:7:52:765 2388 ForceUnloadDriver: NtUnloadDriver error 2
12:7:52:765 2388 main: Driver KLMD successfully dropped
12:7:53:78 2388 main: Driver KLMD successfully loaded
12:7:53:78 2388
Scanning Registry ...
12:7:53:156 2388 ScanServices: Searching service UACd.sys
12:7:53:156 2388 ScanServices: Open/Create key error 2
12:7:53:156 2388 ScanServices: Searching service TDSSserv.sys
12:7:53:156 2388 ScanServices: Open/Create key error 2
12:7:53:156 2388 ScanServices: Searching service gaopdxserv.sys
12:7:53:156 2388 ScanServices: Open/Create key error 2
12:7:53:156 2388 ScanServices: Searching service gxvxcserv.sys
12:7:53:156 2388 ScanServices: Open/Create key error 2
12:7:53:156 2388 ScanServices: Searching service MSIVXserv.sys
12:7:53:156 2388 ScanServices: Open/Create key error 2
12:7:53:156 2388 UnhookRegistry: Kernel module file name: C:\windows\system32\ntkrnlpa.exe, base addr: 80800000
12:7:53:187 2388 UnhookRegistry: Kernel local addr: A40000
12:7:53:187 2388 UnhookRegistry: KeServiceDescriptorTable addr: ADF460
12:7:53:281 2388 UnhookRegistry: KiServiceTable addr: A70F78
12:7:53:281 2388 UnhookRegistry: NtEnumerateKey service number (local): 4B
12:7:53:281 2388 UnhookRegistry: NtEnumerateKey local addr: AF2154
12:7:53:296 2388 KLMD_OpenDevice: Trying to open KLMD device
12:7:53:296 2388 KLMD_GetSystemRoutineAddressA: Trying to get system routine address ZwEnumerateKey
12:7:53:296 2388 KLMD_GetSystemRoutineAddressW: Trying to get system routine address ZwEnumerateKey
12:7:53:296 2388 KLMD_ReadMem: Trying to ReadMemory 0x8082CCAD[0x4]
12:7:53:296 2388 UnhookRegistry: NtEnumerateKey service number (kernel): 4B
12:7:53:296 2388 KLMD_ReadMem: Trying to ReadMemory 0x808310A4[0x4]
12:7:53:296 2388 UnhookRegistry: NtEnumerateKey real addr: 808B2154
12:7:53:296 2388 UnhookRegistry: NtEnumerateKey calc addr: 808B2154
12:7:53:296 2388 UnhookRegistry: No SDT hooks found on NtEnumerateKey
12:7:53:296 2388 KLMD_ReadMem: Trying to ReadMemory 0x808B2154[0xA]
12:7:53:296 2388 UnhookRegistry: No splicing found on NtEnumerateKey
12:7:53:296 2388
Scanning Kernel memory ...
12:7:53:296 2388 KLMD_OpenDevice: Trying to open KLMD device
12:7:53:296 2388 KLMD_GetSystemObjectAddressByNameA: Trying to get system object address by name \Driver\Disk
12:7:53:296 2388 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
12:7:53:296 2388 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 869A5E40
12:7:53:296 2388 DetectCureTDL3: KLMD_GetDeviceObjectList returned 5 DevObjects
12:7:53:296 2388 DetectCureTDL3: 0 Curr stack PDEVICE_OBJECT: 86942030
12:7:53:296 2388 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86942030
12:7:53:296 2388 KLMD_ReadMem: Trying to ReadMemory 0x86942030[0x38]
12:7:53:296 2388 DetectCureTDL3: DRIVER_OBJECT addr: 869A5E40
12:7:53:296 2388 KLMD_ReadMem: Trying to ReadMemory 0x869A5E40[0xA8]
12:7:53:296 2388 KLMD_ReadMem: Trying to ReadMemory 0xE18FD788[0x208]
12:7:53:296 2388 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
12:7:53:296 2388 DetectCureTDL3: IrpHandler (0) addr: F727A1E0
12:7:53:296 2388 DetectCureTDL3: IrpHandler (1) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (2) addr: F727A1E0
12:7:53:296 2388 DetectCureTDL3: IrpHandler (3) addr: F7271485
12:7:53:296 2388 DetectCureTDL3: IrpHandler (4) addr: F7271485
12:7:53:296 2388 DetectCureTDL3: IrpHandler (5) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (6) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (7) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (8) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (9) addr: F7271E9A
12:7:53:296 2388 DetectCureTDL3: IrpHandler (10) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (11) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (12) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (13) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (14) addr: F7272208
12:7:53:296 2388 DetectCureTDL3: IrpHandler (15) addr: F72764C1
12:7:53:296 2388 DetectCureTDL3: IrpHandler (16) addr: F7271E9A
12:7:53:296 2388 DetectCureTDL3: IrpHandler (17) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (18) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (19) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (20) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (21) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (22) addr: F7273D14
12:7:53:296 2388 DetectCureTDL3: IrpHandler (23) addr: F727C264
12:7:53:296 2388 DetectCureTDL3: IrpHandler (24) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (25) addr: 8082063E
12:7:53:296 2388 DetectCureTDL3: IrpHandler (26) addr: 8082063E
12:7:53:296 2388 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]
12:7:53:296 2388 KLMD_ReadMem: DeviceIoControl error 1
12:7:53:296 2388 TDL3_StartIoHookDetect: Unable to get StartIo handler code
12:7:53:296 2388 TDL3_FileDetect: Processing driver: Disk
12:7:53:296 2388 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\tsk_disk.sys, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\tsk_disk.sys
12:7:53:296 2388 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys
12:7:53:296 2388 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys
12:7:53:343 2388 DetectCureTDL3: 1 Curr stack PDEVICE_OBJECT: 869A6C68
12:7:53:343 2388 KLMD_GetLowerDeviceObject: Trying to get lower device object for 869A6C68
12:7:53:343 2388 KLMD_ReadMem: Trying to ReadMemory 0x869A6C68[0x38]
12:7:53:343 2388 DetectCureTDL3: DRIVER_OBJECT addr: 869A5E40
12:7:53:343 2388 KLMD_ReadMem: Trying to ReadMemory 0x869A5E40[0xA8]
12:7:53:343 2388 KLMD_ReadMem: Trying to ReadMemory 0xE18FD788[0x208]
12:7:53:343 2388 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
12:7:53:343 2388 DetectCureTDL3: IrpHandler (0) addr: F727A1E0
12:7:53:343 2388 DetectCureTDL3: IrpHandler (1) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (2) addr: F727A1E0
12:7:53:343 2388 DetectCureTDL3: IrpHandler (3) addr: F7271485
12:7:53:343 2388 DetectCureTDL3: IrpHandler (4) addr: F7271485
12:7:53:343 2388 DetectCureTDL3: IrpHandler (5) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (6) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (7) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (8) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (9) addr: F7271E9A
12:7:53:343 2388 DetectCureTDL3: IrpHandler (10) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (11) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (12) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (13) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (14) addr: F7272208
12:7:53:343 2388 DetectCureTDL3: IrpHandler (15) addr: F72764C1
12:7:53:343 2388 DetectCureTDL3: IrpHandler (16) addr: F7271E9A
12:7:53:343 2388 DetectCureTDL3: IrpHandler (17) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (18) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (19) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (20) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (21) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (22) addr: F7273D14
12:7:53:343 2388 DetectCureTDL3: IrpHandler (23) addr: F727C264
12:7:53:343 2388 DetectCureTDL3: IrpHandler (24) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (25) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (26) addr: 8082063E
12:7:53:343 2388 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]
12:7:53:343 2388 KLMD_ReadMem: DeviceIoControl error 1
12:7:53:343 2388 TDL3_StartIoHookDetect: Unable to get StartIo handler code
12:7:53:343 2388 TDL3_FileDetect: Processing driver: Disk
12:7:53:343 2388 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\tsk_disk.sys, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\tsk_disk.sys
12:7:53:343 2388 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys
12:7:53:343 2388 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys
12:7:53:343 2388 DetectCureTDL3: 2 Curr stack PDEVICE_OBJECT: 869A6030
12:7:53:343 2388 KLMD_GetLowerDeviceObject: Trying to get lower device object for 869A6030
12:7:53:343 2388 KLMD_ReadMem: Trying to ReadMemory 0x869A6030[0x38]
12:7:53:343 2388 DetectCureTDL3: DRIVER_OBJECT addr: 869A5E40
12:7:53:343 2388 KLMD_ReadMem: Trying to ReadMemory 0x869A5E40[0xA8]
12:7:53:343 2388 KLMD_ReadMem: Trying to ReadMemory 0xE18FD788[0x208]
12:7:53:343 2388 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
12:7:53:343 2388 DetectCureTDL3: IrpHandler (0) addr: F727A1E0
12:7:53:343 2388 DetectCureTDL3: IrpHandler (1) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (2) addr: F727A1E0
12:7:53:343 2388 DetectCureTDL3: IrpHandler (3) addr: F7271485
12:7:53:343 2388 DetectCureTDL3: IrpHandler (4) addr: F7271485
12:7:53:343 2388 DetectCureTDL3: IrpHandler (5) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (6) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (7) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (8) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (9) addr: F7271E9A
12:7:53:343 2388 DetectCureTDL3: IrpHandler (10) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (11) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (12) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (13) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (14) addr: F7272208
12:7:53:343 2388 DetectCureTDL3: IrpHandler (15) addr: F72764C1
12:7:53:343 2388 DetectCureTDL3: IrpHandler (16) addr: F7271E9A
12:7:53:343 2388 DetectCureTDL3: IrpHandler (17) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (18) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (19) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (20) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (21) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (22) addr: F7273D14
12:7:53:343 2388 DetectCureTDL3: IrpHandler (23) addr: F727C264
12:7:53:343 2388 DetectCureTDL3: IrpHandler (24) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (25) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (26) addr: 8082063E
12:7:53:343 2388 KLMD_ReadMem: Trying to ReadMemory 0x0[0x400]
12:7:53:343 2388 KLMD_ReadMem: DeviceIoControl error 1
12:7:53:343 2388 TDL3_StartIoHookDetect: Unable to get StartIo handler code
12:7:53:343 2388 TDL3_FileDetect: Processing driver: Disk
12:7:53:343 2388 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\disk.sys, C:\WINDOWS\system32\Drivers\tsk_disk.sys, SYSTEM\CurrentControlSet\Services\Disk, system32\Drivers\tsk_disk.sys
12:7:53:343 2388 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\disk.sys
12:7:53:343 2388 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\disk.sys
12:7:53:343 2388 DetectCureTDL3: 3 Curr stack PDEVICE_OBJECT: 8696B030
12:7:53:343 2388 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8696B030
12:7:53:343 2388 DetectCureTDL3: 3 Curr stack PDEVICE_OBJECT: 869269E8
12:7:53:343 2388 KLMD_GetLowerDeviceObject: Trying to get lower device object for 869269E8
12:7:53:343 2388 DetectCureTDL3: 3 Curr stack PDEVICE_OBJECT: 86926B00
12:7:53:343 2388 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86926B00
12:7:53:343 2388 KLMD_ReadMem: Trying to ReadMemory 0x86926B00[0x38]
12:7:53:343 2388 DetectCureTDL3: DRIVER_OBJECT addr: 86946950
12:7:53:343 2388 KLMD_ReadMem: Trying to ReadMemory 0x86946950[0xA8]
12:7:53:343 2388 KLMD_ReadMem: Trying to ReadMemory 0xE18FF2F0[0x208]
12:7:53:343 2388 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
12:7:53:343 2388 DetectCureTDL3: IrpHandler (0) addr: F72ADB88
12:7:53:343 2388 DetectCureTDL3: IrpHandler (1) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (2) addr: F72ADB88
12:7:53:343 2388 DetectCureTDL3: IrpHandler (3) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (4) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (5) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (6) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (7) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (8) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (9) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (10) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (11) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (12) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (13) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (14) addr: F72ADBA8
12:7:53:343 2388 DetectCureTDL3: IrpHandler (15) addr: F72A98E6
12:7:53:343 2388 DetectCureTDL3: IrpHandler (16) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (17) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (18) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (19) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (20) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (21) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (22) addr: F72ADBD2
12:7:53:343 2388 DetectCureTDL3: IrpHandler (23) addr: F72B60A0
12:7:53:343 2388 DetectCureTDL3: IrpHandler (24) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (25) addr: 8082063E
12:7:53:343 2388 DetectCureTDL3: IrpHandler (26) addr: 8082063E
12:7:53:343 2388 KLMD_ReadMem: Trying to ReadMemory 0xF72A9E2E[0x400]
12:7:53:343 2388 TDL3_StartIoHookDetect: CheckParameters: 0, 0, 316, 0
12:7:53:343 2388 TDL3_FileDetect: Processing driver: atapi
12:7:53:343 2388 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\atapi.sys, C:\WINDOWS\system32\Drivers\tsk_atapi.sys, SYSTEM\CurrentControlSet\Services\atapi, system32\Drivers\tsk_atapi.sys
12:7:53:343 2388 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\atapi.sys
12:7:53:343 2388 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\atapi.sys
12:7:53:359 2388 DetectCureTDL3: 4 Curr stack PDEVICE_OBJECT: 869A8030
12:7:53:359 2388 KLMD_GetLowerDeviceObject: Trying to get lower device object for 869A8030
12:7:53:359 2388 DetectCureTDL3: 4 Curr stack PDEVICE_OBJECT: 8696CC80
12:7:53:359 2388 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8696CC80
12:7:53:359 2388 DetectCureTDL3: 4 Curr stack PDEVICE_OBJECT: 8696C948
12:7:53:359 2388 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8696C948
12:7:53:359 2388 KLMD_ReadMem: Trying to ReadMemory 0x8696C948[0x38]
12:7:53:359 2388 DetectCureTDL3: DRIVER_OBJECT addr: 86946950
12:7:53:359 2388 KLMD_ReadMem: Trying to ReadMemory 0x86946950[0xA8]
12:7:53:359 2388 KLMD_ReadMem: Trying to ReadMemory 0xE18FF2F0[0x208]
12:7:53:359 2388 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
12:7:53:359 2388 DetectCureTDL3: IrpHandler (0) addr: F72ADB88
12:7:53:359 2388 DetectCureTDL3: IrpHandler (1) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (2) addr: F72ADB88
12:7:53:359 2388 DetectCureTDL3: IrpHandler (3) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (4) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (5) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (6) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (7) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (8) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (9) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (10) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (11) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (12) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (13) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (14) addr: F72ADBA8
12:7:53:359 2388 DetectCureTDL3: IrpHandler (15) addr: F72A98E6
12:7:53:359 2388 DetectCureTDL3: IrpHandler (16) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (17) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (18) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (19) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (20) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (21) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (22) addr: F72ADBD2
12:7:53:359 2388 DetectCureTDL3: IrpHandler (23) addr: F72B60A0
12:7:53:359 2388 DetectCureTDL3: IrpHandler (24) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (25) addr: 8082063E
12:7:53:359 2388 DetectCureTDL3: IrpHandler (26) addr: 8082063E
12:7:53:359 2388 KLMD_ReadMem: Trying to ReadMemory 0xF72A9E2E[0x400]
12:7:53:359 2388 TDL3_StartIoHookDetect: CheckParameters: 0, 0, 316, 0
12:7:53:359 2388 TDL3_FileDetect: Processing driver: atapi
12:7:53:359 2388 TDL3_FileDetect: Parameters: C:\WINDOWS\system32\drivers\atapi.sys, C:\WINDOWS\system32\Drivers\tsk_atapi.sys, SYSTEM\CurrentControlSet\Services\atapi, system32\Drivers\tsk_atapi.sys
12:7:53:359 2388 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\atapi.sys
12:7:53:359 2388 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\atapi.sys
12:7:53:359 2388
Completed
Results:
12:7:53:359 2388 Infected objects in memory: 0
12:7:53:359 2388 Cured objects in memory: 0
12:7:53:359 2388 Infected objects on disk: 0
12:7:53:359 2388 Objects on disk cured on reboot: 0
12:7:53:359 2388 Objects on disk deleted on reboot: 0
12:7:53:359 2388 Registry nodes deleted on reboot: 0
12:7:53:359 2388