I thought maybe I should post some logs of what ive done so far to help get the ball rolling.
10:03:15:671 3688 TDSS rootkit removing tool 2.2.8.1 Mar 22 2010 10:43:04
10:03:15:671 3688 ================================================================================
10:03:15:671 3688 SystemInfo:
10:03:15:671 3688 OS Version: 5.1.2600 ServicePack: 2.0
10:03:15:671 3688 Product type: Workstation
10:03:15:671 3688 ComputerName: YOUR-631F5B18CA
10:03:15:671 3688 UserName: Owner
10:03:15:671 3688 Windows directory: C:\WINDOWS
10:03:15:671 3688 Processor architecture: Intel x86
10:03:15:671 3688 Number of processors: 1
10:03:15:671 3688 Page size: 0x1000
10:03:15:671 3688 Boot type: Normal boot
10:03:15:671 3688 ================================================================================
10:03:15:671 3688 UnloadDriverW: NtUnloadDriver error 2
10:03:15:671 3688 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
10:03:16:234 3688 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
10:03:16:234 3688 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
10:03:16:234 3688 wfopen_ex: Trying to KLMD file open
10:03:16:234 3688 wfopen_ex: File opened ok (Flags 2)
10:03:16:265 3688 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
10:03:16:265 3688 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
10:03:16:265 3688 wfopen_ex: Trying to KLMD file open
10:03:16:265 3688 wfopen_ex: File opened ok (Flags 2)
10:03:16:265 3688 Initialize success
10:03:16:265 3688
10:03:16:265 3688 Scanning Services ...
10:03:17:468 3688 Raw services enum returned 345 services
10:03:17:500 3688
10:03:17:500 3688 Scanning Kernel memory ...
10:03:17:500 3688 Devices to scan: 3
10:03:17:500 3688
10:03:17:500 3688 Driver Name: Disk
10:03:17:500 3688 IRP_MJ_CREATE : F76D2C30
10:03:17:500 3688 IRP_MJ_CREATE_NAMED_PIPE : 804F3418
10:03:17:500 3688 IRP_MJ_CLOSE : F76D2C30
10:03:17:500 3688 IRP_MJ_READ : F76CCD9B
10:03:17:500 3688 IRP_MJ_WRITE : F76CCD9B
10:03:17:500 3688 IRP_MJ_QUERY_INFORMATION : 804F3418
10:03:17:500 3688 IRP_MJ_SET_INFORMATION : 804F3418
10:03:17:500 3688 IRP_MJ_QUERY_EA : 804F3418
10:03:17:500 3688 IRP_MJ_SET_EA : 804F3418
10:03:17:500 3688 IRP_MJ_FLUSH_BUFFERS : F76CD366
10:03:17:500 3688 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F3418
10:03:17:500 3688 IRP_MJ_SET_VOLUME_INFORMATION : 804F3418
10:03:17:500 3688 IRP_MJ_DIRECTORY_CONTROL : 804F3418
10:03:17:500 3688 IRP_MJ_FILE_SYSTEM_CONTROL : 804F3418
10:03:17:500 3688 IRP_MJ_DEVICE_CONTROL : F76CD44D
10:03:17:500 3688 IRP_MJ_INTERNAL_DEVICE_CONTROL : F76D0FC3
10:03:17:500 3688 IRP_MJ_SHUTDOWN : F76CD366
10:03:17:500 3688 IRP_MJ_LOCK_CONTROL : 804F3418
10:03:17:500 3688 IRP_MJ_CLEANUP : 804F3418
10:03:17:500 3688 IRP_MJ_CREATE_MAILSLOT : 804F3418
10:03:17:500 3688 IRP_MJ_QUERY_SECURITY : 804F3418
10:03:17:500 3688 IRP_MJ_SET_SECURITY : 804F3418
10:03:17:500 3688 IRP_MJ_POWER : F76CEEF3
10:03:17:500 3688 IRP_MJ_SYSTEM_CONTROL : F76D3A24
10:03:17:500 3688 IRP_MJ_DEVICE_CHANGE : 804F3418
10:03:17:500 3688 IRP_MJ_QUERY_QUOTA : 804F3418
10:03:17:500 3688 IRP_MJ_SET_QUOTA : 804F3418
10:03:17:578 3688 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
10:03:17:578 3688
10:03:17:578 3688 Driver Name: Disk
10:03:17:578 3688 IRP_MJ_CREATE : F76D2C30
10:03:17:578 3688 IRP_MJ_CREATE_NAMED_PIPE : 804F3418
10:03:17:578 3688 IRP_MJ_CLOSE : F76D2C30
10:03:17:578 3688 IRP_MJ_READ : F76CCD9B
10:03:17:578 3688 IRP_MJ_WRITE : F76CCD9B
10:03:17:578 3688 IRP_MJ_QUERY_INFORMATION : 804F3418
10:03:17:578 3688 IRP_MJ_SET_INFORMATION : 804F3418
10:03:17:578 3688 IRP_MJ_QUERY_EA : 804F3418
10:03:17:578 3688 IRP_MJ_SET_EA : 804F3418
10:03:17:578 3688 IRP_MJ_FLUSH_BUFFERS : F76CD366
10:03:17:578 3688 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F3418
10:03:17:578 3688 IRP_MJ_SET_VOLUME_INFORMATION : 804F3418
10:03:17:578 3688 IRP_MJ_DIRECTORY_CONTROL : 804F3418
10:03:17:578 3688 IRP_MJ_FILE_SYSTEM_CONTROL : 804F3418
10:03:17:578 3688 IRP_MJ_DEVICE_CONTROL : F76CD44D
10:03:17:578 3688 IRP_MJ_INTERNAL_DEVICE_CONTROL : F76D0FC3
10:03:17:578 3688 IRP_MJ_SHUTDOWN : F76CD366
10:03:17:578 3688 IRP_MJ_LOCK_CONTROL : 804F3418
10:03:17:578 3688 IRP_MJ_CLEANUP : 804F3418
10:03:17:578 3688 IRP_MJ_CREATE_MAILSLOT : 804F3418
10:03:17:578 3688 IRP_MJ_QUERY_SECURITY : 804F3418
10:03:17:578 3688 IRP_MJ_SET_SECURITY : 804F3418
10:03:17:578 3688 IRP_MJ_POWER : F76CEEF3
10:03:17:578 3688 IRP_MJ_SYSTEM_CONTROL : F76D3A24
10:03:17:578 3688 IRP_MJ_DEVICE_CHANGE : 804F3418
10:03:17:578 3688 IRP_MJ_QUERY_QUOTA : 804F3418
10:03:17:578 3688 IRP_MJ_SET_QUOTA : 804F3418
10:03:17:593 3688 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
10:03:17:593 3688
10:03:17:593 3688 Driver Name: atapi
10:03:17:593 3688 IRP_MJ_CREATE : 846E2AC8
10:03:17:593 3688 IRP_MJ_CREATE_NAMED_PIPE : 846E2AC8
10:03:17:593 3688 IRP_MJ_CLOSE : 846E2AC8
10:03:17:593 3688 IRP_MJ_READ : 846E2AC8
10:03:17:593 3688 IRP_MJ_WRITE : 846E2AC8
10:03:17:593 3688 IRP_MJ_QUERY_INFORMATION : 846E2AC8
10:03:17:593 3688 IRP_MJ_SET_INFORMATION : 846E2AC8
10:03:17:593 3688 IRP_MJ_QUERY_EA : 846E2AC8
10:03:17:593 3688 IRP_MJ_SET_EA : 846E2AC8
10:03:17:593 3688 IRP_MJ_FLUSH_BUFFERS : 846E2AC8
10:03:17:593 3688 IRP_MJ_QUERY_VOLUME_INFORMATION : 846E2AC8
10:03:17:593 3688 IRP_MJ_SET_VOLUME_INFORMATION : 846E2AC8
10:03:17:593 3688 IRP_MJ_DIRECTORY_CONTROL : 846E2AC8
10:03:17:593 3688 IRP_MJ_FILE_SYSTEM_CONTROL : 846E2AC8
10:03:17:593 3688 IRP_MJ_DEVICE_CONTROL : 846E2AC8
10:03:17:593 3688 IRP_MJ_INTERNAL_DEVICE_CONTROL : 846E2AC8
10:03:17:593 3688 IRP_MJ_SHUTDOWN : 846E2AC8
10:03:17:593 3688 IRP_MJ_LOCK_CONTROL : 846E2AC8
10:03:17:593 3688 IRP_MJ_CLEANUP : 846E2AC8
10:03:17:593 3688 IRP_MJ_CREATE_MAILSLOT : 846E2AC8
10:03:17:593 3688 IRP_MJ_QUERY_SECURITY : 846E2AC8
10:03:17:593 3688 IRP_MJ_SET_SECURITY : 846E2AC8
10:03:17:593 3688 IRP_MJ_POWER : 846E2AC8
10:03:17:593 3688 IRP_MJ_SYSTEM_CONTROL : 846E2AC8
10:03:17:593 3688 IRP_MJ_DEVICE_CHANGE : 846E2AC8
10:03:17:593 3688 IRP_MJ_QUERY_QUOTA : 846E2AC8
10:03:17:593 3688 IRP_MJ_SET_QUOTA : 846E2AC8
10:03:17:593 3688 Driver "atapi" infected by TDSS rootkit!
10:03:17:640 3688 C:\WINDOWS\system32\drivers\atapi.sys - Verdict: 1
10:03:17:640 3688 File "C:\WINDOWS\system32\drivers\atapi.sys" infected by TDSS rootkit ... 10:03:17:656 3688 Processing driver file: C:\WINDOWS\system32\drivers\atapi.sys
10:03:17:656 3688 ProcessDirEnumEx: FindFirstFile(C:\WINDOWS\system32\DriverStore\FileRepository\*) error 3
10:03:18:390 3688 vfvi6
10:03:18:562 3688 !dsvbh1
10:03:21:484 3688 dsvbh2
10:03:21:484 3688 fdfb2
10:03:21:484 3688 Backup copy found, using it..
10:03:21:531 3688 will be cured on next reboot
10:03:21:531 3688 Reboot required for cure complete..
10:03:21:890 3688 Cure on reboot scheduled successfully
10:03:21:890 3688
10:03:21:890 3688 Completed
10:03:21:890 3688
10:03:21:890 3688 Results:
10:03:21:890 3688 Memory objects infected / cured / cured on reboot: 1 / 0 / 0
10:03:21:890 3688 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
10:03:21:890 3688 File objects infected / cured / cured on reboot: 1 / 0 / 1
10:03:21:921 3688
10:03:21:921 3688 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
10:03:21:921 3688 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
10:03:21:921 3688 UnloadDriverW: NtUnloadDriver error 1
10:03:21:937 3688 KLMD(ARK) unloaded successfully
Edited by Bodazephyr, 16 April 2010 - 01:54 PM.