Yes, my friend built this machine from parts he had laying around.
18:22:54:218 3484 TDSS rootkit removing tool 2.2.2 Jan 13 2010 08:42:25
18:22:54:218 3484 ============================================================ ====================
18:22:54:218 3484 SystemInfo:
18:22:54:218 3484 OS Version: 5.1.2600 ServicePack: 3.0
18:22:54:218 3484 Product type: Workstation
18:22:54:218 3484 ComputerName: DEN
18:22:54:218 3484 UserName: Jason
18:22:54:218 3484 Windows directory: C:\WINDOWS
18:22:54:218 3484 Processor architecture: Intel x86
18:22:54:218 3484 Number of processors: 2
18:22:54:218 3484 Page size: 0x1000
18:22:54:218 3484 Boot type: Normal boot
18:22:54:218 3484 ============================================================ ====================
18:22:54:218 3484 UnloadDriverW: NtUnloadDriver error 2
18:22:54:218 3484 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
18:22:54:218 3484 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
18:22:54:234 3484 UtilityInit: KLMD drop and load success
18:22:54:234 3484 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201000)
18:22:54:234 3484 UtilityInit: KLMD open success
18:22:54:234 3484 UtilityInit: Initialize success
18:22:54:234 3484
18:22:54:234 3484 Scanning Services ...
18:22:54:234 3484 CreateRegParser: Registry parser init started
18:22:54:234 3484 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
18:22:54:234 3484 CreateRegParser: DisableWow64Redirection error
18:22:54:234 3484 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
18:22:54:234 3484 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043
18:22:54:234 3484 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
18:22:54:234 3484 wfopen_ex: Trying to KLMD file open
18:22:54:234 3484 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system
18:22:54:234 3484 wfopen_ex: File opened ok (Flags 2)
18:22:54:234 3484 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: 384868
18:22:54:234 3484 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
18:22:54:234 3484 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043
18:22:54:234 3484 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
18:22:54:234 3484 wfopen_ex: Trying to KLMD file open
18:22:54:234 3484 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software
18:22:54:234 3484 wfopen_ex: File opened ok (Flags 2)
18:22:54:234 3484 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: 384910
18:22:54:234 3484 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
18:22:54:234 3484 CreateRegParser: EnableWow64Redirection error
18:22:54:234 3484 CreateRegParser: RegParser init completed
18:22:54:281 3484 GetAdvancedServicesInfo: Raw services enum returned 310 services
18:22:54:296 3484 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
18:22:54:296 3484 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
18:22:54:296 3484
18:22:54:296 3484 Scanning Kernel memory ...
18:22:54:296 3484 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
18:22:54:296 3484 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 89D82A48
18:22:54:296 3484 DetectCureTDL3: KLMD_GetDeviceObjectList returned 3 DevObjects
18:22:54:296 3484
18:22:54:296 3484 DetectCureTDL3: DEVICE_OBJECT: 89D3C8A0
18:22:54:296 3484 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89D3C8A0
18:22:54:296 3484 KLMD_ReadMem: Trying to ReadMemory 0x89D3C8A0[0x38]
18:22:54:296 3484 DetectCureTDL3: DRIVER_OBJECT: 89D82A48
18:22:54:296 3484 KLMD_ReadMem: Trying to ReadMemory 0x89D82A48[0xA8]
18:22:54:296 3484 KLMD_ReadMem: Trying to ReadMemory 0xE1019210[0x18]
18:22:54:296 3484 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
18:22:54:296 3484 DetectCureTDL3: IrpHandler (0) addr: B80EEBB0
18:22:54:296 3484 DetectCureTDL3: IrpHandler (1) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (2) addr: B80EEBB0
18:22:54:296 3484 DetectCureTDL3: IrpHandler (3) addr: B80E8D1F
18:22:54:296 3484 DetectCureTDL3: IrpHandler (4) addr: B80E8D1F
18:22:54:296 3484 DetectCureTDL3: IrpHandler (5) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (6) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (7) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (8) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (9) addr: B80E92E2
18:22:54:296 3484 DetectCureTDL3: IrpHandler (10) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (11) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (12) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (13) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (14) addr: B80E93BB
18:22:54:296 3484 DetectCureTDL3: IrpHandler (15) addr: B80ECF28
18:22:54:296 3484 DetectCureTDL3: IrpHandler (16) addr: B80E92E2
18:22:54:296 3484 DetectCureTDL3: IrpHandler (17) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (18) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (19) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (20) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (21) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (22) addr: B80EAC82
18:22:54:296 3484 DetectCureTDL3: IrpHandler (23) addr: B80EF99E
18:22:54:296 3484 DetectCureTDL3: IrpHandler (24) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (25) addr: 804F4562
18:22:54:296 3484 DetectCureTDL3: IrpHandler (26) addr: 804F4562
18:22:54:296 3484 TDL3_FileDetect: Processing driver: Disk
18:22:54:296 3484 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
18:22:54:296 3484 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
18:22:54:312 3484 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
18:22:54:312 3484
18:22:54:312 3484 DetectCureTDL3: DEVICE_OBJECT: 89D3CC68
18:22:54:312 3484 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89D3CC68
18:22:54:312 3484 KLMD_ReadMem: Trying to ReadMemory 0x89D3CC68[0x38]
18:22:54:312 3484 DetectCureTDL3: DRIVER_OBJECT: 89D82A48
18:22:54:312 3484 KLMD_ReadMem: Trying to ReadMemory 0x89D82A48[0xA8]
18:22:54:312 3484 KLMD_ReadMem: Trying to ReadMemory 0xE1019210[0x18]
18:22:54:312 3484 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
18:22:54:312 3484 DetectCureTDL3: IrpHandler (0) addr: B80EEBB0
18:22:54:312 3484 DetectCureTDL3: IrpHandler (1) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (2) addr: B80EEBB0
18:22:54:312 3484 DetectCureTDL3: IrpHandler (3) addr: B80E8D1F
18:22:54:312 3484 DetectCureTDL3: IrpHandler (4) addr: B80E8D1F
18:22:54:312 3484 DetectCureTDL3: IrpHandler (5) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (6) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (7) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (8) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (9) addr: B80E92E2
18:22:54:312 3484 DetectCureTDL3: IrpHandler (10) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (11) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (12) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (13) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (14) addr: B80E93BB
18:22:54:312 3484 DetectCureTDL3: IrpHandler (15) addr: B80ECF28
18:22:54:312 3484 DetectCureTDL3: IrpHandler (16) addr: B80E92E2
18:22:54:312 3484 DetectCureTDL3: IrpHandler (17) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (18) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (19) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (20) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (21) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (22) addr: B80EAC82
18:22:54:312 3484 DetectCureTDL3: IrpHandler (23) addr: B80EF99E
18:22:54:312 3484 DetectCureTDL3: IrpHandler (24) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (25) addr: 804F4562
18:22:54:312 3484 DetectCureTDL3: IrpHandler (26) addr: 804F4562
18:22:54:312 3484 TDL3_FileDetect: Processing driver: Disk
18:22:54:312 3484 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
18:22:54:312 3484 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
18:22:54:312 3484 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
18:22:54:312 3484
18:22:54:312 3484 DetectCureTDL3: DEVICE_OBJECT: 89CFCAB8
18:22:54:312 3484 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89CFCAB8
18:22:54:312 3484 DetectCureTDL3: DEVICE_OBJECT: 89D3DF18
18:22:54:312 3484 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89D3DF18
18:22:54:312 3484 DetectCureTDL3: DEVICE_OBJECT: 89D82030
18:22:54:312 3484 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89D82030
18:22:54:312 3484 KLMD_ReadMem: Trying to ReadMemory 0x89D82030[0x38]
18:22:54:312 3484 DetectCureTDL3: DRIVER_OBJECT: 89CB4208
18:22:54:312 3484 KLMD_ReadMem: Trying to ReadMemory 0x89CB4208[0xA8]
18:22:54:312 3484 KLMD_ReadMem: Trying to ReadMemory 0xE15E71E8[0x1A]
18:22:54:312 3484 DetectCureTDL3: DRIVER_OBJECT name: \Driver\nvata, Driver Name: nvata
18:22:54:312 3484 DetectCureTDL3: IrpHandler (0) addr: B7F17894
18:22:54:312 3484 DetectCureTDL3: IrpHandler (1) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (2) addr: B7F17894
18:22:54:312 3484 DetectCureTDL3: IrpHandler (3) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (4) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (5) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (6) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (7) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (8) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (9) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (10) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (11) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (12) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (13) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (14) addr: B7F178AE
18:22:54:312 3484 DetectCureTDL3: IrpHandler (15) addr: B7F17D6E
18:22:54:312 3484 DetectCureTDL3: IrpHandler (16) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (17) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (18) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (19) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (20) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (21) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (22) addr: B7F17D0E
18:22:54:312 3484 DetectCureTDL3: IrpHandler (23) addr: B7F17A9C
18:22:54:312 3484 DetectCureTDL3: IrpHandler (24) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (25) addr: B7F17874
18:22:54:312 3484 DetectCureTDL3: IrpHandler (26) addr: B7F17874
18:22:54:312 3484 TDL3_FileDetect: Processing driver: nvata
18:22:54:312 3484 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\nvata.sys
18:22:54:312 3484 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\nvata.sys
18:22:54:312 3484 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\nvata.sys - Verdict: Clean
18:22:54:312 3484
18:22:54:312 3484 Completed
18:22:54:312 3484
18:22:54:312 3484 Results:
18:22:54:312 3484 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
18:22:54:312 3484 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
18:22:54:312 3484 File objects infected / cured / cured on reboot: 0 / 0 / 0
18:22:54:312 3484
18:22:54:312 3484 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
18:22:54:312 3484 UtilityDeinit: KLMD(ARK) unloaded successfully


Mit Zitat antworten