servus,
hier das LOG:
Code:
Alles auswählen Aufklappen ATTFilter
13:19:42:281 1620 TDSS rootkit removing tool 2.2.2 Jan 13 2010 08:42:25
13:19:42:281 1620 ================================================================================
13:19:42:281 1620 SystemInfo:
13:19:42:281 1620 OS Version: 5.1.2600 ServicePack: 3.0
13:19:42:281 1620 Product type: Workstation
13:19:42:281 1620 ComputerName: ***
13:19:42:281 1620 UserName: ******a
13:19:42:281 1620 Windows directory: C:\WINDOWS
13:19:42:281 1620 Processor architecture: Intel x86
13:19:42:281 1620 Number of processors: 2
13:19:42:281 1620 Page size: 0x1000
13:19:42:281 1620 Boot type: Normal boot
13:19:42:281 1620 ================================================================================
13:19:42:296 1620 UnloadDriverW: NtUnloadDriver error 2
13:19:42:296 1620 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
13:19:42:312 1620 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
13:19:42:328 1620 UtilityInit: KLMD drop and load success
13:19:42:328 1620 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201000)
13:19:42:328 1620 UtilityInit: KLMD open success
13:19:42:328 1620 UtilityInit: Initialize success
13:19:42:328 1620
13:19:42:328 1620 Scanning Services ...
13:19:42:328 1620 CreateRegParser: Registry parser init started
13:19:42:328 1620 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
13:19:42:328 1620 CreateRegParser: DisableWow64Redirection error
13:19:42:328 1620 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
13:19:42:328 1620 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043
13:19:42:328 1620 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
13:19:42:328 1620 wfopen_ex: Trying to KLMD file open
13:19:42:328 1620 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system
13:19:42:328 1620 wfopen_ex: File opened ok (Flags 2)
13:19:42:328 1620 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: 3849D0
13:19:42:328 1620 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
13:19:42:328 1620 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043
13:19:42:328 1620 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
13:19:42:328 1620 wfopen_ex: Trying to KLMD file open
13:19:42:328 1620 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software
13:19:42:328 1620 wfopen_ex: File opened ok (Flags 2)
13:19:42:328 1620 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: 384A78
13:19:42:328 1620 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
13:19:42:328 1620 CreateRegParser: EnableWow64Redirection error
13:19:42:328 1620 CreateRegParser: RegParser init completed
13:19:42:609 1620 GetAdvancedServicesInfo: Raw services enum returned 375 services
13:19:42:609 1620 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
13:19:42:609 1620 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
13:19:42:609 1620
13:19:42:609 1620 Scanning Kernel memory ...
13:19:42:609 1620 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
13:19:42:609 1620 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 89C13030
13:19:42:609 1620 DetectCureTDL3: KLMD_GetDeviceObjectList returned 6 DevObjects
13:19:42:609 1620
13:19:42:609 1620 DetectCureTDL3: DEVICE_OBJECT: 88FF0C68
13:19:42:609 1620 KLMD_GetLowerDeviceObject: Trying to get lower device object for 88FF0C68
13:19:42:609 1620 KLMD_ReadMem: Trying to ReadMemory 0x88FF0C68[0x38]
13:19:42:609 1620 DetectCureTDL3: DRIVER_OBJECT: 89C13030
13:19:42:609 1620 KLMD_ReadMem: Trying to ReadMemory 0x89C13030[0xA8]
13:19:42:609 1620 KLMD_ReadMem: Trying to ReadMemory 0xE1603D78[0x18]
13:19:42:609 1620 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
13:19:42:609 1620 DetectCureTDL3: IrpHandler (0) addr: F765DBB0
13:19:42:609 1620 DetectCureTDL3: IrpHandler (1) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (2) addr: F765DBB0
13:19:42:609 1620 DetectCureTDL3: IrpHandler (3) addr: F7657D1F
13:19:42:609 1620 DetectCureTDL3: IrpHandler (4) addr: F7657D1F
13:19:42:609 1620 DetectCureTDL3: IrpHandler (5) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (6) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (7) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (8) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (9) addr: F76582E2
13:19:42:609 1620 DetectCureTDL3: IrpHandler (10) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (11) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (12) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (13) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (14) addr: F76583BB
13:19:42:609 1620 DetectCureTDL3: IrpHandler (15) addr: F765BF28
13:19:42:609 1620 DetectCureTDL3: IrpHandler (16) addr: F76582E2
13:19:42:609 1620 DetectCureTDL3: IrpHandler (17) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (18) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (19) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (20) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (21) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (22) addr: F7659C82
13:19:42:609 1620 DetectCureTDL3: IrpHandler (23) addr: F765E99E
13:19:42:609 1620 DetectCureTDL3: IrpHandler (24) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (25) addr: 804F9739
13:19:42:609 1620 DetectCureTDL3: IrpHandler (26) addr: 804F9739
13:19:42:609 1620 TDL3_FileDetect: Processing driver: Disk
13:19:42:609 1620 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
13:19:42:609 1620 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
13:19:42:656 1620 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
13:19:42:656 1620
13:19:42:656 1620 DetectCureTDL3: DEVICE_OBJECT: 88FE8AB8
13:19:42:656 1620 KLMD_GetLowerDeviceObject: Trying to get lower device object for 88FE8AB8
13:19:42:656 1620 DetectCureTDL3: DEVICE_OBJECT: 88FF6030
13:19:42:656 1620 KLMD_GetLowerDeviceObject: Trying to get lower device object for 88FF6030
13:19:42:656 1620 KLMD_ReadMem: Trying to ReadMemory 0x88FF6030[0x38]
13:19:42:656 1620 DetectCureTDL3: DRIVER_OBJECT: 894BC790
13:19:42:656 1620 KLMD_ReadMem: Trying to ReadMemory 0x894BC790[0xA8]
13:19:42:656 1620 KLMD_ReadMem: Trying to ReadMemory 0xE50BD738[0x1E]
13:19:42:656 1620 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR
13:19:42:656 1620 DetectCureTDL3: IrpHandler (0) addr: 88FEA1F8
13:19:42:656 1620 DetectCureTDL3: IrpHandler (1) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (2) addr: 88FEA1F8
13:19:42:656 1620 DetectCureTDL3: IrpHandler (3) addr: 88FEA1F8
13:19:42:656 1620 DetectCureTDL3: IrpHandler (4) addr: 88FEA1F8
13:19:42:656 1620 DetectCureTDL3: IrpHandler (5) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (6) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (7) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (8) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (9) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (10) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (11) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (12) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (13) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (14) addr: 88FEA1F8
13:19:42:656 1620 DetectCureTDL3: IrpHandler (15) addr: 88FEA1F8
13:19:42:656 1620 DetectCureTDL3: IrpHandler (16) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (17) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (18) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (19) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (20) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (21) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (22) addr: 88FEA1F8
13:19:42:656 1620 DetectCureTDL3: IrpHandler (23) addr: 88FEA1F8
13:19:42:656 1620 DetectCureTDL3: IrpHandler (24) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (25) addr: 804F9739
13:19:42:656 1620 DetectCureTDL3: IrpHandler (26) addr: 804F9739
13:19:42:656 1620 KLMD_ReadMem: Trying to ReadMemory 0xF77A8F26[0x400]
13:19:42:656 1620 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
13:19:42:656 1620 TDL3_FileDetect: Processing driver: USBSTOR
13:19:42:656 1620 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
13:19:42:656 1620 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
13:19:42:671 1620 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
13:19:42:671 1620
13:19:42:671 1620 DetectCureTDL3: DEVICE_OBJECT: 89AE9030
13:19:42:671 1620 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89AE9030
13:19:42:671 1620 KLMD_ReadMem: Trying to ReadMemory 0x89AE9030[0x38]
13:19:42:671 1620 DetectCureTDL3: DRIVER_OBJECT: 89C13030
13:19:42:671 1620 KLMD_ReadMem: Trying to ReadMemory 0x89C13030[0xA8]
13:19:42:671 1620 KLMD_ReadMem: Trying to ReadMemory 0xE1603D78[0x18]
13:19:42:671 1620 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
13:19:42:671 1620 DetectCureTDL3: IrpHandler (0) addr: F765DBB0
13:19:42:671 1620 DetectCureTDL3: IrpHandler (1) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (2) addr: F765DBB0
13:19:42:671 1620 DetectCureTDL3: IrpHandler (3) addr: F7657D1F
13:19:42:671 1620 DetectCureTDL3: IrpHandler (4) addr: F7657D1F
13:19:42:671 1620 DetectCureTDL3: IrpHandler (5) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (6) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (7) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (8) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (9) addr: F76582E2
13:19:42:671 1620 DetectCureTDL3: IrpHandler (10) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (11) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (12) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (13) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (14) addr: F76583BB
13:19:42:671 1620 DetectCureTDL3: IrpHandler (15) addr: F765BF28
13:19:42:671 1620 DetectCureTDL3: IrpHandler (16) addr: F76582E2
13:19:42:671 1620 DetectCureTDL3: IrpHandler (17) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (18) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (19) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (20) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (21) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (22) addr: F7659C82
13:19:42:671 1620 DetectCureTDL3: IrpHandler (23) addr: F765E99E
13:19:42:671 1620 DetectCureTDL3: IrpHandler (24) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (25) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (26) addr: 804F9739
13:19:42:671 1620 TDL3_FileDetect: Processing driver: Disk
13:19:42:671 1620 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
13:19:42:671 1620 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
13:19:42:671 1620 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
13:19:42:671 1620
13:19:42:671 1620 DetectCureTDL3: DEVICE_OBJECT: 89AE7A28
13:19:42:671 1620 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89AE7A28
13:19:42:671 1620 KLMD_ReadMem: Trying to ReadMemory 0x89AE7A28[0x38]
13:19:42:671 1620 DetectCureTDL3: DRIVER_OBJECT: 89C13030
13:19:42:671 1620 KLMD_ReadMem: Trying to ReadMemory 0x89C13030[0xA8]
13:19:42:671 1620 KLMD_ReadMem: Trying to ReadMemory 0xE1603D78[0x18]
13:19:42:671 1620 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
13:19:42:671 1620 DetectCureTDL3: IrpHandler (0) addr: F765DBB0
13:19:42:671 1620 DetectCureTDL3: IrpHandler (1) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (2) addr: F765DBB0
13:19:42:671 1620 DetectCureTDL3: IrpHandler (3) addr: F7657D1F
13:19:42:671 1620 DetectCureTDL3: IrpHandler (4) addr: F7657D1F
13:19:42:671 1620 DetectCureTDL3: IrpHandler (5) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (6) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (7) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (8) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (9) addr: F76582E2
13:19:42:671 1620 DetectCureTDL3: IrpHandler (10) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (11) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (12) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (13) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (14) addr: F76583BB
13:19:42:671 1620 DetectCureTDL3: IrpHandler (15) addr: F765BF28
13:19:42:671 1620 DetectCureTDL3: IrpHandler (16) addr: F76582E2
13:19:42:671 1620 DetectCureTDL3: IrpHandler (17) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (18) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (19) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (20) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (21) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (22) addr: F7659C82
13:19:42:671 1620 DetectCureTDL3: IrpHandler (23) addr: F765E99E
13:19:42:671 1620 DetectCureTDL3: IrpHandler (24) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (25) addr: 804F9739
13:19:42:671 1620 DetectCureTDL3: IrpHandler (26) addr: 804F9739
13:19:42:671 1620 TDL3_FileDetect: Processing driver: Disk
13:19:42:671 1620 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
13:19:42:671 1620 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
13:19:42:687 1620 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
13:19:42:687 1620
13:19:42:687 1620 DetectCureTDL3: DEVICE_OBJECT: 89B20AB8
13:19:42:687 1620 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89B20AB8
13:19:42:687 1620 DetectCureTDL3: DEVICE_OBJECT: 89AE5D98
13:19:42:687 1620 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89AE5D98
13:19:42:687 1620 KLMD_ReadMem: Trying to ReadMemory 0x89AE5D98[0x38]
13:19:42:687 1620 DetectCureTDL3: DRIVER_OBJECT: 89B25850
13:19:42:687 1620 KLMD_ReadMem: Trying to ReadMemory 0x89B25850[0xA8]
13:19:42:687 1620 KLMD_ReadMem: Trying to ReadMemory 0xE1016B90[0x1A]
13:19:42:687 1620 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
13:19:42:687 1620 DetectCureTDL3: IrpHandler (0) addr: F7833B40
13:19:42:687 1620 DetectCureTDL3: IrpHandler (1) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (2) addr: F7833B40
13:19:42:687 1620 DetectCureTDL3: IrpHandler (3) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (4) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (5) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (6) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (7) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (8) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (9) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (10) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (11) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (12) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (13) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (14) addr: F7833B40
13:19:42:687 1620 DetectCureTDL3: IrpHandler (15) addr: F7833B40
13:19:42:687 1620 DetectCureTDL3: IrpHandler (16) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (17) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (18) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (19) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (20) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (21) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (22) addr: F7833B40
13:19:42:687 1620 DetectCureTDL3: IrpHandler (23) addr: F7833B40
13:19:42:687 1620 DetectCureTDL3: IrpHandler (24) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (25) addr: 804F9739
13:19:42:687 1620 DetectCureTDL3: IrpHandler (26) addr: 804F9739
13:19:42:687 1620 KLMD_ReadMem: Trying to ReadMemory 0xF7831864[0x400]
13:19:42:687 1620 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
13:19:42:687 1620 TDL3_FileDetect: Processing driver: atapi
13:19:42:687 1620 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
13:19:42:687 1620 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys
13:19:42:703 1620 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Clean
13:19:42:703 1620
13:19:42:703 1620 DetectCureTDL3: DEVICE_OBJECT: 89AECAB8
13:19:42:703 1620 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89AECAB8
13:19:42:703 1620 DetectCureTDL3: DEVICE_OBJECT: 89AEDB00
13:19:42:703 1620 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89AEDB00
13:19:42:703 1620 KLMD_ReadMem: Trying to ReadMemory 0x89AEDB00[0x38]
13:19:42:703 1620 DetectCureTDL3: DRIVER_OBJECT: 89B25850
13:19:42:703 1620 KLMD_ReadMem: Trying to ReadMemory 0x89B25850[0xA8]
13:19:42:703 1620 KLMD_ReadMem: Trying to ReadMemory 0xE1016B90[0x1A]
13:19:42:703 1620 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
13:19:42:703 1620 DetectCureTDL3: IrpHandler (0) addr: F7833B40
13:19:42:703 1620 DetectCureTDL3: IrpHandler (1) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (2) addr: F7833B40
13:19:42:703 1620 DetectCureTDL3: IrpHandler (3) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (4) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (5) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (6) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (7) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (8) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (9) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (10) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (11) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (12) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (13) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (14) addr: F7833B40
13:19:42:703 1620 DetectCureTDL3: IrpHandler (15) addr: F7833B40
13:19:42:703 1620 DetectCureTDL3: IrpHandler (16) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (17) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (18) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (19) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (20) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (21) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (22) addr: F7833B40
13:19:42:703 1620 DetectCureTDL3: IrpHandler (23) addr: F7833B40
13:19:42:703 1620 DetectCureTDL3: IrpHandler (24) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (25) addr: 804F9739
13:19:42:703 1620 DetectCureTDL3: IrpHandler (26) addr: 804F9739
13:19:42:703 1620 KLMD_ReadMem: Trying to ReadMemory 0xF7831864[0x400]
13:19:42:703 1620 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
13:19:42:703 1620 TDL3_FileDetect: Processing driver: atapi
13:19:42:703 1620 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
13:19:42:703 1620 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys
13:19:42:703 1620 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Clean
13:19:42:703 1620
13:19:42:703 1620 Completed
13:19:42:703 1620
13:19:42:703 1620 Results:
13:19:42:703 1620 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
13:19:42:703 1620 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
13:19:42:703 1620 File objects infected / cured / cured on reboot: 0 / 0 / 0
13:19:42:703 1620
13:19:42:703 1620 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
13:19:42:703 1620 UtilityDeinit: KLMD(ARK) unloaded successfully