Having problems with interet, being redirected when searching on google,
-
Having problems with interet, being redirected when searching on google,
Hey, im Zach and i have been having some issues with my computer. i fear that i have picked up a nasty virus of some sort and i was just wondering if i could get some help fixing it. Here is my hijack this log,
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:25:56 PM, on 3/8/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = Dell Start Page
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [pagazenum] Rundll32.exe "c:\windows\system32\reduwebi.dll",a
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15030/CTSUEng.cab
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupda...01/CTSUEng.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...Uploader55.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupda...5106/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DBB2A7A8-EFEA-4DB7-ABE3-B2C9FA9C6C8F}: NameServer = 217.23.14.75,4.2.2.1,192.168.0.1 205.171.3.25
O20 - AppInit_DLLs: c:\windows\system32\reduwebi.dll
O21 - SSODL: tiramebuh - {89bcadf4-be4d-4c5f-918c-ffee97756094} - c:\windows\system32\reduwebi.dll
O22 - SharedTaskScheduler: gahurihor - {89bcadf4-be4d-4c5f-918c-ffee97756094} - c:\windows\system32\reduwebi.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 7405 bytes
I really could use some help.
Thanks,
Zach
-
Print these instructions out.
NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe
***VERY IMPORTANT! Make sure, you update Malwarebytes before running the scans.***
STEP 1. Download Malwarebytes' Anti-Malware: Malwarebytes.org to your desktop.
(Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)
* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform Quick Scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.
The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
RESTART COMPUTER!
STEP 2. Download GMER: GMER - Rootkit Detector and Remover, by clicking on Download EXE button.
Alternative downloads:
- |MG| GMER 1.0.15.15281 Download
- http://www.softpedia.com/get/Interne...ers/GMER.shtml
Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
When scan is completed, click Save button, and save the results as gmer.log
Warning ! Please, do not select the "Show all" checkbox during the scan.
Post the log to your next reply.
RESTART COMPUTER
STEP 3. Download HijackThis:
HijackThis - Trend Micro USA
by clicking on Installer under Version 2.0.2
[DO NOT download version 2.0.3 (beta)]
Install, and run it.
Post HijackThis log.
NOTE. If you're using Vista, or 7, right click on HijackThis, and click Run as Administrator
Do NOT attempt to "fix" anything!
DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
-
Hey,
I have tried to install malwarebytes from the link that you have given me, but when i click the file it says "Windows cannot access the specified path, link, or file. you may not have the appropriate permissions to access the item." I have tried to rename the file, and have moved it to a different file. Do you have any ideas on how to get around this problem.
Thanks,
Zach
-
Please download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
- Please, never rename Combofix unless instructed.
- Close any open browsers.
- Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
NOTE1. If Combofix asks you to install Recovery Console, please allow it.
NOTE 2. If Combofix asks you to update the program, always do so.
- Close any open browsers.
- WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
- Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
- If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
- Double click on combofix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
Make sure, you re-enable your security programs, when you're done with Combofix.
DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
-
Hey,
It looks like i have got something very nasty and it will not allow me to run any EXE programs which includes the one you just told me to install. it keeps coming up with that same error message.
-
Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
There are 4 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click Rkill and choose Run as Administrator
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
* Rkill.com
* Rkill.scr
* Rkill.pif
* Rkill.exe
* Double-click on the Rkill desktop icon to run the tool.
* If using Vista or Windows 7 right-click on it and choose Run As Administrator.
* A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
* If not, delete the file, then download and use the one provided in Link 2.
* If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
* Do not reboot until instructed.
* If the tool does not run from any of the links provided, please let me know.
Once you've gotten one of them to run then try to immediately run the following.
Now download and run exeHelper.
* Please download exeHelper from Raktor to your desktop.
* Double-click on exeHelper.com to run the fix.
* A black window should pop up, press any key to close once the fix is completed.
* A log file named log.txt will be created in the directory where you ran exeHelper.com
* Attach the log.txt file to your next message.[/LIST]
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
Try to run Combofix again immediately.
-
Hey,
None of them worked, the first link i opened gave me the normal message and the rest didnt do anything. If there is a way to get them to work i could use that, or if you have another idea to solve the problem it would be useful.
Thank you very much for working with me on this.
zach
-
Download TDSSKiller and save it to your Desktop.
Extract its contents to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop itself, not within a folder on the desktop.
Go to Start > Run (Or you can hold down your Windows key and press R) and copy and paste the following into the text field. (make sure you include the quote marks) Then press OK.
"%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v
If it says "Hidden service detected" DO NOT type anything in. Just press Enter on your keyboard to not do anything to the file.
When it is done, a log file should be created on your C: drive called TDSSKiller.txt please copy and paste the contents of that file here.
-
Hey,
None of them worked, the first link i opened gave me the normal message and the rest didnt do anything. If there is a way to get them to work i could use that, or if you have another idea to solve the problem it would be useful.
Thank you very much for working with me on this.
zach
-
Hey here it is
19:14:16:140 3648 TDSS rootkit removing tool 2.2.7.1 Feb 27 2010 13:29:25
19:14:16:140 3648 ================================================== ==============================
19:14:16:140 3648 SystemInfo:
19:14:16:140 3648 OS Version: 5.1.2600 ServicePack: 2.0
19:14:16:140 3648 Product type: Workstation
19:14:16:140 3648 ComputerName: ZACH
19:14:16:140 3648 UserName: Zach
19:14:16:140 3648 Windows directory: C:\WINDOWS
19:14:16:140 3648 Processor architecture: Intel x86
19:14:16:140 3648 Number of processors: 2
19:14:16:140 3648 Page size: 0x1000
19:14:16:140 3648 Boot type: Normal boot
19:14:16:140 3648 ================================================== ==============================
19:14:16:171 3648 UnloadDriverW: NtUnloadDriver error 2
19:14:16:171 3648 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
19:14:16:218 3648 Initialize success
19:14:16:218 3648
19:14:16:218 3648 Scanning Services ...
19:14:16:218 3648 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
19:14:16:218 3648 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
19:14:16:218 3648 wfopen_ex: Trying to KLMD file open
19:14:16:234 3648 wfopen_ex: File opened ok (Flags 2)
19:14:16:234 3648 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
19:14:16:234 3648 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
19:14:16:234 3648 wfopen_ex: Trying to KLMD file open
19:14:16:234 3648 wfopen_ex: File opened ok (Flags 2)
19:14:16:703 3648 GetAdvancedServicesInfo: Raw services enum returned 352 services
19:14:16:718 3648 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
19:14:16:718 3648 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
19:14:16:718 3648
19:14:16:718 3648 Scanning Kernel memory ...
19:14:16:718 3648 Devices to scan: 5
19:14:16:718 3648
19:14:16:718 3648 Driver Name: Disk
19:14:16:718 3648 IRP_MJ_CREATE : F765AC30
19:14:16:718 3648 IRP_MJ_CREATE_NAMED_PIPE : 804F4476
19:14:16:718 3648 IRP_MJ_CLOSE : F765AC30
19:14:16:718 3648 IRP_MJ_READ : F7654D9B
19:14:16:718 3648 IRP_MJ_WRITE : F7654D9B
19:14:16:718 3648 IRP_MJ_QUERY_INFORMATION : 804F4476
19:14:16:718 3648 IRP_MJ_SET_INFORMATION : 804F4476
19:14:16:718 3648 IRP_MJ_QUERY_EA : 804F4476
19:14:16:718 3648 IRP_MJ_SET_EA : 804F4476
19:14:16:718 3648 IRP_MJ_FLUSH_BUFFERS : F7655366
19:14:16:718 3648 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4476
19:14:16:718 3648 IRP_MJ_SET_VOLUME_INFORMATION : 804F4476
19:14:16:718 3648 IRP_MJ_DIRECTORY_CONTROL : 804F4476
19:14:16:718 3648 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4476
19:14:16:718 3648 IRP_MJ_DEVICE_CONTROL : F765544D
19:14:16:718 3648 IRP_MJ_INTERNAL_DEVICE_CONTROL : F7658FC3
19:14:16:718 3648 IRP_MJ_SHUTDOWN : F7655366
19:14:16:718 3648 IRP_MJ_LOCK_CONTROL : 804F4476
19:14:16:718 3648 IRP_MJ_CLEANUP : 804F4476
19:14:16:718 3648 IRP_MJ_CREATE_MAILSLOT : 804F4476
19:14:16:718 3648 IRP_MJ_QUERY_SECURITY : 804F4476
19:14:16:718 3648 IRP_MJ_SET_SECURITY : 804F4476
19:14:16:718 3648 IRP_MJ_POWER : F7656EF3
19:14:16:718 3648 IRP_MJ_SYSTEM_CONTROL : F765BA24
19:14:16:718 3648 IRP_MJ_DEVICE_CHANGE : 804F4476
19:14:16:718 3648 IRP_MJ_QUERY_QUOTA : 804F4476
19:14:16:718 3648 IRP_MJ_SET_QUOTA : 804F4476
19:14:16:718 3648 TDL3_StartIoLastChanceHookDetect: Unable to dump StartIo handler code
19:14:16:718 3648 sion
19:14:16:718 3648 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
19:14:16:718 3648
19:14:16:718 3648 Driver Name: Disk
19:14:16:718 3648 IRP_MJ_CREATE : F765AC30
19:14:16:718 3648 IRP_MJ_CREATE_NAMED_PIPE : 804F4476
19:14:16:718 3648 IRP_MJ_CLOSE : F765AC30
19:14:16:718 3648 IRP_MJ_READ : F7654D9B
19:14:16:718 3648 IRP_MJ_WRITE : F7654D9B
19:14:16:718 3648 IRP_MJ_QUERY_INFORMATION : 804F4476
19:14:16:718 3648 IRP_MJ_SET_INFORMATION : 804F4476
19:14:16:718 3648 IRP_MJ_QUERY_EA : 804F4476
19:14:16:718 3648 IRP_MJ_SET_EA : 804F4476
19:14:16:718 3648 IRP_MJ_FLUSH_BUFFERS : F7655366
19:14:16:718 3648 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4476
19:14:16:718 3648 IRP_MJ_SET_VOLUME_INFORMATION : 804F4476
19:14:16:718 3648 IRP_MJ_DIRECTORY_CONTROL : 804F4476
19:14:16:718 3648 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4476
19:14:16:718 3648 IRP_MJ_DEVICE_CONTROL : F765544D
19:14:16:718 3648 IRP_MJ_INTERNAL_DEVICE_CONTROL : F7658FC3
19:14:16:718 3648 IRP_MJ_SHUTDOWN : F7655366
19:14:16:718 3648 IRP_MJ_LOCK_CONTROL : 804F4476
19:14:16:718 3648 IRP_MJ_CLEANUP : 804F4476
19:14:16:718 3648 IRP_MJ_CREATE_MAILSLOT : 804F4476
19:14:16:718 3648 IRP_MJ_QUERY_SECURITY : 804F4476
19:14:16:718 3648 IRP_MJ_SET_SECURITY : 804F4476
19:14:16:718 3648 IRP_MJ_POWER : F7656EF3
19:14:16:718 3648 IRP_MJ_SYSTEM_CONTROL : F765BA24
19:14:16:718 3648 IRP_MJ_DEVICE_CHANGE : 804F4476
19:14:16:718 3648 IRP_MJ_QUERY_QUOTA : 804F4476
19:14:16:718 3648 IRP_MJ_SET_QUOTA : 804F4476
19:14:16:718 3648 TDL3_StartIoLastChanceHookDetect: Unable to dump StartIo handler code
19:14:16:718 3648 sion
19:14:16:718 3648 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
19:14:16:718 3648
19:14:16:718 3648 Driver Name: Disk
19:14:16:718 3648 IRP_MJ_CREATE : F765AC30
19:14:16:718 3648 IRP_MJ_CREATE_NAMED_PIPE : 804F4476
19:14:16:718 3648 IRP_MJ_CLOSE : F765AC30
19:14:16:718 3648 IRP_MJ_READ : F7654D9B
19:14:16:718 3648 IRP_MJ_WRITE : F7654D9B
19:14:16:718 3648 IRP_MJ_QUERY_INFORMATION : 804F4476
19:14:16:718 3648 IRP_MJ_SET_INFORMATION : 804F4476
19:14:16:718 3648 IRP_MJ_QUERY_EA : 804F4476
19:14:16:718 3648 IRP_MJ_SET_EA : 804F4476
19:14:16:718 3648 IRP_MJ_FLUSH_BUFFERS : F7655366
19:14:16:718 3648 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4476
19:14:16:718 3648 IRP_MJ_SET_VOLUME_INFORMATION : 804F4476
19:14:16:718 3648 IRP_MJ_DIRECTORY_CONTROL : 804F4476
19:14:16:718 3648 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4476
19:14:16:718 3648 IRP_MJ_DEVICE_CONTROL : F765544D
19:14:16:718 3648 IRP_MJ_INTERNAL_DEVICE_CONTROL : F7658FC3
19:14:16:718 3648 IRP_MJ_SHUTDOWN : F7655366
19:14:16:718 3648 IRP_MJ_LOCK_CONTROL : 804F4476
19:14:16:718 3648 IRP_MJ_CLEANUP : 804F4476
19:14:16:718 3648 IRP_MJ_CREATE_MAILSLOT : 804F4476
19:14:16:718 3648 IRP_MJ_QUERY_SECURITY : 804F4476
19:14:16:718 3648 IRP_MJ_SET_SECURITY : 804F4476
19:14:16:718 3648 IRP_MJ_POWER : F7656EF3
19:14:16:718 3648 IRP_MJ_SYSTEM_CONTROL : F765BA24
19:14:16:718 3648 IRP_MJ_DEVICE_CHANGE : 804F4476
19:14:16:718 3648 IRP_MJ_QUERY_QUOTA : 804F4476
19:14:16:718 3648 IRP_MJ_SET_QUOTA : 804F4476
19:14:16:718 3648 TDL3_StartIoLastChanceHookDetect: Unable to dump StartIo handler code
19:14:16:718 3648 sion
19:14:16:734 3648 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
19:14:16:734 3648
19:14:16:734 3648 Driver Name: Disk
19:14:16:734 3648 IRP_MJ_CREATE : F765AC30
19:14:16:734 3648 IRP_MJ_CREATE_NAMED_PIPE : 804F4476
19:14:16:734 3648 IRP_MJ_CLOSE : F765AC30
19:14:16:734 3648 IRP_MJ_READ : F7654D9B
19:14:16:734 3648 IRP_MJ_WRITE : F7654D9B
19:14:16:734 3648 IRP_MJ_QUERY_INFORMATION : 804F4476
19:14:16:734 3648 IRP_MJ_SET_INFORMATION : 804F4476
19:14:16:734 3648 IRP_MJ_QUERY_EA : 804F4476
19:14:16:734 3648 IRP_MJ_SET_EA : 804F4476
19:14:16:734 3648 IRP_MJ_FLUSH_BUFFERS : F7655366
19:14:16:734 3648 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4476
19:14:16:734 3648 IRP_MJ_SET_VOLUME_INFORMATION : 804F4476
19:14:16:734 3648 IRP_MJ_DIRECTORY_CONTROL : 804F4476
19:14:16:734 3648 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4476
19:14:16:734 3648 IRP_MJ_DEVICE_CONTROL : F765544D
19:14:16:734 3648 IRP_MJ_INTERNAL_DEVICE_CONTROL : F7658FC3
19:14:16:734 3648 IRP_MJ_SHUTDOWN : F7655366
19:14:16:734 3648 IRP_MJ_LOCK_CONTROL : 804F4476
19:14:16:734 3648 IRP_MJ_CLEANUP : 804F4476
19:14:16:734 3648 IRP_MJ_CREATE_MAILSLOT : 804F4476
19:14:16:734 3648 IRP_MJ_QUERY_SECURITY : 804F4476
19:14:16:734 3648 IRP_MJ_SET_SECURITY : 804F4476
19:14:16:734 3648 IRP_MJ_POWER : F7656EF3
19:14:16:734 3648 IRP_MJ_SYSTEM_CONTROL : F765BA24
19:14:16:734 3648 IRP_MJ_DEVICE_CHANGE : 804F4476
19:14:16:734 3648 IRP_MJ_QUERY_QUOTA : 804F4476
19:14:16:734 3648 IRP_MJ_SET_QUOTA : 804F4476
19:14:16:734 3648 TDL3_StartIoLastChanceHookDetect: Unable to dump StartIo handler code
19:14:16:734 3648 sion
19:14:16:734 3648 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
19:14:16:734 3648
19:14:16:734 3648 Driver Name: atapi
19:14:16:734 3648 IRP_MJ_CREATE : 86FD51F8
19:14:16:734 3648 IRP_MJ_CREATE_NAMED_PIPE : 804F4476
19:14:16:734 3648 IRP_MJ_CLOSE : 86FD51F8
19:14:16:734 3648 IRP_MJ_READ : 804F4476
19:14:16:734 3648 IRP_MJ_WRITE : 804F4476
19:14:16:734 3648 IRP_MJ_QUERY_INFORMATION : 804F4476
19:14:16:734 3648 IRP_MJ_SET_INFORMATION : 804F4476
19:14:16:734 3648 IRP_MJ_QUERY_EA : 804F4476
19:14:16:734 3648 IRP_MJ_SET_EA : 804F4476
19:14:16:734 3648 IRP_MJ_FLUSH_BUFFERS : 804F4476
19:14:16:734 3648 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4476
19:14:16:734 3648 IRP_MJ_SET_VOLUME_INFORMATION : 804F4476
19:14:16:734 3648 IRP_MJ_DIRECTORY_CONTROL : 804F4476
19:14:16:734 3648 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4476
19:14:16:734 3648 IRP_MJ_DEVICE_CONTROL : 86FD51F8
19:14:16:734 3648 IRP_MJ_INTERNAL_DEVICE_CONTROL : 86FD51F8
19:14:16:734 3648 IRP_MJ_SHUTDOWN : 804F4476
19:14:16:734 3648 IRP_MJ_LOCK_CONTROL : 804F4476
19:14:16:734 3648 IRP_MJ_CLEANUP : 804F4476
19:14:16:734 3648 IRP_MJ_CREATE_MAILSLOT : 804F4476
19:14:16:734 3648 IRP_MJ_QUERY_SECURITY : 804F4476
19:14:16:734 3648 IRP_MJ_SET_SECURITY : 804F4476
19:14:16:734 3648 IRP_MJ_POWER : 86FD51F8
19:14:16:734 3648 IRP_MJ_SYSTEM_CONTROL : 86FD51F8
19:14:16:734 3648 IRP_MJ_DEVICE_CHANGE : 804F4476
19:14:16:734 3648 IRP_MJ_QUERY_QUOTA : 804F4476
19:14:16:734 3648 IRP_MJ_SET_QUOTA : 804F4476
19:14:16:734 3648 siohd: 0
19:14:16:750 3648 C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Clean
19:14:16:750 3648
19:14:16:750 3648 Completed
19:14:16:750 3648
19:14:16:750 3648 Results:
19:14:16:750 3648 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
19:14:16:750 3648 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
19:14:16:750 3648 File objects infected / cured / cured on reboot: 0 / 0 / 0
19:14:16:750 3648
19:14:16:750 3648 KLMD(ARK) unloaded successfully