pariendo | |
| 2010-04-17 15:10 - Respuestas: 1 - Tema nº: 2679741
Windows XP Home .
TDSS rootkit removing tool 2.2.8.1 Mar 22 2010 10:43:04
08:34:27:031 1976 ==========================
08:34:27:031 1976 SystemInfo:
08:34:27:031 1976 OS Version: 5.1.2600 ServicePack: 3.0
08:34:27:031 1976 Product type: Workstation
08:34:27:031 1976 ComputerName: TOSHIBA-USER
08:34:27:031 1976 UserName: Jesus Amaya
08:34:27:031 1976 Windows directory: C:\WINDOWS
08:34:27:031 1976 Processor architecture: Intel x86
08:34:27:031 1976 Number of processors: 2
08:34:27:031 1976 Page size: 0x1000
08:34:27:046 1976 Boot type: Normal boot
08:34:27:046 1976 ==========================
08:34:27:046 1976 UnloadDriverW: NtUnloadDriver error 1
08:34:27:046 1976 ForceUnloadDriverW: UnloadDriverW(klmd21) error 1
08:34:27:156 1976 LoadDriverW: Driver already loaded
08:34:27:156 1976 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
08:34:27:156 1976 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
08:34:27:156 1976 wfopen_ex: Trying to KLMD file open
08:34:27:156 1976 wfopen_ex: File opened ok (Flags 2)
08:34:27:156 1976 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
08:34:27:156 1976 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
08:34:27:156 1976 wfopen_ex: Trying to KLMD file open
08:34:27:156 1976 wfopen_ex: File opened ok (Flags 2)
08:34:27:156 1976 Initialize success
08:34:27:156 1976
08:34:27:156 1976 Scanning Services ...
08:34:27:890 1976 Raw services enum returned 345 services
08:34:27:906 1976
08:34:27:906 1976 Scanning Kernel memory ...
08:34:27:906 1976 Devices to scan: 2
08:34:27:906 1976
08:34:27:906 1976 Driver Name: Disk
08:34:27:906 1976 IRP_MJ_CREATE : F78D7BB0
08:34:27:906 1976 IRP_MJ_CREATE_NAMED_PIPE : 804F9759
08:34:27:906 1976 IRP_MJ_CLOSE : F78D7BB0
08:34:27:906 1976 IRP_MJ_READ : F78D1D1F
08:34:27:906 1976 IRP_MJ_WRITE : F78D1D1F
08:34:27:906 1976 IRP_MJ_QUERY_INFORMATION : 804F9759
08:34:27:906 1976 IRP_MJ_SET_INFORMATION : 804F9759
08:34:27:906 1976 IRP_MJ_QUERY_EA : 804F9759
08:34:27:906 1976 IRP_MJ_SET_EA : 804F9759
08:34:27:906 1976 IRP_MJ_FLUSH_BUFFERS : F78D22E2
08:34:27:906 1976 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F9759
08:34:27:906 1976 IRP_MJ_SET_VOLUME_INFORMATION : 804F9759
08:34:27:906 1976 IRP_MJ_DIRECTORY_CONTROL : 804F9759
08:34:27:906 1976 IRP_MJ_FILE_SYSTEM_CONTROL : 804F9759
08:34:27:906 1976 IRP_MJ_DEVICE_CONTROL : F78D23BB
08:34:27:906 1976 IRP_MJ_INTERNAL_DEVICE_CONTROL : F78D5F28
08:34:27:906 1976 IRP_MJ_SHUTDOWN : F78D22E2
08:34:27:906 1976 IRP_MJ_LOCK_CONTROL : 804F9759
08:34:27:906 1976 IRP_MJ_CLEANUP : 804F9759
08:34:27:906 1976 IRP_MJ_CREATE_MAILSLOT : 804F9759
08:34:27:906 1976 IRP_MJ_QUERY_SECURITY : 804F9759
08:34:27:906 1976 IRP_MJ_SET_SECURITY : 804F9759
08:34:27:906 1976 IRP_MJ_POWER : F78D3C82
08:34:27:906 1976 IRP_MJ_SYSTEM_CONTROL : F78D899E
08:34:27:906 1976 IRP_MJ_DEVICE_CHANGE : 804F9759
08:34:27:906 1976 IRP_MJ_QUERY_QUOTA : 804F9759
08:34:27:906 1976 IRP_MJ_SET_QUOTA : 804F9759
08:34:27:937 1976 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
08:34:27:937 1976
08:34:27:937 1976 Driver Name: atapi
08:34:27:937 1976 IRP_MJ_CREATE : 866D1AC8
08:34:27:937 1976 IRP_MJ_CREATE_NAMED_PIPE : 866D1AC8
08:34:27:937 1976 IRP_MJ_CLOSE : 866D1AC8
08:34:27:937 1976 IRP_MJ_READ : 866D1AC8
08:34:27:937 1976 IRP_MJ_WRITE : 866D1AC8
08:34:27:937 1976 IRP_MJ_QUERY_INFORMATION : 866D1AC8
08:34:27:937 1976 IRP_MJ_SET_INFORMATION : 866D1AC8
08:34:27:937 1976 IRP_MJ_QUERY_EA : 866D1AC8
08:34:27:937 1976 IRP_MJ_SET_EA : 866D1AC8
08:34:27:937 1976 IRP_MJ_FLUSH_BUFFERS : 866D1AC8
08:34:27:937 1976 IRP_MJ_QUERY_VOLUME_INFORMATION : 866D1AC8
08:34:27:937 1976 IRP_MJ_SET_VOLUME_INFORMATION : 866D1AC8
08:34:27:937 1976 IRP_MJ_DIRECTORY_CONTROL : 866D1AC8
08:34:27:937 1976 IRP_MJ_FILE_SYSTEM_CONTROL : 866D1AC8
08:34:27:937 1976 IRP_MJ_DEVICE_CONTROL : 866D1AC8
08:34:27:937 1976 IRP_MJ_INTERNAL_DEVICE_CONTROL : 866D1AC8
08:34:27:937 1976 IRP_MJ_SHUTDOWN : 866D1AC8
08:34:27:937 1976 IRP_MJ_LOCK_CONTROL : 866D1AC8
08:34:27:937 1976 IRP_MJ_CLEANUP : 866D1AC8
08:34:27:937 1976 IRP_MJ_CREATE_MAILSLOT : 866D1AC8
08:34:27:937 1976 IRP_MJ_QUERY_SECURITY : 866D1AC8
08:34:27:937 1976 IRP_MJ_SET_SECURITY : 866D1AC8
08:34:27:937 1976 IRP_MJ_POWER : 866D1AC8
08:34:27:937 1976 IRP_MJ_SYSTEM_CONTROL : 866D1AC8
08:34:27:937 1976 IRP_MJ_DEVICE_CHANGE : 866D1AC8
08:34:27:937 1976 IRP_MJ_QUERY_QUOTA : 866D1AC8
08:34:27:937 1976 IRP_MJ_SET_QUOTA : 866D1AC8
08:34:27:937 1976 Driver "atapi" infected by TDSS rootkit!
08:34:27:953 1976 C:\WINDOWS\system32\drivers\tsk1D.tmp - Verdict: 3
08:34:27:953 1976
08:34:27:953 1976 Completed
08:34:27:953 1976
08:34:27:953 1976 Results:
08:34:27:953 1976 Memory objects infected / cured / cured on reboot: 1 / 0 / 0
08:34:27:953 1976 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
08:34:27:953 1976 File objects infected / cured / cured on reboot: 0 / 0 / 0
08:34:27:953 1976
08:34:27:953 1976 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
08:34:27:953 1976 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
08:34:27:953 1976 UnloadDriverW: NtUnloadDriver error 1
08:34:27:953 1976 KLMD(ARK) unloaded successfully
| |
|