Ok, thank you. I'll make sure to keep that in mind when running further scans.
I'm sorry, I didn't know you wanted the log, I thought you meant for me to tell you what the verdicts were. My mistake. . .I knew that seemed a little weird.
14:37:17:828 3276 TDSS rootkit removing tool 2.2.4 Feb 15 2010 19:38:31
14:37:17:828 3276 ================================================================================
14:37:17:828 3276 SystemInfo:
14:37:17:828 3276 OS Version: 5.1.2600 ServicePack: 3.0
14:37:17:828 3276 Product type: Workstation
14:37:17:828 3276 ComputerName: WILKINS
14:37:17:828 3276 UserName: Steven Wilkins
14:37:17:828 3276 Windows directory: C:\WINDOWS
14:37:17:828 3276 Processor architecture: Intel x86
14:37:17:828 3276 Number of processors: 2
14:37:17:828 3276 Page size: 0x1000
14:37:17:843 3276 Boot type: Normal boot
14:37:17:843 3276 ================================================================================
14:37:17:843 3276 UnloadDriverW: NtUnloadDriver error 2
14:37:17:843 3276 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
14:37:17:843 3276 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
14:37:17:859 3276 UtilityInit: KLMD drop and load success
14:37:17:859 3276 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201010)
14:37:17:859 3276 UtilityInit: KLMD open success
14:37:17:859 3276 UtilityInit: Initialize success
14:37:17:859 3276
14:37:17:859 3276 Scanning Services ...
14:37:17:859 3276 CreateRegParser: Registry parser init started
14:37:17:859 3276 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
14:37:17:859 3276 CreateRegParser: DisableWow64Redirection error
14:37:17:859 3276 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
14:37:17:859 3276 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043
14:37:17:859 3276 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
14:37:17:859 3276 wfopen_ex: Trying to KLMD file open
14:37:17:859 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system
14:37:17:859 3276 wfopen_ex: File opened ok (Flags 2)
14:37:17:859 3276 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: 3C49E0
14:37:17:859 3276 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
14:37:17:859 3276 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043
14:37:17:859 3276 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
14:37:17:859 3276 wfopen_ex: Trying to KLMD file open
14:37:17:859 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software
14:37:17:859 3276 wfopen_ex: File opened ok (Flags 2)
14:37:17:859 3276 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: 3C4A88
14:37:17:859 3276 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
14:37:17:859 3276 CreateRegParser: EnableWow64Redirection error
14:37:17:859 3276 CreateRegParser: RegParser init completed
14:37:17:921 3276 GetAdvancedServicesInfo: Raw services enum returned 388 services
14:37:17:921 3276 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
14:37:17:921 3276 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
14:37:17:921 3276
14:37:17:921 3276 Scanning Kernel memory ...
14:37:17:921 3276 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
14:37:17:921 3276 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 8A8FC910
14:37:17:921 3276 DetectCureTDL3: KLMD_GetDeviceObjectList returned 12 DevObjects
14:37:17:921 3276
14:37:17:921 3276 DetectCureTDL3: DEVICE_OBJECT: 890ED030
14:37:17:921 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 890ED030
14:37:17:921 3276 KLMD_ReadMem: Trying to ReadMemory 0x890ED030[0x38]
14:37:17:921 3276 DetectCureTDL3: DRIVER_OBJECT: 8A8FC910
14:37:17:921 3276 KLMD_ReadMem: Trying to ReadMemory 0x8A8FC910[0xA8]
14:37:17:921 3276 KLMD_ReadMem: Trying to ReadMemory 0xE1939758[0x18]
14:37:17:921 3276 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_CREATE : BA0EEBB0
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_CLOSE : BA0EEBB0
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_READ : BA0E8D1F
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_WRITE : BA0E8D1F
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_SET_EA : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : BA0E92E2
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : BA0E93BB
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : BA0ECF28
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_SHUTDOWN : BA0E92E2
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_CLEANUP : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_POWER : BA0EAC82
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : BA0EF99E
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F4562
14:37:17:921 3276 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F4562
14:37:17:921 3276 TDL3_FileDetect: Processing driver: Disk
14:37:17:921 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:17:921 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:17:953 3276 TDL3_FileDetect: Processing driver: Disk
14:37:17:953 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:17:953 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:17:953 3276 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
14:37:17:953 3276
14:37:17:953 3276 DetectCureTDL3: DEVICE_OBJECT: 8909A030
14:37:17:953 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8909A030
14:37:17:953 3276 KLMD_ReadMem: Trying to ReadMemory 0x8909A030[0x38]
14:37:17:953 3276 DetectCureTDL3: DRIVER_OBJECT: 8A8FC910
14:37:17:953 3276 KLMD_ReadMem: Trying to ReadMemory 0x8A8FC910[0xA8]
14:37:17:953 3276 KLMD_ReadMem: Trying to ReadMemory 0xE1939758[0x18]
14:37:17:953 3276 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_CREATE : BA0EEBB0
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_CLOSE : BA0EEBB0
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_READ : BA0E8D1F
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_WRITE : BA0E8D1F
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_SET_EA : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : BA0E92E2
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : BA0E93BB
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : BA0ECF28
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_SHUTDOWN : BA0E92E2
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_CLEANUP : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_POWER : BA0EAC82
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : BA0EF99E
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F4562
14:37:17:953 3276 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F4562
14:37:17:953 3276 TDL3_FileDetect: Processing driver: Disk
14:37:17:953 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:17:953 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:17:968 3276 TDL3_FileDetect: Processing driver: Disk
14:37:17:968 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:17:968 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:17:968 3276 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
14:37:17:968 3276
14:37:17:968 3276 DetectCureTDL3: DEVICE_OBJECT: 88F92498
14:37:17:968 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 88F92498
14:37:17:968 3276 KLMD_ReadMem: Trying to ReadMemory 0x88F92498[0x38]
14:37:17:968 3276 DetectCureTDL3: DRIVER_OBJECT: 8A8FC910
14:37:17:968 3276 KLMD_ReadMem: Trying to ReadMemory 0x8A8FC910[0xA8]
14:37:17:968 3276 KLMD_ReadMem: Trying to ReadMemory 0xE1939758[0x18]
14:37:17:984 3276 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_CREATE : BA0EEBB0
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_CLOSE : BA0EEBB0
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_READ : BA0E8D1F
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_WRITE : BA0E8D1F
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_SET_EA : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : BA0E92E2
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : BA0E93BB
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : BA0ECF28
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_SHUTDOWN : BA0E92E2
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_CLEANUP : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_POWER : BA0EAC82
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : BA0EF99E
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F4562
14:37:17:984 3276 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F4562
14:37:17:984 3276 TDL3_FileDetect: Processing driver: Disk
14:37:17:984 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:17:984 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:17:984 3276 TDL3_FileDetect: Processing driver: Disk
14:37:17:984 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:17:984 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:000 3276 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
14:37:18:000 3276
14:37:18:000 3276 DetectCureTDL3: DEVICE_OBJECT: 890DC030
14:37:18:000 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 890DC030
14:37:18:000 3276 KLMD_ReadMem: Trying to ReadMemory 0x890DC030[0x38]
14:37:18:000 3276 DetectCureTDL3: DRIVER_OBJECT: 8A8FC910
14:37:18:000 3276 KLMD_ReadMem: Trying to ReadMemory 0x8A8FC910[0xA8]
14:37:18:000 3276 KLMD_ReadMem: Trying to ReadMemory 0xE1939758[0x18]
14:37:18:000 3276 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_CREATE : BA0EEBB0
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_CLOSE : BA0EEBB0
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_READ : BA0E8D1F
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_WRITE : BA0E8D1F
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_SET_EA : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : BA0E92E2
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : BA0E93BB
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : BA0ECF28
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_SHUTDOWN : BA0E92E2
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_CLEANUP : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_POWER : BA0EAC82
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : BA0EF99E
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F4562
14:37:18:000 3276 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F4562
14:37:18:000 3276 TDL3_FileDetect: Processing driver: Disk
14:37:18:000 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:000 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:000 3276 TDL3_FileDetect: Processing driver: Disk
14:37:18:000 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:000 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:015 3276 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
14:37:18:015 3276
14:37:18:015 3276 DetectCureTDL3: DEVICE_OBJECT: 89103920
14:37:18:015 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89103920
14:37:18:015 3276 DetectCureTDL3: DEVICE_OBJECT: 890F1330
14:37:18:015 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 890F1330
14:37:18:015 3276 DetectCureTDL3: DEVICE_OBJECT: 89D32810
14:37:18:015 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89D32810
14:37:18:015 3276 KLMD_ReadMem: Trying to ReadMemory 0x89D32810[0x38]
14:37:18:015 3276 DetectCureTDL3: DRIVER_OBJECT: 891FA4D8
14:37:18:015 3276 KLMD_ReadMem: Trying to ReadMemory 0x891FA4D8[0xA8]
14:37:18:015 3276 KLMD_ReadMem: Trying to ReadMemory 0xE1956FB0[0x1E]
14:37:18:015 3276 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_CREATE : AF47B218
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_CLOSE : AF47B218
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_READ : AF47B23C
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_WRITE : AF47B23C
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_SET_EA : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : AF47B180
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : AF4769E6
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_SHUTDOWN : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_CLEANUP : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_POWER : AF47A5F0
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : AF478A6E
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F4562
14:37:18:015 3276 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F4562
14:37:18:015 3276 TDL3_FileDetect: Processing driver: USBSTOR
14:37:18:015 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:015 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:046 3276 KLMD_ReadMem: Trying to ReadMemory 0xAF477F26[0x400]
14:37:18:046 3276 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
14:37:18:046 3276 TDL3_FileDetect: Processing driver: USBSTOR
14:37:18:046 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:046 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:046 3276 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
14:37:18:046 3276
14:37:18:046 3276 DetectCureTDL3: DEVICE_OBJECT: 89106030
14:37:18:046 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89106030
14:37:18:046 3276 DetectCureTDL3: DEVICE_OBJECT: 890F3ED0
14:37:18:046 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 890F3ED0
14:37:18:046 3276 DetectCureTDL3: DEVICE_OBJECT: 89DBE2E0
14:37:18:046 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89DBE2E0
14:37:18:046 3276 KLMD_ReadMem: Trying to ReadMemory 0x89DBE2E0[0x38]
14:37:18:046 3276 DetectCureTDL3: DRIVER_OBJECT: 891FA4D8
14:37:18:046 3276 KLMD_ReadMem: Trying to ReadMemory 0x891FA4D8[0xA8]
14:37:18:046 3276 KLMD_ReadMem: Trying to ReadMemory 0xE1956FB0[0x1E]
14:37:18:046 3276 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_CREATE : AF47B218
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_CLOSE : AF47B218
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_READ : AF47B23C
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_WRITE : AF47B23C
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_SET_EA : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : AF47B180
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : AF4769E6
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_SHUTDOWN : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_CLEANUP : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_POWER : AF47A5F0
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : AF478A6E
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F4562
14:37:18:046 3276 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F4562
14:37:18:046 3276 TDL3_FileDetect: Processing driver: USBSTOR
14:37:18:046 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:046 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:062 3276 KLMD_ReadMem: Trying to ReadMemory 0xAF477F26[0x400]
14:37:18:062 3276 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
14:37:18:062 3276 TDL3_FileDetect: Processing driver: USBSTOR
14:37:18:062 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:062 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:062 3276 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
14:37:18:062 3276
14:37:18:062 3276 DetectCureTDL3: DEVICE_OBJECT: 8910A030
14:37:18:062 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8910A030
14:37:18:062 3276 DetectCureTDL3: DEVICE_OBJECT: 890F9ED0
14:37:18:062 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 890F9ED0
14:37:18:062 3276 DetectCureTDL3: DEVICE_OBJECT: 89125030
14:37:18:062 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89125030
14:37:18:062 3276 KLMD_ReadMem: Trying to ReadMemory 0x89125030[0x38]
14:37:18:062 3276 DetectCureTDL3: DRIVER_OBJECT: 891FA4D8
14:37:18:062 3276 KLMD_ReadMem: Trying to ReadMemory 0x891FA4D8[0xA8]
14:37:18:062 3276 KLMD_ReadMem: Trying to ReadMemory 0xE1956FB0[0x1E]
14:37:18:062 3276 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_CREATE : AF47B218
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_CLOSE : AF47B218
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_READ : AF47B23C
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_WRITE : AF47B23C
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_SET_EA : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : AF47B180
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : AF4769E6
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_SHUTDOWN : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_CLEANUP : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_POWER : AF47A5F0
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : AF478A6E
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F4562
14:37:18:062 3276 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F4562
14:37:18:062 3276 TDL3_FileDetect: Processing driver: USBSTOR
14:37:18:062 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:062 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:078 3276 KLMD_ReadMem: Trying to ReadMemory 0xAF477F26[0x400]
14:37:18:078 3276 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
14:37:18:078 3276 TDL3_FileDetect: Processing driver: USBSTOR
14:37:18:078 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:078 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:078 3276 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
14:37:18:078 3276
14:37:18:078 3276 DetectCureTDL3: DEVICE_OBJECT: 890F9030
14:37:18:078 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 890F9030
14:37:18:078 3276 DetectCureTDL3: DEVICE_OBJECT: 891F0020
14:37:18:078 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 891F0020
14:37:18:078 3276 DetectCureTDL3: DEVICE_OBJECT: 8915EAF8
14:37:18:078 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8915EAF8
14:37:18:078 3276 KLMD_ReadMem: Trying to ReadMemory 0x8915EAF8[0x38]
14:37:18:078 3276 DetectCureTDL3: DRIVER_OBJECT: 891FA4D8
14:37:18:078 3276 KLMD_ReadMem: Trying to ReadMemory 0x891FA4D8[0xA8]
14:37:18:078 3276 KLMD_ReadMem: Trying to ReadMemory 0xE1956FB0[0x1E]
14:37:18:078 3276 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR
14:37:18:078 3276 DetectCureTDL3: IRP_MJ_CREATE : AF47B218
14:37:18:078 3276 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F4562
14:37:18:078 3276 DetectCureTDL3: IRP_MJ_CLOSE : AF47B218
14:37:18:078 3276 DetectCureTDL3: IRP_MJ_READ : AF47B23C
14:37:18:078 3276 DetectCureTDL3: IRP_MJ_WRITE : AF47B23C
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_SET_EA : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : AF47B180
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : AF4769E6
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_SHUTDOWN : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_CLEANUP : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_POWER : AF47A5F0
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : AF478A6E
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F4562
14:37:18:093 3276 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F4562
14:37:18:093 3276 TDL3_FileDetect: Processing driver: USBSTOR
14:37:18:093 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:093 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:125 3276 KLMD_ReadMem: Trying to ReadMemory 0xAF477F26[0x400]
14:37:18:125 3276 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
14:37:18:125 3276 TDL3_FileDetect: Processing driver: USBSTOR
14:37:18:125 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:125 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:37:18:125 3276 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
14:37:18:125 3276
14:37:18:125 3276 DetectCureTDL3: DEVICE_OBJECT: 8A8D7838
14:37:18:125 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A8D7838
14:37:18:125 3276 KLMD_ReadMem: Trying to ReadMemory 0x8A8D7838[0x38]
14:37:18:125 3276 DetectCureTDL3: DRIVER_OBJECT: 8A8FC910
14:37:18:125 3276 KLMD_ReadMem: Trying to ReadMemory 0x8A8FC910[0xA8]
14:37:18:125 3276 KLMD_ReadMem: Trying to ReadMemory 0xE1939758[0x18]
14:37:18:125 3276 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_CREATE : BA0EEBB0
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_CLOSE : BA0EEBB0
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_READ : BA0E8D1F
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_WRITE : BA0E8D1F
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_SET_EA : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : BA0E92E2
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : BA0E93BB
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : BA0ECF28
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_SHUTDOWN : BA0E92E2
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_CLEANUP : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_POWER : BA0EAC82
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : BA0EF99E
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F4562
14:37:18:125 3276 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F4562
14:37:18:125 3276 TDL3_FileDetect: Processing driver: Disk
14:37:18:125 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:125 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:140 3276 TDL3_FileDetect: Processing driver: Disk
14:37:18:140 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:140 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:156 3276 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
14:37:18:156 3276
14:37:18:156 3276 DetectCureTDL3: DEVICE_OBJECT: 8A8F7C68
14:37:18:156 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A8F7C68
14:37:18:156 3276 KLMD_ReadMem: Trying to ReadMemory 0x8A8F7C68[0x38]
14:37:18:156 3276 DetectCureTDL3: DRIVER_OBJECT: 8A8FC910
14:37:18:156 3276 KLMD_ReadMem: Trying to ReadMemory 0x8A8FC910[0xA8]
14:37:18:156 3276 KLMD_ReadMem: Trying to ReadMemory 0xE1939758[0x18]
14:37:18:156 3276 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_CREATE : BA0EEBB0
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_CLOSE : BA0EEBB0
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_READ : BA0E8D1F
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_WRITE : BA0E8D1F
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_SET_EA : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : BA0E92E2
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : BA0E93BB
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : BA0ECF28
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_SHUTDOWN : BA0E92E2
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_CLEANUP : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_POWER : BA0EAC82
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : BA0EF99E
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F4562
14:37:18:156 3276 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F4562
14:37:18:156 3276 TDL3_FileDetect: Processing driver: Disk
14:37:18:156 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:156 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:156 3276 TDL3_FileDetect: Processing driver: Disk
14:37:18:156 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:156 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:171 3276 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
14:37:18:171 3276
14:37:18:171 3276 DetectCureTDL3: DEVICE_OBJECT: 8A8CBC68
14:37:18:171 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A8CBC68
14:37:18:171 3276 KLMD_ReadMem: Trying to ReadMemory 0x8A8CBC68[0x38]
14:37:18:171 3276 DetectCureTDL3: DRIVER_OBJECT: 8A8FC910
14:37:18:171 3276 KLMD_ReadMem: Trying to ReadMemory 0x8A8FC910[0xA8]
14:37:18:171 3276 KLMD_ReadMem: Trying to ReadMemory 0xE1939758[0x18]
14:37:18:171 3276 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_CREATE : BA0EEBB0
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_CLOSE : BA0EEBB0
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_READ : BA0E8D1F
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_WRITE : BA0E8D1F
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_SET_EA : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : BA0E92E2
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : BA0E93BB
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : BA0ECF28
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_SHUTDOWN : BA0E92E2
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_CLEANUP : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_POWER : BA0EAC82
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : BA0EF99E
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F4562
14:37:18:171 3276 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F4562
14:37:18:171 3276 TDL3_FileDetect: Processing driver: Disk
14:37:18:171 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:171 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:187 3276 TDL3_FileDetect: Processing driver: Disk
14:37:18:187 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:187 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
14:37:18:203 3276 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
14:37:18:203 3276
14:37:18:203 3276 DetectCureTDL3: DEVICE_OBJECT: 8A90DAB8
14:37:18:203 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A90DAB8
14:37:18:203 3276 DetectCureTDL3: DEVICE_OBJECT: 8A901030
14:37:18:203 3276 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8A901030
14:37:18:203 3276 KLMD_ReadMem: Trying to ReadMemory 0x8A901030[0x38]
14:37:18:203 3276 DetectCureTDL3: DRIVER_OBJECT: 8A8FCA08
14:37:18:203 3276 KLMD_ReadMem: Trying to ReadMemory 0x8A8FCA08[0xA8]
14:37:18:203 3276 KLMD_ReadMem: Trying to ReadMemory 0xE101D8B0[0x1C]
14:37:18:203 3276 DetectCureTDL3: DRIVER_OBJECT name: \Driver\iastor, Driver Name: iastor
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_CREATE : B9E45142
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_CLOSE : B9E45142
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_READ : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_WRITE : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_QUERY_EA : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_SET_EA : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : B9E4884E
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : B9E48B10
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_SHUTDOWN : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_CLEANUP : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_POWER : B9E4D968
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : B9E4D9F4
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804F4562
14:37:18:203 3276 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804F4562
14:37:18:203 3276 TDL3_FileDetect: Processing driver: iastor
14:37:18:203 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\iastor.sys
14:37:18:203 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\iastor.sys
14:37:18:234 3276 TDL3_FileDetect: Processing driver: iastor
14:37:18:234 3276 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\iastor.sys
14:37:18:234 3276 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\iastor.sys
14:37:18:265 3276 TDL3_FileDetect: C:\WINDOWS\system32\drivers\iastor.sys - Verdict: Clean
14:37:18:265 3276
14:37:18:265 3276 Completed
14:37:18:265 3276
14:37:18:265 3276 Results:
14:37:18:265 3276 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
14:37:18:265 3276 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
14:37:18:265 3276 File objects infected / cured / cured on reboot: 0 / 0 / 0
14:37:18:265 3276
14:37:18:281 3276 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
14:37:18:281 3276 UtilityDeinit: KLMD(ARK) unloaded successfully