I have tried to shut down AVG, but Security Tool is intercepting avgui.exe and preventing it from running. Is there a command I can run to shut down AVG?
Tried TDSSKiller.exe - the first time I ran it, I got a message that said I didn't have the proper privileges to run it.
Sidenote: This computer was originally set up to log in from home to a corporate network (when they parted ways, they left her the computer but didn't wipe it, so her account has whatever privileges were set by the corporate IT guy), and I don't know the administrator password on it. And with Security Tool intercepting most of the things I try, I'm not sure how to even check what her account privileges are.I tried it again, and got a CMD window for a second or so, which then disappeared, followed by a message from Security Tool that TDSSKiller was a virus. The log from that run is here:
15:49:10:312 2152 TDSS rootkit removing tool 2.2.2 Jan 13 2010 08:42:25
15:49:10:312 2152 ================================================================================
15:49:10:312 2152 SystemInfo:
15:49:10:312 2152 OS Version: 5.1.2600 ServicePack: 2.0
15:49:10:312 2152 Product type: Workstation
15:49:10:312 2152 ComputerName: N16468
15:49:10:312 2152 UserName: eduffy
15:49:10:312 2152 Windows directory: C:\WINDOWS
15:49:10:312 2152 Processor architecture: Intel x86
15:49:10:312 2152 Number of processors: 2
15:49:10:312 2152 Page size: 0x1000
15:49:10:312 2152 Boot type: Normal boot
15:49:10:312 2152 ================================================================================
15:49:10:328 2152 UnloadDriverW: NtUnloadDriver error 2
15:49:10:328 2152 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
15:49:10:359 2152 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
15:49:10:437 2152 UtilityInit: KLMD drop and load success
15:49:10:437 2152 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201000)
15:49:10:437 2152 UtilityInit: KLMD open success
15:49:10:437 2152 UtilityInit: Initialize success
15:49:10:437 2152
15:49:10:437 2152 Scanning Services ...
15:49:10:437 2152 CreateRegParser: Registry parser init started
15:49:10:437 2152 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
15:49:10:437 2152 CreateRegParser: DisableWow64Redirection error
15:49:10:437 2152 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
15:49:10:437 2152 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043
15:49:10:437 2152 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
15:49:10:437 2152 wfopen_ex: Trying to KLMD file open
15:49:10:437 2152 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system
15:49:10:437 2152 wfopen_ex: File opened ok (Flags 2)
15:49:10:437 2152 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: AC4908
15:49:10:437 2152 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
15:49:10:437 2152 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043
15:49:10:437 2152 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
15:49:10:437 2152 wfopen_ex: Trying to KLMD file open
15:49:10:437 2152 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software
15:49:10:453 2152 wfopen_ex: File opened ok (Flags 2)
15:49:10:453 2152 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: AC49B0
15:49:10:453 2152 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
15:49:10:453 2152 CreateRegParser: EnableWow64Redirection error
15:49:10:453 2152 CreateRegParser: RegParser init completed
I tried a couple of times, and got similar logs. I decided to try running rkill immediately before the command and it ran longer, but never reached the point where it prompted me to delete anything. I got the following log:
15:49:56:234 2160 TDSS rootkit removing tool 2.2.2 Jan 13 2010 08:42:25
15:49:56:234 2160 ================================================================================
15:49:56:234 2160 SystemInfo:
15:49:56:234 2160 OS Version: 5.1.2600 ServicePack: 2.0
15:49:56:234 2160 Product type: Workstation
15:49:56:234 2160 ComputerName: N16468
15:49:56:234 2160 UserName: eduffy
15:49:56:234 2160 Windows directory: C:\WINDOWS
15:49:56:234 2160 Processor architecture: Intel x86
15:49:56:234 2160 Number of processors: 2
15:49:56:234 2160 Page size: 0x1000
15:49:56:234 2160 Boot type: Normal boot
15:49:56:234 2160 ================================================================================
15:49:56:250 2160 UnloadDriverW: NtUnloadDriver error 2
15:49:56:250 2160 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
15:49:56:250 2160 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
15:49:56:296 2160 UtilityInit: KLMD drop and load success
15:49:56:296 2160 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201000)
15:49:56:296 2160 UtilityInit: KLMD open success
15:49:56:296 2160 UtilityInit: Initialize success
15:49:56:296 2160
15:49:56:296 2160 Scanning Services ...
15:49:56:296 2160 CreateRegParser: Registry parser init started
15:49:56:296 2160 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
15:49:56:296 2160 CreateRegParser: DisableWow64Redirection error
15:49:56:296 2160 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
15:49:56:296 2160 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043
15:49:56:296 2160 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
15:49:56:296 2160 wfopen_ex: Trying to KLMD file open
15:49:56:296 2160 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system
15:49:56:296 2160 wfopen_ex: File opened ok (Flags 2)
15:49:56:296 2160 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: AC4908
15:49:56:296 2160 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
15:49:56:296 2160 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043
15:49:56:296 2160 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
15:49:56:296 2160 wfopen_ex: Trying to KLMD file open
15:49:56:296 2160 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software
15:49:56:296 2160 wfopen_ex: File opened ok (Flags 2)
15:49:56:296 2160 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: AC49B0
15:49:56:296 2160 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
15:49:56:296 2160 CreateRegParser: EnableWow64Redirection error
15:49:56:296 2160 CreateRegParser: RegParser init completed
15:49:56:781 2160 GetAdvancedServicesInfo: Raw services enum returned 315 services
15:49:56:796 2160 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
15:49:56:796 2160 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
15:49:56:796 2160
15:49:56:796 2160 Scanning Kernel memory ...
15:49:56:796 2160 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
15:49:56:796 2160 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 8638D920
15:49:56:796 2160 DetectCureTDL3: KLMD_GetDeviceObjectList returned 5 DevObjects
15:49:56:796 2160
15:49:56:796 2160 DetectCureTDL3: DEVICE_OBJECT: 85BA6C68
15:49:56:796 2160 KLMD_GetLowerDeviceObject: Trying to get lower device object for 85BA6C68
15:49:56:796 2160 KLMD_ReadMem: Trying to ReadMemory 0x85BA6C68[0x38]
15:49:56:796 2160 DetectCureTDL3: DRIVER_OBJECT: 8638D920
15:49:56:796 2160 KLMD_ReadMem: Trying to ReadMemory 0x8638D920[0xA8]
15:49:56:796 2160 KLMD_ReadMem: Trying to ReadMemory 0xE15BFB58[0x18]
15:49:56:796 2160 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
15:49:56:796 2160 DetectCureTDL3: IrpHandler (0) addr: F7653C30
15:49:56:796 2160 DetectCureTDL3: IrpHandler (1) addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (2) addr: F7653C30
15:49:56:796 2160 DetectCureTDL3: IrpHandler (3) addr: F764DD9B
15:49:56:796 2160 DetectCureTDL3: IrpHandler (4) addr: F764DD9B
15:49:56:796 2160 DetectCureTDL3: IrpHandler (5) addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (6) addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (7) addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (
addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (9) addr: F764E366
15:49:56:796 2160 DetectCureTDL3: IrpHandler (10) addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (11) addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (12) addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (13) addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (14) addr: F764E44D
15:49:56:796 2160 DetectCureTDL3: IrpHandler (15) addr: F7651FC3
15:49:56:796 2160 DetectCureTDL3: IrpHandler (16) addr: F764E366
15:49:56:796 2160 DetectCureTDL3: IrpHandler (17) addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (18) addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (19) addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (20) addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (21) addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (22) addr: F764FEF3
15:49:56:796 2160 DetectCureTDL3: IrpHandler (23) addr: F7654A24
15:49:56:796 2160 DetectCureTDL3: IrpHandler (24) addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (25) addr: 804F9709
15:49:56:796 2160 DetectCureTDL3: IrpHandler (26) addr: 804F9709
15:49:56:796 2160 TDL3_FileDetect: Processing driver: Disk
15:49:56:796 2160 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
15:49:56:796 2160 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
15:49:56:859 2160 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
15:49:56:859 2160
15:49:56:859 2160 DetectCureTDL3: DEVICE_OBJECT: 85C91AB8
15:49:56:859 2160 KLMD_GetLowerDeviceObject: Trying to get lower device object for 85C91AB8
15:49:56:859 2160 DetectCureTDL3: DEVICE_OBJECT: 85C5DC50
15:49:56:859 2160 KLMD_GetLowerDeviceObject: Trying to get lower device object for 85C5DC50
15:49:56:859 2160 KLMD_ReadMem: Trying to ReadMemory 0x85C5DC50[0x38]
15:49:56:859 2160 DetectCureTDL3: DRIVER_OBJECT: 85EA7030
15:49:56:859 2160 KLMD_ReadMem: Trying to ReadMemory 0x85EA7030[0xA8]
15:49:56:859 2160 KLMD_ReadMem: Trying to ReadMemory 0xE7D0BCF0[0x1E]
15:49:56:859 2160 DetectCureTDL3: DRIVER_OBJECT name: \Driver\usbstor, Driver Name: usbstor
15:49:56:859 2160 DetectCureTDL3: IrpHandler (0) addr: F78AA218
15:49:56:859 2160 DetectCureTDL3: IrpHandler (1) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (2) addr: F78AA218
15:49:56:859 2160 DetectCureTDL3: IrpHandler (3) addr: F78AA23C
15:49:56:859 2160 DetectCureTDL3: IrpHandler (4) addr: F78AA23C
15:49:56:859 2160 DetectCureTDL3: IrpHandler (5) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (6) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (7) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (
addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (9) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (10) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (11) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (12) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (13) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (14) addr: F78AA180
15:49:56:859 2160 DetectCureTDL3: IrpHandler (15) addr: F78A59E6
15:49:56:859 2160 DetectCureTDL3: IrpHandler (16) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (17) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (18) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (19) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (20) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (21) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (22) addr: F78A95F0
15:49:56:859 2160 DetectCureTDL3: IrpHandler (23) addr: F78A7A6E
15:49:56:859 2160 DetectCureTDL3: IrpHandler (24) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (25) addr: 804F9709
15:49:56:859 2160 DetectCureTDL3: IrpHandler (26) addr: 804F9709
15:49:56:859 2160 KLMD_ReadMem: Trying to ReadMemory 0xF78A6F26[0x400]
15:49:56:859 2160 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
15:49:56:859 2160 TDL3_FileDetect: Processing driver: usbstor
15:49:56:859 2160 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
15:49:56:859 2160 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
15:49:56:890 2160 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
15:49:56:890 2160
15:49:56:890 2160 DetectCureTDL3: DEVICE_OBJECT: 86351C68
15:49:56:890 2160 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86351C68
15:49:56:890 2160 KLMD_ReadMem: Trying to ReadMemory 0x86351C68[0x38]
15:49:56:890 2160 DetectCureTDL3: DRIVER_OBJECT: 8638D920
15:49:56:890 2160 KLMD_ReadMem: Trying to ReadMemory 0x8638D920[0xA8]
15:49:56:890 2160 KLMD_ReadMem: Trying to ReadMemory 0xE15BFB58[0x18]
15:49:56:890 2160 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
15:49:56:890 2160 DetectCureTDL3: IrpHandler (0) addr: F7653C30
15:49:56:890 2160 DetectCureTDL3: IrpHandler (1) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (2) addr: F7653C30
15:49:56:890 2160 DetectCureTDL3: IrpHandler (3) addr: F764DD9B
15:49:56:890 2160 DetectCureTDL3: IrpHandler (4) addr: F764DD9B
15:49:56:890 2160 DetectCureTDL3: IrpHandler (5) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (6) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (7) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (
addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (9) addr: F764E366
15:49:56:890 2160 DetectCureTDL3: IrpHandler (10) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (11) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (12) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (13) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (14) addr: F764E44D
15:49:56:890 2160 DetectCureTDL3: IrpHandler (15) addr: F7651FC3
15:49:56:890 2160 DetectCureTDL3: IrpHandler (16) addr: F764E366
15:49:56:890 2160 DetectCureTDL3: IrpHandler (17) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (18) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (19) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (20) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (21) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (22) addr: F764FEF3
15:49:56:890 2160 DetectCureTDL3: IrpHandler (23) addr: F7654A24
15:49:56:890 2160 DetectCureTDL3: IrpHandler (24) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (25) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (26) addr: 804F9709
15:49:56:890 2160 TDL3_FileDetect: Processing driver: Disk
15:49:56:890 2160 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
15:49:56:890 2160 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
15:49:56:890 2160 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
15:49:56:890 2160
15:49:56:890 2160 DetectCureTDL3: DEVICE_OBJECT: 8633FC68
15:49:56:890 2160 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8633FC68
15:49:56:890 2160 KLMD_ReadMem: Trying to ReadMemory 0x8633FC68[0x38]
15:49:56:890 2160 DetectCureTDL3: DRIVER_OBJECT: 8638D920
15:49:56:890 2160 KLMD_ReadMem: Trying to ReadMemory 0x8638D920[0xA8]
15:49:56:890 2160 KLMD_ReadMem: Trying to ReadMemory 0xE15BFB58[0x18]
15:49:56:890 2160 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
15:49:56:890 2160 DetectCureTDL3: IrpHandler (0) addr: F7653C30
15:49:56:890 2160 DetectCureTDL3: IrpHandler (1) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (2) addr: F7653C30
15:49:56:890 2160 DetectCureTDL3: IrpHandler (3) addr: F764DD9B
15:49:56:890 2160 DetectCureTDL3: IrpHandler (4) addr: F764DD9B
15:49:56:890 2160 DetectCureTDL3: IrpHandler (5) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (6) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (7) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (
addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (9) addr: F764E366
15:49:56:890 2160 DetectCureTDL3: IrpHandler (10) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (11) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (12) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (13) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (14) addr: F764E44D
15:49:56:890 2160 DetectCureTDL3: IrpHandler (15) addr: F7651FC3
15:49:56:890 2160 DetectCureTDL3: IrpHandler (16) addr: F764E366
15:49:56:890 2160 DetectCureTDL3: IrpHandler (17) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (18) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (19) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (20) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (21) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (22) addr: F764FEF3
15:49:56:890 2160 DetectCureTDL3: IrpHandler (23) addr: F7654A24
15:49:56:890 2160 DetectCureTDL3: IrpHandler (24) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (25) addr: 804F9709
15:49:56:890 2160 DetectCureTDL3: IrpHandler (26) addr: 804F9709
15:49:56:890 2160 TDL3_FileDetect: Processing driver: Disk
15:49:56:890 2160 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
15:49:56:890 2160 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
15:49:56:906 2160 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
15:49:56:906 2160
15:49:56:906 2160 DetectCureTDL3: DEVICE_OBJECT: 863A6AB8
15:49:56:906 2160 KLMD_GetLowerDeviceObject: Trying to get lower device object for 863A6AB8
15:49:56:906 2160 DetectCureTDL3: DEVICE_OBJECT: 863E1908
15:49:56:906 2160 KLMD_GetLowerDeviceObject: Trying to get lower device object for 863E1908
15:49:56:906 2160 KLMD_ReadMem: Trying to ReadMemory 0x863E1908[0x38]
15:49:56:906 2160 DetectCureTDL3: DRIVER_OBJECT: 863489C8
15:49:56:906 2160 KLMD_ReadMem: Trying to ReadMemory 0x863489C8[0xA8]
15:49:56:906 2160 KLMD_ReadMem: Trying to ReadMemory 0xE1017B28[0x1A]
15:49:56:906 2160 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
15:49:56:906 2160 DetectCureTDL3: IrpHandler (0) addr: F755A572
15:49:56:906 2160 DetectCureTDL3: IrpHandler (1) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (2) addr: F755A572
15:49:56:906 2160 DetectCureTDL3: IrpHandler (3) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (4) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (5) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (6) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (7) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (
addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (9) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (10) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (11) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (12) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (13) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (14) addr: F755A592
15:49:56:906 2160 DetectCureTDL3: IrpHandler (15) addr: F75567B4
15:49:56:906 2160 DetectCureTDL3: IrpHandler (16) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (17) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (18) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (19) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (20) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (21) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (22) addr: F755A5BC
15:49:56:906 2160 DetectCureTDL3: IrpHandler (23) addr: F7561164
15:49:56:906 2160 DetectCureTDL3: IrpHandler (24) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (25) addr: 804F9709
15:49:56:906 2160 DetectCureTDL3: IrpHandler (26) addr: 804F9709
15:49:56:906 2160 KLMD_ReadMem: Trying to ReadMemory 0xF75577C6[0x400]
15:49:56:906 2160 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
15:49:56:906 2160 TDL3_FileDetect: Processing driver: atapi
15:49:56:906 2160 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
15:49:56:906 2160 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys
15:49:56:921 2160 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Clean
15:49:56:921 2160
15:49:56:921 2160 Completed
15:49:56:921 2160
15:49:56:921 2160 Results:
15:49:56:921 2160 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
15:49:56:921 2160 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
15:49:56:921 2160 File objects infected / cured / cured on reboot: 0 / 0 / 0
15:49:56:921 2160
15:49:56:921 2160 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
15:49:56:921 2160 UtilityDeinit: KLMD(ARK) unloaded successfully
As always, I appreciate any help you can give me.