My computer has contracted the Alureon-FR virus. I have downloaded and ran TDSSKiller and have run the scan. I will post the log here.
Has the issue been taken care of? Sorry but I have very little knowledge of computers and the lingo so please be patient.
Thanks!!!
17:40:20:375 1248 TDSS rootkit removing tool 2.2.8 Mar 10 2010 15:53:20
17:40:20:375 1248 ================================================================================
17:40:20:375 1248 SystemInfo:
17:40:20:375 1248 OS Version: 5.1.2600 ServicePack: 3.0
17:40:20:375 1248 Product type: Workstation
17:40:20:375 1248 ComputerName: SEANIX-6C874BFA
17:40:20:375 1248 UserName: Owner
17:40:20:375 1248 Windows directory: C:\WINDOWS
17:40:20:375 1248 Processor architecture: Intel x86
17:40:20:375 1248 Number of processors: 1
17:40:20:375 1248 Page size: 0x1000
17:40:20:375 1248 Boot type: Normal boot
17:40:20:375 1248 ================================================================================
17:40:20:468 1248 UnloadDriverW: NtUnloadDriver error 2
17:40:20:468 1248 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
17:40:20:593 1248 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
17:40:20:593 1248 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
17:40:20:593 1248 wfopen_ex: Trying to KLMD file open
17:40:20:593 1248 wfopen_ex: File opened ok (Flags 2)
17:40:20:593 1248 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
17:40:20:593 1248 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
17:40:20:593 1248 wfopen_ex: Trying to KLMD file open
17:40:20:593 1248 wfopen_ex: File opened ok (Flags 2)
17:40:20:593 1248 Initialize success
17:40:20:593 1248
17:40:20:593 1248 Scanning Services …
17:40:21:093 1248 GetAdvancedServicesInfo: Raw services enum returned 324 services
17:40:21:093 1248
17:40:21:093 1248 Scanning Kernel memory …
17:40:21:093 1248 Devices to scan: 2
17:40:21:093 1248
17:40:21:093 1248 Driver Name: Disk
17:40:21:093 1248 IRP_MJ_CREATE : F7602BB0
17:40:21:093 1248 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
17:40:21:093 1248 IRP_MJ_CLOSE : F7602BB0
17:40:21:093 1248 IRP_MJ_READ : F75FCD1F
17:40:21:093 1248 IRP_MJ_WRITE : F75FCD1F
17:40:21:093 1248 IRP_MJ_QUERY_INFORMATION : 804F355A
17:40:21:093 1248 IRP_MJ_SET_INFORMATION : 804F355A
17:40:21:093 1248 IRP_MJ_QUERY_EA : 804F355A
17:40:21:093 1248 IRP_MJ_SET_EA : 804F355A
17:40:21:093 1248 IRP_MJ_FLUSH_BUFFERS : F75FD2E2
17:40:21:093 1248 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
17:40:21:093 1248 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
17:40:21:093 1248 IRP_MJ_DIRECTORY_CONTROL : 804F355A
17:40:21:093 1248 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
17:40:21:093 1248 IRP_MJ_DEVICE_CONTROL : F75FD3BB
17:40:21:093 1248 IRP_MJ_INTERNAL_DEVICE_CONTROL : F7600F28
17:40:21:093 1248 IRP_MJ_SHUTDOWN : F75FD2E2
17:40:21:093 1248 IRP_MJ_LOCK_CONTROL : 804F355A
17:40:21:093 1248 IRP_MJ_CLEANUP : 804F355A
17:40:21:093 1248 IRP_MJ_CREATE_MAILSLOT : 804F355A
17:40:21:093 1248 IRP_MJ_QUERY_SECURITY : 804F355A
17:40:21:093 1248 IRP_MJ_SET_SECURITY : 804F355A
17:40:21:093 1248 IRP_MJ_POWER : F75FEC82
17:40:21:093 1248 IRP_MJ_SYSTEM_CONTROL : F760399E
17:40:21:093 1248 IRP_MJ_DEVICE_CHANGE : 804F355A
17:40:21:093 1248 IRP_MJ_QUERY_QUOTA : 804F355A
17:40:21:093 1248 IRP_MJ_SET_QUOTA : 804F355A
17:40:21:109 1248 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
17:40:21:109 1248
17:40:21:109 1248 Driver Name: atapi
17:40:21:109 1248 IRP_MJ_CREATE : 872E1CA1
17:40:21:109 1248 IRP_MJ_CREATE_NAMED_PIPE : 872E1CA1
17:40:21:109 1248 IRP_MJ_CLOSE : 872E1CA1
17:40:21:109 1248 IRP_MJ_READ : 872E1CA1
17:40:21:109 1248 IRP_MJ_WRITE : 872E1CA1
17:40:21:109 1248 IRP_MJ_QUERY_INFORMATION : 872E1CA1
17:40:21:109 1248 IRP_MJ_SET_INFORMATION : 872E1CA1
17:40:21:109 1248 IRP_MJ_QUERY_EA : 872E1CA1
17:40:21:109 1248 IRP_MJ_SET_EA : 872E1CA1
17:40:21:109 1248 IRP_MJ_FLUSH_BUFFERS : 872E1CA1
17:40:21:109 1248 IRP_MJ_QUERY_VOLUME_INFORMATION : 872E1CA1
17:40:21:109 1248 IRP_MJ_SET_VOLUME_INFORMATION : 872E1CA1
17:40:21:109 1248 IRP_MJ_DIRECTORY_CONTROL : 872E1CA1
17:40:21:109 1248 IRP_MJ_FILE_SYSTEM_CONTROL : 872E1CA1
17:40:21:109 1248 IRP_MJ_DEVICE_CONTROL : 872E1CA1
17:40:21:109 1248 IRP_MJ_INTERNAL_DEVICE_CONTROL : 872E1CA1
17:40:21:109 1248 IRP_MJ_SHUTDOWN : 872E1CA1
17:40:21:109 1248 IRP_MJ_LOCK_CONTROL : 872E1CA1
17:40:21:109 1248 IRP_MJ_CLEANUP : 872E1CA1
17:40:21:109 1248 IRP_MJ_CREATE_MAILSLOT : 872E1CA1
17:40:21:109 1248 IRP_MJ_QUERY_SECURITY : 872E1CA1
17:40:21:109 1248 IRP_MJ_SET_SECURITY : 872E1CA1
17:40:21:109 1248 IRP_MJ_POWER : 872E1CA1
17:40:21:109 1248 IRP_MJ_SYSTEM_CONTROL : 872E1CA1
17:40:21:109 1248 IRP_MJ_DEVICE_CHANGE : 872E1CA1
17:40:21:109 1248 IRP_MJ_QUERY_QUOTA : 872E1CA1
17:40:21:109 1248 IRP_MJ_SET_QUOTA : 872E1CA1
17:40:21:109 1248 Driver “atapi” infected by TDSS rootkit!
17:40:21:109 1248 C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: 1
17:40:21:109 1248 File “C:\WINDOWS\system32\DRIVERS\atapi.sys” infected by TDSS rootkit … 17:40:21:109 1248 Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
17:40:21:109 1248 ProcessDirEnumEx: FindFirstFile(C:\WINDOWS\system32\DriverStore\FileRepository*) error 3
17:40:21:187 1248 vfvi6
17:40:21:234 1248 !dsvbh1
17:40:23:156 1248 dsvbh2
17:40:23:171 1248 fdfb2
17:40:23:171 1248 Backup copy found, using it…
17:40:23:171 1248 will be cured on next reboot
17:40:23:171 1248 Reboot required for cure complete…
17:40:23:218 1248 Cure on reboot scheduled successfully
17:40:23:218 1248
17:40:23:218 1248 Completed
17:40:23:218 1248
17:40:23:218 1248 Results:
17:40:23:218 1248 Memory objects infected / cured / cured on reboot: 1 / 0 / 0
17:40:23:218 1248 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
17:40:23:218 1248 File objects infected / cured / cured on reboot: 1 / 0 / 1
17:40:23:218 1248
17:40:23:218 1248 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
17:40:23:218 1248 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
17:40:23:218 1248 UnloadDriverW: NtUnloadDriver error 1
17:40:23:218 1248 KLMD_Unload: UnloadDriverW(klmd21) error 1
17:40:23:234 1248 KLMD(ARK) unloaded successfully