1
Malware removal help / Re: Badimage.exe
« on: March 13, 2015, 02:35:27 AM »
Curson, I'm happy to report that the updated roguekiller driver did stop the badimage windows. Below you will find my log from the TDDSSKiller scan
21:19:01.0012 0x1608 TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04
21:19:15.0672 0x1608 ============================================================
21:19:15.0672 0x1608 Current date / time: 2015/03/12 21:19:15.0672
21:19:15.0672 0x1608 SystemInfo:
21:19:15.0673 0x1608
21:19:15.0673 0x1608 OS Version: 6.1.7601 ServicePack: 1.0
21:19:15.0673 0x1608 Product type: Workstation
21:19:15.0673 0x1608 ComputerName: MARTIN-PC
21:19:15.0673 0x1608 UserName: Martin
21:19:15.0673 0x1608 Windows directory: C:\Windows
21:19:15.0673 0x1608 System windows directory: C:\Windows
21:19:15.0673 0x1608 Running under WOW64
21:19:15.0673 0x1608 Processor architecture: Intel x64
21:19:15.0673 0x1608 Number of processors: 2
21:19:15.0673 0x1608 Page size: 0x1000
21:19:15.0673 0x1608 Boot type: Normal boot
21:19:15.0673 0x1608 ============================================================
21:19:17.0312 0x1608 KLMD registered as C:\Windows\system32\drivers\96494859.sys
21:19:17.0674 0x1608 System UUID: {CCAE5EBC-7580-8082-4472-9C95289E85AD}
21:19:18.0357 0x1608 Drive \Device\Harddisk0\DR0 - Size: 0x5D27700000 ( 372.62 Gb ), SectorSize: 0x200, Cylinders: 0xBE01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:19:18.0385 0x1608 ============================================================
21:19:18.0385 0x1608 \Device\Harddisk0\DR0:
21:19:18.0390 0x1608 MBR partitions:
21:19:18.0390 0x1608 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1B5CE3B
21:19:18.0390 0x1608 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1B5CE7A, BlocksNum 0x2CDDAE47
21:19:18.0390 0x1608 ============================================================
21:19:18.0418 0x1608 C: <-> \Device\Harddisk0\DR0\Partition2
21:19:18.0457 0x1608 K: <-> \Device\Harddisk0\DR0\Partition1
21:19:18.0457 0x1608 ============================================================
21:19:18.0457 0x1608 Initialize success
21:19:18.0457 0x1608 ============================================================
21:20:11.0211 0x1604 KLMD registered as C:\Windows\system32\drivers\75398767.sys
21:20:12.0568 0x1604 Deinitialize success
21:19:01.0012 0x1608 TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04
21:19:15.0672 0x1608 ============================================================
21:19:15.0672 0x1608 Current date / time: 2015/03/12 21:19:15.0672
21:19:15.0672 0x1608 SystemInfo:
21:19:15.0673 0x1608
21:19:15.0673 0x1608 OS Version: 6.1.7601 ServicePack: 1.0
21:19:15.0673 0x1608 Product type: Workstation
21:19:15.0673 0x1608 ComputerName: MARTIN-PC
21:19:15.0673 0x1608 UserName: Martin
21:19:15.0673 0x1608 Windows directory: C:\Windows
21:19:15.0673 0x1608 System windows directory: C:\Windows
21:19:15.0673 0x1608 Running under WOW64
21:19:15.0673 0x1608 Processor architecture: Intel x64
21:19:15.0673 0x1608 Number of processors: 2
21:19:15.0673 0x1608 Page size: 0x1000
21:19:15.0673 0x1608 Boot type: Normal boot
21:19:15.0673 0x1608 ============================================================
21:19:17.0312 0x1608 KLMD registered as C:\Windows\system32\drivers\96494859.sys
21:19:17.0674 0x1608 System UUID: {CCAE5EBC-7580-8082-4472-9C95289E85AD}
21:19:18.0357 0x1608 Drive \Device\Harddisk0\DR0 - Size: 0x5D27700000 ( 372.62 Gb ), SectorSize: 0x200, Cylinders: 0xBE01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:19:18.0385 0x1608 ============================================================
21:19:18.0385 0x1608 \Device\Harddisk0\DR0:
21:19:18.0390 0x1608 MBR partitions:
21:19:18.0390 0x1608 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1B5CE3B
21:19:18.0390 0x1608 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1B5CE7A, BlocksNum 0x2CDDAE47
21:19:18.0390 0x1608 ============================================================
21:19:18.0418 0x1608 C: <-> \Device\Harddisk0\DR0\Partition2
21:19:18.0457 0x1608 K: <-> \Device\Harddisk0\DR0\Partition1
21:19:18.0457 0x1608 ============================================================
21:19:18.0457 0x1608 Initialize success
21:19:18.0457 0x1608 ============================================================
21:20:11.0211 0x1604 KLMD registered as C:\Windows\system32\drivers\75398767.sys
21:20:12.0568 0x1604 Deinitialize success