My computer seems to be fixed now! My search results are not being redirected anymore!!
I am cured?
Below are the results of the two logs you requested:
mbr Log:
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
TDSSKiller Log:
17:35:14:906 6516 TDSS rootkit removing tool 2.2.2 Jan 13 2010 08:42:25
17:35:14:906 6516 ================================================================================
17:35:14:906 6516 SystemInfo:
17:35:14:906 6516 OS Version: 5.1.2600 ServicePack: 3.0
17:35:14:906 6516 Product type: Workstation
17:35:14:906 6516 ComputerName: MFPDT095
17:35:14:906 6516 UserName: Ryan
17:35:14:906 6516 Windows directory: C:\WINDOWS
17:35:14:906 6516 Processor architecture: Intel x86
17:35:14:906 6516 Number of processors: 2
17:35:14:906 6516 Page size: 0x1000
17:35:14:906 6516 Boot type: Normal boot
17:35:14:906 6516 ================================================================================
17:35:14:921 6516 UnloadDriverW: NtUnloadDriver error 2
17:35:14:921 6516 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
17:35:14:921 6516 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
17:35:14:937 6516 UtilityInit: KLMD drop and load success
17:35:14:937 6516 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201000)
17:35:14:937 6516 UtilityInit: KLMD open success
17:35:14:937 6516 UtilityInit: Initialize success
17:35:14:937 6516
17:35:14:937 6516 Scanning Services ...
17:35:14:937 6516 CreateRegParser: Registry parser init started
17:35:14:937 6516 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
17:35:14:937 6516 CreateRegParser: DisableWow64Redirection error
17:35:14:937 6516 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
17:35:14:937 6516 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043
17:35:14:937 6516 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
17:35:14:937 6516 wfopen_ex: Trying to KLMD file open
17:35:14:937 6516 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system
17:35:14:937 6516 wfopen_ex: File opened ok (Flags 2)
17:35:14:937 6516 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: 274C88
17:35:14:937 6516 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
17:35:14:937 6516 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043
17:35:14:937 6516 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
17:35:14:937 6516 wfopen_ex: Trying to KLMD file open
17:35:14:937 6516 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software
17:35:14:937 6516 wfopen_ex: File opened ok (Flags 2)
17:35:14:937 6516 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: 274D30
17:35:14:937 6516 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
17:35:14:937 6516 CreateRegParser: EnableWow64Redirection error
17:35:14:937 6516 CreateRegParser: RegParser init completed
17:35:15:203 6516 GetAdvancedServicesInfo: Raw services enum returned 313 services
17:35:15:203 6516 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
17:35:15:203 6516 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
17:35:15:203 6516
17:35:15:203 6516 Scanning Kernel memory ...
17:35:15:203 6516 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
17:35:15:203 6516 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 89E4C6D0
17:35:15:203 6516 DetectCureTDL3: KLMD_GetDeviceObjectList returned 3 DevObjects
17:35:15:203 6516
17:35:15:203 6516 DetectCureTDL3: DEVICE_OBJECT: 89E12758
17:35:15:203 6516 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89E12758
17:35:15:203 6516 KLMD_ReadMem: Trying to ReadMemory 0x89E12758[0x38]
17:35:15:203 6516 DetectCureTDL3: DRIVER_OBJECT: 89E4C6D0
17:35:15:203 6516 KLMD_ReadMem: Trying to ReadMemory 0x89E4C6D0[0xA8]
17:35:15:203 6516 KLMD_ReadMem: Trying to ReadMemory 0xE14CE170[0x18]
17:35:15:203 6516 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
17:35:15:203 6516 DetectCureTDL3: IrpHandler (0) addr: BA0FEBB0
17:35:15:203 6516 DetectCureTDL3: IrpHandler (1) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (2) addr: BA0FEBB0
17:35:15:203 6516 DetectCureTDL3: IrpHandler (3) addr: BA0F8D1F
17:35:15:203 6516 DetectCureTDL3: IrpHandler (4) addr: BA0F8D1F
17:35:15:203 6516 DetectCureTDL3: IrpHandler (5) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (6) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (7) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (8) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (9) addr: BA0F92E2
17:35:15:203 6516 DetectCureTDL3: IrpHandler (10) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (11) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (12) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (13) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (14) addr: BA0F93BB
17:35:15:203 6516 DetectCureTDL3: IrpHandler (15) addr: BA0FCF28
17:35:15:203 6516 DetectCureTDL3: IrpHandler (16) addr: BA0F92E2
17:35:15:203 6516 DetectCureTDL3: IrpHandler (17) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (18) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (19) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (20) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (21) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (22) addr: BA0FAC82
17:35:15:203 6516 DetectCureTDL3: IrpHandler (23) addr: BA0FF99E
17:35:15:203 6516 DetectCureTDL3: IrpHandler (24) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (25) addr: 804F4562
17:35:15:203 6516 DetectCureTDL3: IrpHandler (26) addr: 804F4562
17:35:15:203 6516 TDL3_FileDetect: Processing driver: Disk
17:35:15:203 6516 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
17:35:15:203 6516 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
17:35:15:250 6516 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
17:35:15:250 6516
17:35:15:250 6516 DetectCureTDL3: DEVICE_OBJECT: 89E11030
17:35:15:250 6516 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89E11030
17:35:15:250 6516 KLMD_ReadMem: Trying to ReadMemory 0x89E11030[0x38]
17:35:15:250 6516 DetectCureTDL3: DRIVER_OBJECT: 89E4C6D0
17:35:15:250 6516 KLMD_ReadMem: Trying to ReadMemory 0x89E4C6D0[0xA8]
17:35:15:250 6516 KLMD_ReadMem: Trying to ReadMemory 0xE14CE170[0x18]
17:35:15:250 6516 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
17:35:15:250 6516 DetectCureTDL3: IrpHandler (0) addr: BA0FEBB0
17:35:15:250 6516 DetectCureTDL3: IrpHandler (1) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (2) addr: BA0FEBB0
17:35:15:250 6516 DetectCureTDL3: IrpHandler (3) addr: BA0F8D1F
17:35:15:250 6516 DetectCureTDL3: IrpHandler (4) addr: BA0F8D1F
17:35:15:250 6516 DetectCureTDL3: IrpHandler (5) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (6) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (7) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (8) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (9) addr: BA0F92E2
17:35:15:250 6516 DetectCureTDL3: IrpHandler (10) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (11) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (12) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (13) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (14) addr: BA0F93BB
17:35:15:250 6516 DetectCureTDL3: IrpHandler (15) addr: BA0FCF28
17:35:15:250 6516 DetectCureTDL3: IrpHandler (16) addr: BA0F92E2
17:35:15:250 6516 DetectCureTDL3: IrpHandler (17) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (18) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (19) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (20) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (21) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (22) addr: BA0FAC82
17:35:15:250 6516 DetectCureTDL3: IrpHandler (23) addr: BA0FF99E
17:35:15:250 6516 DetectCureTDL3: IrpHandler (24) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (25) addr: 804F4562
17:35:15:250 6516 DetectCureTDL3: IrpHandler (26) addr: 804F4562
17:35:15:250 6516 TDL3_FileDetect: Processing driver: Disk
17:35:15:250 6516 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
17:35:15:250 6516 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
17:35:15:250 6516 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
17:35:15:250 6516
17:35:15:250 6516 DetectCureTDL3: DEVICE_OBJECT: 89DEA848
17:35:15:250 6516 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89DEA848
17:35:15:250 6516 DetectCureTDL3: DEVICE_OBJECT: 89E3CB00
17:35:15:250 6516 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89E3CB00
17:35:15:250 6516 KLMD_ReadMem: Trying to ReadMemory 0x89E3CB00[0x38]
17:35:15:250 6516 DetectCureTDL3: DRIVER_OBJECT: 89DE48B0
17:35:15:250 6516 KLMD_ReadMem: Trying to ReadMemory 0x89DE48B0[0xA8]
17:35:15:250 6516 KLMD_ReadMem: Trying to ReadMemory 0x89DE8030[0x38]
17:35:15:250 6516 KLMD_ReadMem: Trying to ReadMemory 0x89DD0250[0xA8]
17:35:15:250 6516 KLMD_ReadMem: Trying to ReadMemory 0xE10169E0[0x1A]
17:35:15:250 6516 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
17:35:15:250 6516 DetectCureTDL3: IrpHandler (0) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (1) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (2) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (3) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (4) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (5) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (6) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (7) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (8) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (9) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (10) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (11) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (12) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (13) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (14) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (15) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (16) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (17) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (18) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (19) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (20) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (21) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (22) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (23) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (24) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (25) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: IrpHandler (26) addr: 89D74618
17:35:15:250 6516 DetectCureTDL3: All IRP handlers pointed to one addr: 89D74618
17:35:15:250 6516 KLMD_ReadMem: Trying to ReadMemory 0x89D74618[0x400]
17:35:15:250 6516 TDL3_IrpHookDetect: CheckParameters: 4, FFDF0308, 313, 101, 3, 89
17:35:15:250 6516 Driver "atapi" Irp handler infected by TDSS rootkit ... 17:35:15:250 6516 KLMD_WriteMem: Trying to WriteMemory 0x89D7467D[0xD]
17:35:15:250 6516 cured
17:35:15:250 6516 KLMD_ReadMem: Trying to ReadMemory 0x89D744BF[0x400]
17:35:15:250 6516 TDL3_StartIoHookDetect: CheckParameters: 9, FFDF0308, 1
17:35:15:250 6516 Driver "atapi" StartIo handler infected by TDSS rootkit ... 17:35:15:250 6516 TDL3_StartIoHookCure: Number of patches 1
17:35:15:250 6516 KLMD_WriteMem: Trying to WriteMemory 0x89D745B6[0x6]
17:35:15:250 6516 cured
17:35:15:250 6516 TDL3_FileDetect: Processing driver: atapi
17:35:15:250 6516 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
17:35:15:250 6516 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys
17:35:15:265 6516 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Infected
17:35:15:265 6516 File C:\WINDOWS\system32\DRIVERS\atapi.sys infected by TDSS rootkit ... 17:35:15:265 6516 TDL3_FileCure: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys
17:35:15:265 6516 ProcessDirEnumEx: FindFirstFile(C:\WINDOWS\system32\DriverStore\FileRepository\*) error 3
17:35:15:265 6516 CABFileCallback: Processing cab-file: C:\WINDOWS\Driver Cache\i386\driver.cab
17:35:15:328 6516 CABFileCallback: Processing cab-file: C:\WINDOWS\Driver Cache\i386\sp2.cab
17:35:15:343 6516 CABFileCallback: Processing cab-file: C:\WINDOWS\Driver Cache\i386\sp3.cab
17:35:15:359 6516 CabinetCallback: Backup candidate found: atapi.sys:96512, extracting..
17:35:15:468 6516 CabinetCallback: File extracted successfully: C:\DOCUME~1\Ryan\LOCALS~1\Temp\bck34F.tmp
17:35:15:468 6516 ValidateDriverFile: Stage 1 passed
17:35:15:468 6516 ValidateDriverFile: Stage 2 passed
17:35:15:531 6516 DigitalSignVerifyByHandle: Embedded DS result: 800B0100
17:35:15:703 6516 DigitalSignVerifyByHandle: Cat DS result: 00000000
17:35:15:703 6516 ValidateDriverFile: Stage 3 passed
17:35:15:703 6516 CabinetCallback: File validated successfully, restore information prepared
17:35:15:703 6516 FindDriverFileBackup: Backup copy found in cab-file
17:35:15:703 6516 TDL3_FileCure: Backup copy found, using it..
17:35:15:703 6516 TDL3_FileCure: Dumping cured buffer to file C:\WINDOWS\system32\drivers\tsk350.tmp
17:35:15:734 6516 TDL3_FileCure: New / Old Image paths: (system32\drivers\tsk350.tmp, system32\drivers\atapi.sys)
17:35:15:734 6516 TDL3_FileCure: KLMD jobs schedule success
17:35:15:734 6516 will be cured on next reboot
17:35:15:734 6516 UtilityBootReinit: Reboot required for cure complete..
17:35:15:750 6516 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmdb.sys) returned status 00000000
17:35:15:765 6516 UtilityBootReinit: KLMD drop success
17:35:15:765 6516 KLMD_ApplyPendList: Pending buffer(7A70_4A52, 608) dropped successfully
17:35:15:765 6516 UtilityBootReinit: Cure on reboot scheduled successfully
17:35:15:765 6516
17:35:15:765 6516 Completed
17:35:15:765 6516
17:35:15:765 6516 Results:
17:35:15:765 6516 Memory objects infected / cured / cured on reboot: 2 / 2 / 0
17:35:15:765 6516 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
17:35:15:765 6516 File objects infected / cured / cured on reboot: 1 / 0 / 1
17:35:15:765 6516
17:35:15:765 6516 UnloadDriverW: NtUnloadDriver error 1
17:35:15:765 6516 KLMD_Unload: UnloadDriverW(klmd21) error 1
17:35:15:765 6516 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
17:35:15:765 6516 UtilityDeinit: KLMD(ARK) unloaded successfully