>>>> Probable masking of executable file's name 1164 yahoom~1.exe, real name - YahooMessenger.exe
1.1 Searching for user-mode API hooks
Analysis: kernel32.dll, export table found in section .text
Analysis: ntdll.dll, export table found in section .text
Analysis: user32.dll, export table found in section .text
Analysis: advapi32.dll, export table found in section .text
Analysis: ws2_32.dll, export table found in section .text
Analysis: wininet.dll, export table found in section .text
Analysis: rasapi32.dll, export table found in section .text
Analysis: urlmon.dll, export table found in section .text
Analysis: netapi32.dll, export table found in section .text
1.2 Searching for kernel-mode API hooks
Driver loaded successfully
SDT found (RVA=0846E0)
Kernel ntkrnlpa.exe found in memory at address 804D7000
SDT = 8055B6E0
KiST = 80503734 (284)
Function NtCreateKey (29) intercepted (80622048->F729D0D0), hook C:\WINDOWS\system32\Drivers\sptd.sys
>>> Function restored successfully !
>>> Hook code blocked
Function NtEnumerateKey (47) intercepted (80622888->F72A2FB2), hook C:\WINDOWS\system32\Drivers\sptd.sys
>>> Function restored successfully !
>>> Hook code blocked
Function NtEnumerateValueKey (49) intercepted (80622AF2->F72A3340), hook C:\WINDOWS\system32\Drivers\sptd.sys
>>> Function restored successfully !
>>> Hook code blocked
Function NtOpenKey (77) intercepted (806233DE->F729D0B0), hook C:\WINDOWS\system32\Drivers\sptd.sys
>>> Function restored successfully !
>>> Hook code blocked
Function NtQueryKey (A0) intercepted (80623702->F72A3418), hook C:\WINDOWS\system32\Drivers\sptd.sys
>>> Function restored successfully !
>>> Hook code blocked
Function NtQueryValueKey (B1) intercepted (80620102->F72A3298), hook C:\WINDOWS\system32\Drivers\sptd.sys
>>> Function restored successfully !
>>> Hook code blocked
Function NtSetValueKey (F7) intercepted (80620708->F72A34AA), hook C:\WINDOWS\system32\Drivers\sptd.sys
>>> Function restored successfully !
>>> Hook code blocked
Functions checked: 284, intercepted: 7, restored: 7
1.3 Checking IDT and SYSENTER
Analysis for CPU 1
Analysis for CPU 2
Checking IDT and SYSENTER - complete
1.4 Searching for masking processes and drivers
Checking not performed: extended monitoring driver (AVZPM) is not installed
Driver loaded successfully
1.5 Checking of IRP handlers
\FileSystem\ntfs[IRP_MJ_CREATE] = 86FD51E8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_CLOSE] = 86FD51E8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_WRITE] = 86FD51E8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_INFORMATION] = 86FD51E8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_INFORMATION] = 86FD51E8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_EA] = 86FD51E8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_EA] = 86FD51E8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_VOLUME_INFORMATION] = 86FD51E8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_VOLUME_INFORMATION] = 86FD51E8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_DIRECTORY_CONTROL] = 86FD51E8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_FILE_SYSTEM_CONTROL] = 86FD51E8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_DEVICE_CONTROL] = 86FD51E8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_LOCK_CONTROL] = 86FD51E8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_QUERY_SECURITY] = 86FD51E8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_SET_SECURITY] = 86FD51E8 -> hook not defined
\FileSystem\ntfs[IRP_MJ_PNP] = 86FD51E8 -> hook not defined
Checking - complete
Deleting service/driver: Fms30
Quarantine file: failed (error), attempt of direct disk reading (C:\WINDOWS\System32\Drivers\Fms30.sys)
Quarantine file (direct disk reading) "%S" - failed (error)
Quarantine file: failed (error), attempt of direct disk reading (C:\WINDOWS\System32\Drivers\Fms30.sys)
Quarantine file (direct disk reading) "%S" - failed (error)
Quarantine file: failed (error), attempt of direct disk reading (C:\WINDOWS\userinit.exe)
Quarantine file (direct disk reading) "%S" - failed (error)
Quarantine file: failed (error), attempt of direct disk reading (C:\WINDOWS\userinit.exe)
Quarantine file (direct disk reading) "%S" - failed (error)
Quarantine file: failed (error), attempt of direct disk reading (rqrqnkh.dll)
Quarantine file (direct disk reading) "%S" - failed (error)
Quarantine file: failed (error), attempt of direct disk reading (rqrqnkh.dll)
Quarantine file (direct disk reading) "%S" - failed (error)
Quarantine file: failed (error), attempt of direct disk reading (C:\WINDOWS\system32\urstq.dll)
Quarantine file (direct disk reading) "%S" - failed (error)
Quarantine file: failed (error), attempt of direct disk reading (C:\WINDOWS\system32\urstq.dll)
Quarantine file (direct disk reading) "%S" - failed (error)
Quarantine file: failed (error), attempt of direct disk reading (C:\WINDOWS\system32\rqrqnkh.dll)
Quarantine file (direct disk reading) "%S" - failed (error)
Quarantine file: failed (error), attempt of direct disk reading (C:\WINDOWS\system32\rqrqnkh.dll)
Quarantine file (direct disk reading) "%S" - failed (error)
Delete file:C:\WINDOWS\system32\rqrqnkh.dll
>>>To delete the file C:\WINDOWS\system32\rqrqnkh.dll reboot is required
Delete file:C:\WINDOWS\system32\urstq.dll
>>>To delete the file C:\WINDOWS\system32\urstq.dll reboot is required
Delete file:rqrqnkh.dll
>>>To delete the file rqrqnkh.dll reboot is required
Delete file:C:\WINDOWS\System32\Drivers\Fms30.sys
>>>To delete the file C:\WINDOWS\System32\Drivers\Fms30.sys reboot is required
Removing traces of deleted files...