0% found this document useful (0 votes)
111 views15 pages

Anti Zero Access Log

The log file documents the execution of a Webroot AntiZeroAccess program on an infected Windows XP system. The program repeatedly encountered errors when trying to access the system root volume and send IOCTL commands to check files, indicating the system disk class driver was infected with the ZeroAccess rootkit. Over 100 entries showed the same "Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL" error.

Uploaded by

Imran Khan
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
111 views15 pages

Anti Zero Access Log

The log file documents the execution of a Webroot AntiZeroAccess program on an infected Windows XP system. The program repeatedly encountered errors when trying to access the system root volume and send IOCTL commands to check files, indicating the system disk class driver was infected with the ZeroAccess rootkit. Over 100 entries showed the same "Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL" error.

Uploaded by

Imran Khan
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
You are on page 1/ 15

Webroot AntiZeroAccess 0.

8 Log File Execution time: 08/04/2012 - 12:42 Host operation System: Windows Xp X86 version 5.1.2600 Service Pack 2 12:42:31 - CheckSystem - Begin to check system... 12:42:31 - OpenRootDrive - Opening system root volume and physical drive.... 12:42:32 - C Root Drive: Disk number: 1 Start sector: 0x0000003F Partition Si ze: 0x02711637 sectors. 12:42:32 - PrevX Main driver extracted in "C:\WINDOWS\system32\drivers\ZeroAcces s.sys". 12:42:32 - InstallAndStartDriver - Main driver was installed and now is running. 12:42:32 - CheckSystem - Warning! Disk class driver is INFECTED. 12:42:32 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:32 - CheckFile - Internal consistence error: Sector buffer is not of a PE file! 12:42:32 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:32 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:32 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:32 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:32 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:32 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:32 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:32 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:33 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:33 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:33 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:33 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:33 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:33 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:33 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:33 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:33 - CheckFile - Internal consistence error: Sector buffer is not of a PE file! 12:42:33 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:33 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:33 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:33 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:33 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:33 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system

root volume object. 12:42:33 - CheckFile root volume object. 12:42:33 - CheckFile file! 12:42:33 - CheckFile root volume object. 12:42:33 - CheckFile root volume object. 12:42:33 - CheckFile root volume object. 12:42:33 - CheckFile root volume object. 12:42:33 - CheckFile root volume object. 12:42:33 - CheckFile root volume object. 12:42:33 - CheckFile root volume object. 12:42:33 - CheckFile file! 12:42:33 - CheckFile root volume object. 12:42:33 - CheckFile root volume object. 12:42:33 - CheckFile file! 12:42:33 - CheckFile root volume object. 12:42:33 - CheckFile file! 12:42:33 - CheckFile root volume object. 12:42:33 - CheckFile root volume object. 12:42:33 - CheckFile root volume object. 12:42:33 - CheckFile file! 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile file! 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile

DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system to system to system to system to system

root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile file! 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile file! 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile file! 12:42:34 - CheckFile file! 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile 0000020. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile root volume object. 12:42:34 - CheckFile

DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to read "sptd.sys" file. CreateFile last to system to system to system to system to system to system to system to system to system eror: 0x0

- Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system

root volume object. DeviceIoControl last error: 87 12:42:34 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:34 - CheckFile - Internal consistence error: Sector buffer is not of a PE file! 12:42:34 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:34 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:35 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:35 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:35 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:35 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:35 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:35 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:35 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:35 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:35 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 12:42:35 - CheckFile - Internal consistence error: Sector buffer is not of a PE file! 12:42:35 - StopAndRemoveDriver - AntiZeroAccess Driver is stopped and removed. 12:42:35 - StopAndRemoveDriver - File "ZeroAccess.sys" was deleted! 12:42:35 - Execution Ended! Webroot AntiZeroAccess 0.8 Log File Execution time: 09/04/2012 - 14:10 Host operation System: Windows Xp X86 version 5.1.2600 Service Pack 2 14:11:05 - CheckSystem - Begin to check system... 14:11:05 - OpenRootDrive - Opening system root volume and physical drive.... 14:11:05 - C Root Drive: Disk number: 1 Start sector: 0x0000003F Partition Si ze: 0x02711637 sectors. 14:11:05 - PrevX Main driver extracted in "C:\WINDOWS\system32\drivers\ZeroAcces s.sys". 14:11:05 - InstallAndStartDriver - Main driver was installed and now is running. 14:11:05 - CheckSystem - Disk class driver state is OK. 14:11:05 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 14:11:05 - CheckFile - Internal consistence error: Sector buffer is not of a PE file! 14:11:05 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 14:11:05 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 14:11:05 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 14:11:05 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 14:11:05 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 14:11:05 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system

root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile file! 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile file! 14:11:05 - CheckFile root volume object. 14:11:05 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile file! 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile

DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE

file! 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile file! 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile file! 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile file! 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile file! 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile file! 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile

- Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system to system to system to system to system

root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile file! 14:11:06 - CheckFile file! 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile 0000020. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile root volume object. 14:11:06 - CheckFile file! 14:11:06 - CheckFile root volume object. 14:11:07 - CheckFile root volume object. 14:11:07 - CheckFile root volume object. 14:11:07 - CheckFile root volume object. 14:11:07 - CheckFile root volume object. 14:11:07 - CheckFile root volume object. 14:11:07 - CheckFile root volume object. 14:11:07 - CheckFile root volume object. 14:11:07 - CheckFile root volume object. 14:11:07 - CheckFile root volume object. 14:11:07 - CheckFile

DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to read "sptd.sys" file. CreateFile last to system to system to system to system to system to system to system to system to system eror: 0x0

- Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system to system to system to system to system to system to system to system to system to system to system

root volume object. DeviceIoControl last error: 87 14:11:07 - CheckFile - Internal consistence error: Sector buffer is not of a PE file! 14:11:07 - StopAndRemoveDriver - AntiZeroAccess Driver is stopped and removed. 14:11:07 - StopAndRemoveDriver - File "ZeroAccess.sys" was deleted! 14:11:07 - Execution Ended! Webroot AntiZeroAccess 0.8 Log File Execution time: 01/05/2012 - 13:31 Host operation System: Windows Xp X86 version 5.1.2600 Service Pack 2 13:31:50 - CheckSystem - Begin to check system... 13:31:50 - OpenRootDrive - Opening system root volume and physical drive.... 13:31:50 - C Root Drive: Disk number: 1 Start sector: 0x0000003F Partition Si ze: 0x02711637 sectors. 13:31:50 - PrevX Main driver extracted in "C:\WINDOWS\system32\drivers\ZeroAcces s.sys". 13:31:50 - InstallAndStartDriver - Main driver was installed and now is running. 13:31:50 - CheckSystem - Disk class driver state is OK. 13:31:50 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:50 - CheckFile - Internal consistence error: Sector buffer is not of a PE file! 13:31:50 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:50 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:50 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:50 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:50 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:50 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:50 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:50 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:51 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:51 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:51 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:51 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:51 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:51 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:51 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:51 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:51 - CheckFile - Internal consistence error: Sector buffer is not of a PE file! 13:31:51 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:51 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system

root volume object. 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile file! 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile file! 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile file! 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile file! 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile root volume object. 13:31:51 - CheckFile file! 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile file! 13:31:52 - CheckFile

DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system

root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile file! 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile file! 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile file! 13:31:52 - CheckFile file! 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile root volume object. 13:31:52 - CheckFile

DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system to system to system to system to system to system to system to system to system

root volume object. DeviceIoControl last error: 87 13:31:52 - CheckFile - Unable to read "sptd.sys" file. CreateFile last eror: 0x0 0000020. 13:31:52 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:52 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:52 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:52 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:52 - CheckFile - Internal consistence error: Sector buffer is not of a PE file! 13:31:52 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:53 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:53 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:53 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:53 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:53 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:53 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:53 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:53 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:53 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:53 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 13:31:53 - CheckFile - Internal consistence error: Sector buffer is not of a PE file! 13:31:53 - StopAndRemoveDriver - AntiZeroAccess Driver is stopped and removed. 13:31:53 - StopAndRemoveDriver - File "ZeroAccess.sys" was deleted! 13:31:53 - Execution Ended! Webroot AntiZeroAccess 0.8 Log File Execution time: 26/05/2012 - 10:36 Host operation System: Windows Xp X86 version 5.1.2600 Service Pack 2 10:36:22 - CheckSystem - Begin to check system... 10:36:22 - OpenRootDrive - Opening system root volume and physical drive.... 10:36:23 - C Root Drive: Disk number: 1 Start sector: 0x0000003F Partition Si ze: 0x02711637 sectors. 10:36:23 - PrevX Main driver extracted in "C:\WINDOWS\system32\drivers\ZeroAcces s.sys". 10:36:23 - InstallAndStartDriver - Main driver was installed and now is running. 10:36:23 - CheckSystem - Disk class driver state is OK. 10:36:23 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 10:36:23 - CheckFile - Internal consistence error: Sector buffer is not of a PE file! 10:36:23 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 10:36:23 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system

root volume object. 10:36:23 - CheckFile root volume object. 10:36:23 - CheckFile root volume object. 10:36:23 - CheckFile root volume object. 10:36:23 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile file! 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile file! 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile file! 10:36:24 - CheckFile

DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system

root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile file! 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile file! 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile file! 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:24 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile file! 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile file! 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile file! 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile

DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system

root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile file! 10:36:25 - CheckFile file! 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile file! 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:25 - CheckFile root volume object. 10:36:26 - CheckFile root volume object. 10:36:26 - CheckFile root volume object. 10:36:26 - CheckFile root volume object. 10:36:26 - CheckFile root volume object. 10:36:26 - CheckFile

DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system DeviceIoControl last error: 87 - Internal consistence error: Sector buffer is not of a PE - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL DeviceIoControl last error: 87 - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system to system to system to system to system to system to system to system to system to system

root volume object. DeviceIoControl last error: 87 10:36:26 - CheckFile - Unable to send IOCTL_VOLUME_LOGICAL_TO_PHYSICAL to system root volume object. DeviceIoControl last error: 87 10:36:26 - CheckFile - Internal consistence error: Sector buffer is not of a PE file! 10:36:26 - StopAndRemoveDriver - AntiZeroAccess Driver is stopped and removed. 10:36:26 - StopAndRemoveDriver - File "ZeroAccess.sys" was deleted! 10:36:26 - Execution Ended!

You might also like