running v6.1.2 of tron System reboots during prep phase. Noticed tron.bat is missing after reboot. According to log, TDSS Killer is placing tron.bat in quarantine?
Sorry for the log spam:
23:16:51.0500 0x03cc [ F0B0CF67862ADBD29C2BC89655A2EDD0, 3F75F1D9BCDFAE02A949B8C4B2087E2263E730B29E76E7C83136A6DEDDFCF556 ] C:\Users\BARB\Desktop\tron\tron.bat 23:16:51.0500 0x03cc tron_resume - ok 23:16:51.0500 0x03cc Waiting for KSN requests completion. In queue: 115 23:16:52.0514 0x03cc Waiting for KSN requests completion. In queue: 115 23:16:53.0528 0x03cc Waiting for KSN requests completion. In queue: 115 23:16:54.0542 0x03cc Have new async UDS detects: 1 23:16:54.0542 0x03cc tron_resume - detected UDS:DangerousObject.Multi.Generic ( 0 ) 23:16:54.0604 0x03cc tron_resume ( UDS:DangerousObject.Multi.Generic ) - infected 23:16:54.0604 0x03cc Force sending object to P2P due to detect: C:\Users\BARB\Desktop\tron\tron.bat 23:16:57.0272 0x03cc Object send P2P result: true 23:16:59.0814 0x03cc C:\Users\BARB\Desktop\tron\tron.bat - copied to quarantine 23:16:59.0814 0x03cc HKU\S-1-5-21-769451878-2792895627-1360631962-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce:tron_resume - will be deleted on reboot 23:16:59.0814 0x03cc C:\Users\BARB\Desktop\tron\tron.bat - will be deleted on reboot 23:16:59.0877 0x03cc AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.7.205.0 ), 0x60100 ( disabled : updated ) 23:16:59.0908 0x03cc AV detected via SS2: AVG AntiVirus Free Edition 2015, C:\Program Files (x86)\AVG\AVG2015\avgwsc.exe ( 15.0.0.5863 ), 0x41000 ( enabled : updated ) 23:16:59.0955 0x03cc Win FW state via NFP2: enabled 23:17:02.0435 0x03cc ============================================================ 23:17:02.0435 0x03cc Scan finished 23:17:02.0435 0x03cc ============================================================ 23:17:02.0810 0x02b0 KLMD registered as C:\Windows\system32\drivers\94941870.sys 23:17:02.0966 0x0500 Deinitialize success 2015-04-04 23:17:03.05 Done. 2015-04-04 23:17:03.07 Purging oldest Shadow Copy set Win7 and up^...