14:05:51.0797 0x0df8 TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04 14:05:53.0688 0x0df8 ============================================================ 14:05:53.0689 0x0df8 Current date / time: 2015/07/02 14:05:53.0688 14:05:53.0689 0x0df8 SystemInfo: 14:05:53.0689 0x0df8 14:05:53.0689 0x0df8 OS Version: 6.1.7600 ServicePack: 0.0 14:05:53.0689 0x0df8 Product type: Workstation 14:05:53.0689 0x0df8 ComputerName: HYPER-KOMPUTER 14:05:53.0689 0x0df8 UserName: HYPER 14:05:53.0689 0x0df8 Windows directory: C:\Windows 14:05:53.0689 0x0df8 System windows directory: C:\Windows 14:05:53.0689 0x0df8 Processor architecture: Intel x86 14:05:53.0689 0x0df8 Number of processors: 4 14:05:53.0690 0x0df8 Page size: 0x1000 14:05:53.0690 0x0df8 Boot type: Normal boot 14:05:53.0690 0x0df8 ============================================================ 14:05:55.0884 0x0df8 KLMD registered as C:\Windows\system32\drivers\37058203.sys 14:05:56.0893 0x0df8 System UUID: {98D24377-807A-E6E9-1DF8-6A806BB8150F} 14:05:57.0946 0x0df8 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 14:05:57.0970 0x0df8 ============================================================ 14:05:57.0971 0x0df8 \Device\Harddisk0\DR0: 14:05:57.0971 0x0df8 MBR partitions: 14:05:57.0971 0x0df8 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 14:05:57.0971 0x0df8 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xC31D800 14:05:57.0971 0x0df8 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0xC350000, BlocksNum 0x124F8000 14:05:57.0971 0x0df8 \Device\Harddisk0\DR0\Partition4: MBR, Type 0x7, StartLBA 0x1E848000, BlocksNum 0x1BB3D800 14:05:57.0971 0x0df8 ============================================================ 14:05:58.0031 0x0df8 C: <-> \Device\Harddisk0\DR0\Partition2 14:05:58.0068 0x0df8 D: <-> \Device\Harddisk0\DR0\Partition3 14:05:58.0106 0x0df8 E: <-> \Device\Harddisk0\DR0\Partition4 14:05:58.0144 0x0df8 ============================================================ 14:05:58.0144 0x0df8 Initialize success 14:05:58.0144 0x0df8 ============================================================ 14:06:04.0130 0x1424 Deinitialize success