21:19:24.0972 0x0c80 TDSS rootkit removing tool 3.1.0.11 Aug 5 2016 12:13:31 21:19:25.0487 0x0c80 ============================================================ 21:19:25.0487 0x0c80 Current date / time: 2016/08/24 21:19:25.0487 21:19:25.0487 0x0c80 SystemInfo: 21:19:25.0487 0x0c80 21:19:25.0487 0x0c80 OS Version: 6.1.7601 ServicePack: 1.0 21:19:25.0487 0x0c80 Product type: Workstation 21:19:25.0487 0x0c80 ComputerName: DB-PC 21:19:25.0487 0x0c80 UserName: DB 21:19:25.0487 0x0c80 Windows directory: C:\Windows 21:19:25.0487 0x0c80 System windows directory: C:\Windows 21:19:25.0487 0x0c80 Running under WOW64 21:19:25.0487 0x0c80 Processor architecture: Intel x64 21:19:25.0487 0x0c80 Number of processors: 2 21:19:25.0487 0x0c80 Page size: 0x1000 21:19:25.0487 0x0c80 Boot type: Normal boot 21:19:25.0487 0x0c80 CodeIntegrityOptions = 0x00000003 21:19:25.0487 0x0c80 ============================================================ 21:19:25.0487 0x0c80 KLMD ARK init status: drvProperties = 0xFFFF00, osBuild = 7601.18717, osProperties = 0x1 21:19:25.0487 0x0c80 KLMD BG init status: drvProperties = 0xFFFF00, osBuild = 7601.18717, osProperties = 0x1 21:19:25.0487 0x0c80 BG loaded 21:19:26.0407 0x0c80 System UUID: {A9ED213A-394F-3617-F59B-BA8BBA98CBB4} 21:19:29.0948 0x0c80 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 ( 149.05 Gb ), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 21:19:29.0964 0x0c80 Drive \Device\Harddisk1\DR1 - Size: 0x3AA780000 ( 14.66 Gb ), SectorSize: 0x200, Cylinders: 0x77A, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 21:19:29.0964 0x0c80 ============================================================ 21:19:29.0964 0x0c80 \Device\Harddisk0\DR0: 21:19:29.0964 0x0c80 MBR partitions: 21:19:29.0964 0x0c80 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1402800, BlocksNum 0x11616800 21:19:29.0964 0x0c80 \Device\Harddisk1\DR1: 21:19:29.0964 0x0c80 MBR partitions: 21:19:29.0964 0x0c80 \Device\Harddisk1\DR1\Partition1: MBR, Type 0xC, StartLBA 0x20, BlocksNum 0x1D53BE0 21:19:29.0964 0x0c80 ============================================================ 21:19:30.0011 0x0c80 C: <-> \Device\Harddisk0\DR0\Partition1 21:19:30.0011 0x0c80 ============================================================ 21:19:30.0011 0x0c80 Initialize success 21:19:30.0011 0x0c80 ============================================================ 21:20:20.0138 0x0fac Deinitialize success