13:49:04.0080 7496 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35 13:49:04.0533 7496 ============================================================ 13:49:04.0533 7496 Current date / time: 2013/01/20 13:49:04.0533 13:49:04.0533 7496 SystemInfo: 13:49:04.0533 7496 13:49:04.0533 7496 OS Version: 6.1.7601 ServicePack: 1.0 13:49:04.0533 7496 Product type: Workstation 13:49:04.0533 7496 ComputerName: RAN-PC 13:49:04.0533 7496 UserName: Ran 13:49:04.0533 7496 Windows directory: C:\Windows 13:49:04.0533 7496 System windows directory: C:\Windows 13:49:04.0533 7496 Processor architecture: Intel x86 13:49:04.0533 7496 Number of processors: 2 13:49:04.0533 7496 Page size: 0x1000 13:49:04.0533 7496 Boot type: Normal boot 13:49:04.0533 7496 ============================================================ 13:49:06.0045 7496 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0CADE00 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 13:49:06.0048 7496 Drive \Device\Harddisk2\DR2 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 13:49:06.0048 7496 ============================================================ 13:49:06.0048 7496 \Device\Harddisk0\DR0: 13:49:06.0049 7496 MBR partitions: 13:49:06.0049 7496 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x249ED825 13:49:06.0049 7496 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x249EE000, BlocksNum 0x3D12B000 13:49:06.0069 7496 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x61B19800, BlocksNum 0x12BEC000 13:49:06.0069 7496 \Device\Harddisk2\DR2: 13:49:06.0070 7496 MBR partitions: 13:49:06.0070 7496 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x74705982 13:49:06.0070 7496 ============================================================ 13:49:06.0105 7496 C: <-> \Device\Harddisk0\DR0\Partition2 13:49:06.0131 7496 D: <-> \Device\Harddisk0\DR0\Partition1 13:49:06.0153 7496 E: <-> \Device\Harddisk0\DR0\Partition3 13:49:06.0183 7496 H: <-> \Device\Harddisk2\DR2\Partition1 13:49:06.0183 7496 ============================================================ 13:49:06.0183 7496 Initialize success 13:49:06.0183 7496 ============================================================ 13:49:55.0380 7112 Deinitialize success