10:00:22.0039 0x1a34 TDSS rootkit removing tool 3.0.0.42 Dec 12 2014 00:35:20 10:00:31.0727 0x1a34 ============================================================ 10:00:31.0727 0x1a34 Current date / time: 2015/01/14 10:00:31.0727 10:00:31.0727 0x1a34 SystemInfo: 10:00:31.0727 0x1a34 10:00:31.0727 0x1a34 OS Version: 6.1.7601 ServicePack: 1.0 10:00:31.0727 0x1a34 Product type: Workstation 10:00:31.0727 0x1a34 ComputerName: NIKI-PC 10:00:31.0728 0x1a34 UserName: Niki 10:00:31.0728 0x1a34 Windows directory: C:\windows 10:00:31.0728 0x1a34 System windows directory: C:\windows 10:00:31.0728 0x1a34 Processor architecture: Intel x86 10:00:31.0728 0x1a34 Number of processors: 2 10:00:31.0728 0x1a34 Page size: 0x1000 10:00:31.0728 0x1a34 Boot type: Normal boot 10:00:31.0728 0x1a34 ============================================================ 10:00:33.0233 0x1a34 KLMD registered as C:\windows\system32\drivers\53456415.sys 10:00:35.0008 0x1a34 System UUID: {5607F5C3-29AB-3DBD-DA84-CE585D5E2A2F} 10:00:37.0324 0x1a34 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 ( 298.09 Gb ), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 10:00:37.0396 0x1a34 Drive \Device\Harddisk1\DR1 - Size: 0x1CF000000 ( 7.23 Gb ), SectorSize: 0x200, Cylinders: 0x3B0, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 10:00:37.0397 0x1a34 ============================================================ 10:00:37.0397 0x1a34 \Device\Harddisk0\DR0: 10:00:37.0457 0x1a34 MBR partitions: 10:00:37.0457 0x1a34 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1E00800, BlocksNum 0x32000 10:00:37.0457 0x1a34 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1E32800, BlocksNum 0x10A02800 10:00:37.0457 0x1a34 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x12835000, BlocksNum 0x12BF9000 10:00:37.0457 0x1a34 \Device\Harddisk1\DR1: 10:00:37.0458 0x1a34 MBR partitions: 10:00:37.0458 0x1a34 \Device\Harddisk1\DR1\Partition1: MBR, Type 0xB, StartLBA 0xC98, BlocksNum 0xE77368 10:00:37.0459 0x1a34 ============================================================ 10:00:37.0484 0x1a34 C: <-> \Device\Harddisk0\DR0\Partition2 10:00:37.0575 0x1a34 D: <-> \Device\Harddisk0\DR0\Partition3 10:00:37.0575 0x1a34 ============================================================ 10:00:37.0575 0x1a34 Initialize success 10:00:37.0575 0x1a34 ============================================================ 10:00:44.0625 0x1a30 Deinitialize success