00:59:09.0810 0x1388 TDSS rootkit removing tool 3.0.0.19 Nov 18 2013 09:27:50
00:59:09.0810 0x1388 UEFI system
00:59:17.0969 0x1388 ============================================================
00:59:17.0969 0x1388 Current date / time: 2014/01/11 00:59:17.0969
00:59:17.0969 0x1388 SystemInfo:
00:59:17.0969 0x1388
00:59:17.0969 0x1388 OS Version: 6.2.9200 ServicePack: 0.0
00:59:17.0969 0x1388 Product type: Workstation
00:59:17.0969 0x1388 ComputerName: NEWOS8
00:59:17.0969 0x1388 UserName: Karl
00:59:17.0969 0x1388 Windows directory: C:\WINDOWS
00:59:17.0969 0x1388 System windows directory: C:\WINDOWS
00:59:17.0969 0x1388 Running under WOW64
00:59:17.0969 0x1388 Processor architecture: Intel x64
00:59:17.0969 0x1388 Number of processors: 4
00:59:17.0969 0x1388 Page size: 0x1000
00:59:17.0969 0x1388 Boot type: Normal boot
00:59:17.0969 0x1388 ============================================================
00:59:18.0905 0x1388 KLMD registered as C:\WINDOWS\system32\drivers\15319123.sys
00:59:19.0092 0x1388 System UUID: {1B9D1B86-4DAB-C999-A438-71CE0AA50E81}
00:59:19.0841 0x1388 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
00:59:19.0857 0x1388 Drive \Device\Harddisk1\DR1 - Size: 0x3AE00000 (0.92 Gb), SectorSize: 0x200, Cylinders: 0x78, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
00:59:19.0997 0x1388 ============================================================
00:59:19.0997 0x1388 \Device\Harddisk0\DR0:
00:59:20.0028 0x1388 GPT partitions:
00:59:20.0028 0x1388 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {6B139546-F3E4-423C-8A5A-5429389899B4}, Name: EFI system partition, StartLBA 0x800, BlocksNum 0x96000
00:59:20.0028 0x1388 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {1ECA3787-605B-4E4E-947E-603B155F5389}, Name: Basic data partition, StartLBA 0x96800, BlocksNum 0x1C2000
00:59:20.0028 0x1388 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {453316B9-F18D-4E99-9434-C5F0B6DD80A8}, Name: Microsoft reserved partition, StartLBA 0x258800, BlocksNum 0x40000
00:59:20.0028 0x1388 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {A5DC35F6-5A5E-47F9-97D2-207DDF78489E}, Name: Basic data partition, StartLBA 0x298800, BlocksNum 0x37839800
00:59:20.0028 0x1388 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {297B2F4A-1D68-4536-A576-883CC01C92E2}, Name: , StartLBA 0x37AD2000, BlocksNum 0xAF000
00:59:20.0028 0x1388 \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {14FA438D-4143-4E70-923A-F3A4F971CEB9}, Name: Basic data partition, StartLBA 0x37B81000, BlocksNum 0x2805000
00:59:20.0028 0x1388 MBR partitions:
00:59:20.0028 0x1388 \Device\Harddisk1\DR1:
00:59:20.0028 0x1388 Can't read MBR
00:59:20.0028 0x1388 ============================================================
00:59:20.0122 0x1388 C: <-> \Device\Harddisk0\DR0\Partition4
00:59:20.0122 0x1388 ============================================================
00:59:20.0122 0x1388 Initialize success
00:59:20.0122 0x1388 ============================================================
00:59:25.0270 0x123c KLMD registered as C:\WINDOWS\system32\drivers\78018508.sys
00:59:26.0268 0x123c Deinitialize success