16:20:59.0856 9164 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 16:21:00.0113 9164 ============================================================ 16:21:00.0113 9164 Current date / time: 2017/10/09 16:21:00.0113 16:21:00.0113 9164 SystemInfo: 16:21:00.0113 9164 16:21:00.0122 9164 OS Version: 6.2.9200 ServicePack: 0.0 16:21:00.0122 9164 Product type: Workstation 16:21:00.0122 9164 ComputerName: DESKTOP-GC77QGH 16:21:00.0122 9164 UserName: Jakub K 16:21:00.0122 9164 Windows directory: C:\WINDOWS 16:21:00.0122 9164 System windows directory: C:\WINDOWS 16:21:00.0122 9164 Running under WOW64 16:21:00.0123 9164 Processor architecture: Intel x64 16:21:00.0123 9164 Number of processors: 4 16:21:00.0123 9164 Page size: 0x1000 16:21:00.0123 9164 Boot type: Normal boot 16:21:00.0123 9164 ============================================================ 16:21:00.0989 9164 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 16:21:01.0012 9164 Drive \Device\Harddisk1\DR1 - Size: 0x7470AFDE00 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xFC59, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040 16:21:01.0027 9164 Drive \Device\Harddisk2\DR2 - Size: 0x3A38A25E00 (232.88 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 16:21:02.0309 9164 ============================================================ 16:21:02.0309 9164 \Device\Harddisk0\DR0: 16:21:02.0323 9164 MBR partitions: 16:21:02.0323 9164 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xC651C9E 16:21:02.0323 9164 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xC800800, BlocksNum 0x67F05800 16:21:02.0323 9164 \Device\Harddisk1\DR1: 16:21:02.0323 9164 MBR partitions: 16:21:02.0323 9164 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3A384000 16:21:02.0323 9164 \Device\Harddisk2\DR2: 16:21:02.0326 9164 MBR partitions: 16:21:02.0326 9164 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x7E69800 16:21:02.0326 9164 \Device\Harddisk2\DR2\Partition2: MBR, Type 0x7, StartLBA 0x7E6A000, BlocksNum 0x1535A000 16:21:02.0326 9164 ============================================================ 16:21:02.0390 9164 C: <-> \Device\Harddisk0\DR0\Partition1 16:21:02.0502 9164 D: <-> \Device\Harddisk0\DR0\Partition2 16:21:02.0532 9164 E: <-> \Device\Harddisk1\DR1\Partition1 16:21:02.0568 9164 F: <-> \Device\Harddisk2\DR2\Partition2 16:21:02.0568 9164 ============================================================ 16:21:02.0568 9164 Initialize success 16:21:02.0568 9164 ============================================================ 16:21:04.0582 9924 Deinitialize success