14:12:43.0734 0x0eac TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04 14:12:44.0156 0x0eac ============================================================ 14:12:44.0156 0x0eac Current date / time: 2015/07/02 14:12:44.0156 14:12:44.0156 0x0eac SystemInfo: 14:12:44.0156 0x0eac 14:12:44.0156 0x0eac OS Version: 6.1.7600 ServicePack: 0.0 14:12:44.0156 0x0eac Product type: Workstation 14:12:44.0156 0x0eac ComputerName: HYPER-KOMPUTER 14:12:44.0156 0x0eac UserName: HYPER 14:12:44.0156 0x0eac Windows directory: C:\Windows 14:12:44.0156 0x0eac System windows directory: C:\Windows 14:12:44.0156 0x0eac Processor architecture: Intel x86 14:12:44.0156 0x0eac Number of processors: 4 14:12:44.0156 0x0eac Page size: 0x1000 14:12:44.0156 0x0eac Boot type: Normal boot 14:12:44.0156 0x0eac ============================================================ 14:12:44.0156 0x0eac BG loaded 14:12:44.0843 0x0eac System UUID: {98D24377-807A-E6E9-1DF8-6A806BB8150F} 14:12:47.0218 0x0eac Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 14:12:47.0265 0x0eac ============================================================ 14:12:47.0265 0x0eac \Device\Harddisk0\DR0: 14:12:47.0375 0x0eac MBR partitions: 14:12:47.0375 0x0eac \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 14:12:47.0375 0x0eac \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xC31D800 14:12:47.0375 0x0eac \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0xC350000, BlocksNum 0x124F8000 14:12:47.0375 0x0eac \Device\Harddisk0\DR0\Partition4: MBR, Type 0x7, StartLBA 0x1E848000, BlocksNum 0x1BB3D800 14:12:47.0375 0x0eac ============================================================ 14:12:48.0046 0x0eac C: <-> \Device\Harddisk0\DR0\Partition2 14:12:48.0921 0x0eac D: <-> \Device\Harddisk0\DR0\Partition3 14:12:49.0546 0x0eac E: <-> \Device\Harddisk0\DR0\Partition4 14:12:49.0546 0x0eac ============================================================ 14:12:49.0546 0x0eac Initialize success 14:12:49.0546 0x0eac ============================================================ 14:13:02.0640 0x0e84 Deinitialize success