19:46:20.0983 0x0e6c TDSS rootkit removing tool 3.0.0.19 Nov 18 2013 09:27:50 19:46:24.0009 0x0e6c ============================================================ 19:46:24.0009 0x0e6c Current date / time: 2013/12/09 19:46:24.0009 19:46:24.0009 0x0e6c SystemInfo: 19:46:24.0009 0x0e6c 19:46:24.0009 0x0e6c OS Version: 6.1.7601 ServicePack: 1.0 19:46:24.0009 0x0e6c Product type: Workstation 19:46:24.0009 0x0e6c ComputerName: SPETSNAZ 19:46:24.0009 0x0e6c UserName: Sino 19:46:24.0009 0x0e6c Windows directory: C:\Windows 19:46:24.0009 0x0e6c System windows directory: C:\Windows 19:46:24.0009 0x0e6c Processor architecture: Intel x86 19:46:24.0009 0x0e6c Number of processors: 2 19:46:24.0009 0x0e6c Page size: 0x1000 19:46:24.0009 0x0e6c Boot type: Normal boot 19:46:24.0009 0x0e6c ============================================================ 19:46:28.0730 0x0e6c KLMD registered as C:\Windows\system32\drivers\83148012.sys 19:46:28.0975 0x0e6c System UUID: {1B70738E-B739-45E0-3AF9-FE0911703A0D} 19:46:29.0609 0x0e6c Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 19:46:29.0610 0x0e6c ============================================================ 19:46:29.0610 0x0e6c \Device\Harddisk0\DR0: 19:46:29.0611 0x0e6c MBR partitions: 19:46:29.0611 0x0e6c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A380D41 19:46:29.0611 0x0e6c ============================================================ 19:46:29.0627 0x0e6c C: <-> \Device\Harddisk0\DR0\Partition1 19:46:29.0627 0x0e6c ============================================================ 19:46:29.0627 0x0e6c Initialize success 19:46:29.0627 0x0e6c ============================================================ 19:48:15.0796 0x0fc4 KLMD registered as C:\Windows\system32\drivers\16820966.sys 19:48:17.0906 0x0fc4 Deinitialize success