12:38:48.0230 0x06c0 TDSS rootkit removing tool 3.1.0.11 Aug 5 2016 12:13:31 12:38:53.0456 0x06c0 ============================================================ 12:38:53.0456 0x06c0 Current date / time: 2016/09/26 12:38:53.0456 12:38:53.0456 0x06c0 SystemInfo: 12:38:53.0456 0x06c0 12:38:53.0456 0x06c0 OS Version: 6.1.7601 ServicePack: 1.0 12:38:53.0456 0x06c0 Product type: Workstation 12:38:53.0456 0x06c0 ComputerName: WXPP-XXX 12:38:53.0456 0x06c0 UserName: -user 12:38:53.0456 0x06c0 Windows directory: C:\Windows 12:38:53.0456 0x06c0 System windows directory: C:\Windows 12:38:53.0456 0x06c0 Processor architecture: Intel x86 12:38:53.0456 0x06c0 Number of processors: 2 12:38:53.0456 0x06c0 Page size: 0x1000 12:38:53.0456 0x06c0 Boot type: Normal boot 12:38:53.0456 0x06c0 CodeIntegrityOptions = 0x00000000 12:38:53.0456 0x06c0 ============================================================ 12:38:53.0565 0x06c0 KLMD registered as C:\Windows\system32\drivers\09938355.sys 12:38:53.0565 0x06c0 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 7601.23539, osProperties = 0x0 12:38:53.0909 0x06c0 System UUID: {CCC45FFD-CEEC-1F19-B504-3CD14F086C01} 12:38:54.0501 0x06c0 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 ( 298.09 Gb ), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 12:38:54.0501 0x06c0 ============================================================ 12:38:54.0501 0x06c0 \Device\Harddisk0\DR0: 12:38:54.0501 0x06c0 MBR partitions: 12:38:54.0501 0x06c0 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x28F800 12:38:54.0501 0x06c0 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x290000, BlocksNum 0x2519E2B0 12:38:54.0501 0x06c0 ============================================================ 12:38:54.0548 0x06c0 C: <-> \Device\Harddisk0\DR0\Partition2 12:38:54.0548 0x06c0 ============================================================ 12:38:54.0548 0x06c0 Initialize success 12:38:54.0548 0x06c0 ============================================================ 12:39:46.0387 0x0fb0 KLMD registered as C:\Windows\system32\drivers\59965330.sys 12:39:46.0995 0x0fb0 Deinitialize success