19:17:46.0391 3476 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
19:17:46.0968 3476 ============================================================
19:17:46.0968 3476 Current date / time: 2013/01/01 19:17:46.0968
19:17:46.0968 3476 SystemInfo:
19:17:46.0968 3476
19:17:46.0968 3476 OS Version: 6.0.6002 ServicePack: 2.0
19:17:46.0968 3476 Product type: Workstation
19:17:46.0968 3476 ComputerName: KELLYNICOLE
19:17:46.0968 3476 UserName: Kelly Nicole
19:17:46.0968 3476 Windows directory: C:\Windows
19:17:46.0968 3476 System windows directory: C:\Windows
19:17:46.0968 3476 Processor architecture: Intel x86
19:17:46.0968 3476 Number of processors: 2
19:17:46.0968 3476 Page size: 0x1000
19:17:46.0968 3476 Boot type: Normal boot
19:17:46.0968 3476 ============================================================
19:17:50.0004 3476 BG loaded
19:17:52.0511 3476 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
19:17:52.0729 3476 Drive \Device\Harddisk1\DR1 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
19:17:53.0244 3476 ============================================================
19:17:53.0244 3476 \Device\Harddisk0\DR0:
19:17:53.0260 3476 MBR partitions:
19:17:53.0260 3476 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xCEC0FB8
19:17:53.0260 3476 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xCEC0FF7, BlocksNum 0x10D27CA
19:17:53.0260 3476 \Device\Harddisk1\DR1:
19:17:53.0275 3476 MBR partitions:
19:17:53.0275 3476 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xDF93782
19:17:53.0275 3476 ============================================================
19:17:53.0697 3476 C: <-> \Device\Harddisk0\DR0\Partition1
19:17:53.0759 3476 D: <-> \Device\Harddisk1\DR1\Partition1
19:17:53.0806 3476 E: <-> \Device\Harddisk0\DR0\Partition2
19:17:53.0806 3476 ============================================================
19:17:53.0806 3476 Initialize success
19:17:53.0806 3476 ============================================================