GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-11-15 19:13:56
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000059 SAMSUNG_ rev.1AJ1 465,76GB
Running: louxyidf.exe; Driver: C:\Users\Adam_2\AppData\Local\Temp\kgldqpoc.sys


---- User code sections - GMER 2.1 ----

.text   E:\Program Files (x86)\AMD\OverDrive\AODAssist.exe[1920] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                               0000000075441465 2 bytes [44, 75]
.text   E:\Program Files (x86)\AMD\OverDrive\AODAssist.exe[1920] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                              00000000754414bb 2 bytes [44, 75]
.text   ...                                                                                                                                                            * 2
.text   C:\Program Files (x86)\WebConnect\updateWebConnect.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                           0000000075441465 2 bytes [44, 75]
.text   C:\Program Files (x86)\WebConnect\updateWebConnect.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                          00000000754414bb 2 bytes [44, 75]
.text   ...                                                                                                                                                            * 2
.text   C:\Program Files (x86)\WebConnect\bin\utilWebConnect.exe[2468] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                         0000000075441465 2 bytes [44, 75]
.text   C:\Program Files (x86)\WebConnect\bin\utilWebConnect.exe[2468] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                        00000000754414bb 2 bytes [44, 75]
.text   ...                                                                                                                                                            * 2

---- Kernel IAT/EAT - GMER 2.1 ----

IAT     C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort]                                                                                 [fffff88000edee94] \SystemRoot\System32\Drivers\sptd.sys [.text]
IAT     C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar]                                                                                        [fffff88000edec38] \SystemRoot\System32\Drivers\sptd.sys [.text]
IAT     C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar]                                                                                       [fffff88000edf614] \SystemRoot\System32\Drivers\sptd.sys [.text]
IAT     C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUlong]                                                                                       [fffff88000edfa10] \SystemRoot\System32\Drivers\sptd.sys [.text]
IAT     C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort]                                                                                [fffff88000edf86c] \SystemRoot\System32\Drivers\sptd.sys [.text]

---- Devices - GMER 2.1 ----

Device  \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-3                                                                                                                    fffffa8003b262c0
Device  \Driver\atapi \Device\Ide\IdePort0                                                                                                                             fffffa8003b262c0
Device  \Driver\atapi \Device\Ide\IdePort1                                                                                                                             fffffa8003b262c0
Device  \FileSystem\Ntfs \Ntfs                                                                                                                                         fffffa8003c8a2c0
Device  \Driver\usbehci \Device\USBPDO-5                                                                                                                               fffffa80046482c0
Device  \Driver\usbohci \Device\USBFDO-3                                                                                                                               fffffa80046462c0
Device  \Driver\usbohci \Device\USBPDO-1                                                                                                                               fffffa80046462c0
Device  \Driver\amd_sata \Device\RaidPort0                                                                                                                             fffffa8003b2a2c0
Device  \Driver\NetBT \Device\NetBT_Tcpip_{2FD11226-9B71-46D2-A14A-3C4CDA890B5D}                                                                                       fffffa80044792c0
Device  \Driver\cdrom \Device\CdRom0                                                                                                                                   fffffa80044382c0
Device  \Driver\amd_sata \Device\00000059                                                                                                                              fffffa8003b2a2c0
Device  \Driver\NetBT \Device\NetBT_Tcpip_{01AFC49C-7C34-4F37-BBA1-D66BE87AA0E8}                                                                                       fffffa80044792c0
Device  \Driver\usbohci \Device\USBPDO-6                                                                                                                               fffffa80046462c0
Device  \Driver\usbohci \Device\USBFDO-4                                                                                                                               fffffa80046462c0
Device  \Driver\usbohci \Device\USBFDO-0                                                                                                                               fffffa80046462c0
Device  \Driver\usbehci \Device\USBPDO-2                                                                                                                               fffffa80046482c0
Device  \Driver\usbehci \Device\USBFDO-5                                                                                                                               fffffa80046482c0
Device  \Driver\usbohci \Device\USBPDO-3                                                                                                                               fffffa80046462c0
Device  \Driver\usbohci \Device\USBFDO-1                                                                                                                               fffffa80046462c0
Device  \Driver\NetBT \Device\NetBt_Wins_Export                                                                                                                        fffffa80044792c0
Device  \Driver\usbohci \Device\USBFDO-6                                                                                                                               fffffa80046462c0
Device  \Driver\usbohci \Device\USBPDO-4                                                                                                                               fffffa80046462c0
Device  \Driver\usbehci \Device\USBFDO-2                                                                                                                               fffffa80046482c0
Device  \Driver\atapi \Device\ScsiPort0                                                                                                                                fffffa8003b262c0
Device  \Driver\usbohci \Device\USBPDO-0                                                                                                                               fffffa80046462c0
Device  \Driver\atapi \Device\ScsiPort1                                                                                                                                fffffa8003b262c0
Device  \Driver\amd_sata \Device\ScsiPort2                                                                                                                             fffffa8003b2a2c0

---- Trace I/O - GMER 2.1 ----

Trace   ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa8003c862c0]<< sptd.sys amd_xata.sys >>UNKNOWN [0xfffffa8003b2a2c0]<< storport.sys hal.dll amd_sata.sys   fffffa8003b2a2c0
Trace   1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004374060]                                                                                                fffffa8004374060
Trace   3 CLASSPNP.SYS[fffff880013c843f] -> nt!IofCallDriver -> [0xfffffa80040c9ac0]                                                                                   fffffa80040c9ac0
Trace   \Driver\amd_xata[0xfffffa8003b75370] -> IRP_MJ_CREATE -> 0xfffffa8003c862c0                                                                                    fffffa8003c862c0
Trace   5 amd_xata.sys[fffff8800115dd00] -> nt!IofCallDriver -> \Device\00000059[0xfffffa80040c1060]                                                                   fffffa80040c1060
Trace   \Driver\amd_sata[0xfffffa80040bcd40] -> IRP_MJ_CREATE -> 0xfffffa8003b2a2c0                                                                                    fffffa8003b2a2c0

---- Threads - GMER 2.1 ----

Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4956:4972]                                                                                         00000000779e3e85
Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4956:4976]                                                                                         00000000779e3e85
Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4956:4980]                                                                                         0000000076917587
Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4956:4984]                                                                                         0000000068dd758a
Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4956:4996]                                                                                         00000000779e2e65
Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4956:948]                                                                                          00000000779e3e85

---- Registry - GMER 2.1 ----

Reg     HKLM\SYSTEM\ControlSet001\services\BTHPORT\Parameters\Keys\001167c6dea7 (not active ControlSet)                                                                
Reg     HKLM\SYSTEM\ControlSet001\services\BTHPORT\Parameters\Keys\001167c6dea7@0cdfa43e80e1                                                                           0x2F 0xD8 0xC5 0x4D ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001167c6dea7                                                                                    
Reg     HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001167c6dea7@0cdfa43e80e1                                                                       0x2F 0xD8 0xC5 0x4D ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001167c6dea7@58c38b79a61f                                                                       0x8E 0x18 0xB4 0x62 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001167c6dea7@0c715debe8d6                                                                       0x07 0xEC 0xC5 0x63 ...
Reg     HKLM\SYSTEM\ControlSet003\services\BTHPORT\Parameters\Keys\001167c6dea7 (not active ControlSet)                                                                
Reg     HKLM\SYSTEM\ControlSet003\services\BTHPORT\Parameters\Keys\001167c6dea7@0cdfa43e80e1                                                                           0x2F 0xD8 0xC5 0x4D ...
Reg     HKLM\SYSTEM\ControlSet003\services\BTHPORT\Parameters\Keys\001167c6dea7@58c38b79a61f                                                                           0x8E 0x18 0xB4 0x62 ...
Reg     HKLM\SYSTEM\ControlSet003\services\BTHPORT\Parameters\Keys\001167c6dea7@0c715debe8d6                                                                           0x07 0xEC 0xC5 0x63 ...

---- Files - GMER 2.1 ----

File    C:\Windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{d6fd52a7-bf7b-4575-bf17-6395d261c6fc}                                                          0 bytes
File    C:\Windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\{d6fd52a7-bf7b-4575-bf17-6395d261c6fc}\snapshot.etl                                             278528 bytes

---- EOF - GMER 2.1 ----
