GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-05-16 16:47:13
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\0000006c ST1000DM rev.CC47 931,51GB
Running: ol2rhi6j.exe; Driver: C:\Users\ja\AppData\Local\Temp\uglcyaoc.sys


---- Kernel code sections - GMER 2.1 ----

.text    C:\Windows\system32\drivers\USBPORT.SYS!DllUnload                                                                                                                     fffff8800516cd8c 12 bytes {MOV RAX, 0xfffffa8006d2e2a0; JMP RAX}

---- User code sections - GMER 2.1 ----

.text    C:\Windows\system32\wininit.exe[692] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                            00000000775cef8d 1 byte [62]
.text    C:\Windows\system32\winlogon.exe[760] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                           00000000775cef8d 1 byte [62]
.text    C:\Windows\system32\services.exe[788] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                           00000000775cef8d 1 byte [62]
.text    C:\Windows\System32\svchost.exe[484] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                            00000000775cef8d 1 byte [62]
.text    C:\Windows\system32\svchost.exe[608] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                            00000000775cef8d 1 byte [62]
.text    C:\Windows\system32\svchost.exe[1196] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                           00000000775cef8d 1 byte [62]
.text    C:\Windows\Explorer.EXE[1536] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                                   00000000775cef8d 1 byte [62]
.text    C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[1880] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                           00000000775cef8d 1 byte [62]
.text    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1976] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                              000000007591a2fd 1 byte [62]
.text    C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe[1996] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                    000000007591a2fd 1 byte [62]
.text    D:\Programy Files\Bluetooth\btwdins.exe[2024] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                   00000000775cef8d 1 byte [62]
.text    C:\Windows\system32\taskhost.exe[2288] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                          00000000775cef8d 1 byte [62]
.text    D:\Programy Files\Bluetooth\BTTray.exe[3008] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                    00000000775cef8d 1 byte [62]
.text    C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2228] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112  000000007591a2fd 1 byte [62]
.text    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[1048] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                          000000007591a2fd 1 byte [62]
.text    C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe[2276] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                      000000007591a2fd 1 byte [62]
.text    C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe[2552] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                000000007591a2fd 1 byte [62]
.text    C:\Program Files\AVAST Software\Avast\AvastUI.exe[1964] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter                                                  00000000758f8791 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
.text    C:\Program Files\AVAST Software\Avast\AvastUI.exe[1964] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                         000000007591a2fd 1 byte [62]
.text    C:\Program Files (x86)\Brother\Brmfcmon\BrMfcmon.exe[3172] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                      000000007591a2fd 1 byte [62]
.text    D:\Programy Files\Bluetooth\BtStackServer.exe[3828] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                             00000000775cef8d 1 byte [62]
.text    D:\Programy Files\Bluetooth\BluetoothHeadsetProxy.exe[3732] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                     000000007591a2fd 1 byte [62]
.text    C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4468] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                                   000000007591a2fd 1 byte [62]
.text    C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[2064] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                             000000007591a2fd 1 byte [62]
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[4508] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                    000000007591a2fd 1 byte [62]
.text    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5500] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                            000000007591a2fd 1 byte [62]
.text    C:\Windows\System32\svchost.exe[5612] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                           00000000775cef8d 1 byte [62]
.text    C:\Users\ja\Desktop\ol2rhi6j.exe[4472] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                                          000000007591a2fd 1 byte [62]

---- Kernel IAT/EAT - GMER 2.1 ----

IAT      C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort]                                                                                        [fffff88001079f1c] \SystemRoot\System32\Drivers\sptd.sys [unknown section]
IAT      C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar]                                                                                               [fffff88001079cc0] \SystemRoot\System32\Drivers\sptd.sys [unknown section]
IAT      C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar]                                                                                              [fffff8800107a69c] \SystemRoot\System32\Drivers\sptd.sys [unknown section]
IAT      C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUlong]                                                                                              [fffff8800107aa98] \SystemRoot\System32\Drivers\sptd.sys [unknown section]
IAT      C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort]                                                                                       [fffff8800107a8f4] \SystemRoot\System32\Drivers\sptd.sys [unknown section]

---- Devices - GMER 2.1 ----

Device   \FileSystem\Ntfs \Ntfs                                                                                                                                                fffffa8003c982c0
Device   \Driver\usbehci \Device\USBPDO-1                                                                                                                                      fffffa8006e132c0
Device   \Driver\iaStorA \Device\RaidPort0                                                                                                                                     fffffa8003c942c0
Device   \Driver\cdrom \Device\CdRom0                                                                                                                                          fffffa8006b332c0
Device   \Driver\usbehci \Device\USBFDO-0                                                                                                                                      fffffa8006e132c0
Device   \Driver\iaStorA \Device\0000006c                                                                                                                                      fffffa8003c942c0
Device   \Driver\NetBT \Device\NetBT_Tcpip_{46D30596-D57A-4F36-858E-EB3911063351}                                                                                              fffffa8006dcb2c0
Device   \Driver\iaStorA \Device\0000006d                                                                                                                                      fffffa8003c942c0
Device   \Driver\NetBT \Device\NetBt_Wins_Export                                                                                                                               fffffa8006dcb2c0
Device   \Driver\iaStorA \Device\ScsiPort0                                                                                                                                     fffffa8003c942c0
Device   \Driver\usbehci \Device\USBFDO-2                                                                                                                                      fffffa8006e132c0
Device   \Driver\NetBT \Device\NetBT_Tcpip_{81AD5B6C-36DD-4DAC-8D04-BAD0CF330341}                                                                                              fffffa8006dcb2c0
Device   \Driver\usbehci \Device\USBPDO-0                                                                                                                                      fffffa8006e132c0

---- Trace I/O - GMER 2.1 ----

Trace    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStorF.sys >>UNKNOWN [0xfffffa8003c942c0]<< sptd.sys storport.sys hal.dll iaStorA.sys                                             fffffa8003c942c0
Trace    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006ac2060]                                                                                                       fffffa8006ac2060
Trace    3 CLASSPNP.SYS[fffff880017af43f] -> nt!IofCallDriver -> [0xfffffa8004955c50]                                                                                          fffffa8004955c50
Trace    5 iaStorF.sys[fffff880019e6aa4] -> nt!IofCallDriver -> \Device\0000006c[0xfffffa8004777060]                                                                           fffffa8004777060
Trace    \Driver\iaStorA[0xfffffa800475a770] -> IRP_MJ_CREATE -> 0xfffffa8003c942c0                                                                                            fffffa8003c942c0

---- Threads - GMER 2.1 ----

Thread   C:\Windows\System32\svchost.exe [5612:3560]                                                                                                                           000007fef64d9688
---- Processes - GMER 2.1 ----

Library  C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll (*** suspicious ***) @ C:\Windows\Explorer.EXE [1536] (GG drive overlay/GG Network S.A.)(2013-11-15 21:48:45)           000000005c080000

---- Registry - GMER 2.1 ----

Reg      HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                                                                      
Reg      HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                                                   0x00 0x00 0x00 0x00 ...
Reg      HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                                                   0
Reg      HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                                                0x53 0xE2 0x60 0xFF ...
Reg      HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                                                                   C:\Program Files (x86)\DAEMON Tools Lite\
Reg      HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)                                                                  
Reg      HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                                                       0x00 0x00 0x00 0x00 ...
Reg      HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                                                       0
Reg      HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                                                    0x53 0xE2 0x60 0xFF ...
Reg      HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                                                                       C:\Program Files (x86)\DAEMON Tools Lite\

---- Files - GMER 2.1 ----

File     C:\Users\ja\AppData\Local\Opera Software\Opera Stable\Cache\f_000151                                                                                                  0 bytes

---- EOF - GMER 2.1 ----
