GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2017-05-17 21:31:33 Windows 6.1.7601 Service Pack 1 x64 Running: rmq2tm48.exe ---- Registry - GMER 2.2 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\Instup_14950457558102294@SetupOperations ??? ?????????????????????????????????????????????????????o???????d??h ????\?? ??????????????\??\C:\Program Files\AVAST Software\SZBrowser???? X?? ???y???????t??\??\C:\ProgramData\AVAST Software\SZBrowser?????????? ??????????????\??\C:\Users????? ????????????? ????? ??????????P?4??????F??????????????4r??? ? ? ? ? ? ? ? ??????????????????????????????????????????P?? ???F????h-85??\SystemRoot\system32\drivers\aswStm.sys?ys?ine??????? ?????????e????aswStm???????? ?? ??????p???NDIS????????? ???:??????????tcpip??.28????F?? ??????????????avast! StreamFilter Callout Driver?-0F??? ??????? ????? ???????????????????? ???????81????? ????? ??????? ??????????? ???????? ????????f?9???????????8???????n??? ? ? ???????????c???????n??????? ???5??????????????6C????? ????? ????????????? ????? ??????????P?5??????v??????????? ??????? ? ? ? ? ? ?????????????????????????????4??????EE??????? ???-??????????aswVmm?VM Monitor?????$?? ???M?????n?T????? ????? ??????????????avast! VM Monitor???????? ??????????Extended Base???? ??????? ????? Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\88532edaa20e Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\88532edaa20e@4325a20db1a5 0xED 0x3F 0x00 0xDE ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\88532edaa20e@5055276c16ab 0x33 0x67 0x1A 0x4E ... Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters\Instup_14950457558102294@SetupOperations ?????????&??Sftredir?t???????&??????????????????????%systemroot%\system32\scext.dll???????8??'???????????????????????????????e????H??-??????????????Microsoft?????`??'????????????`??'?????????? NOEXECUTE=OPTIN NUMPROC=4? SAFEBOOT:MINIMAL SOS BOOTLOG NOGUIBOOT BOOTLOGO????????????????????????????????????????????????????????????????????????????????????????????????????????????????? ??????????????????????????H???????????????????????????????????RA??????