GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-06-01 20:00:58
Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 SAMSUNG_SP1604N rev.TM100-24
Running: 5jtwyrwx.exe; Driver: C:\DOCUME~1\Fil\USTAWI~1\Temp\agwoqfob.sys


---- System - GMER 1.0.15 ----

SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                 ZwAllocateVirtualMemory [0xBAD71CB2]
SSDT            \??\C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys                                                                ZwClose [0xB897C9AC]
SSDT            \??\C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys                                                                ZwCreateKey [0xB897C95E]
SSDT            \??\C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys                                                                ZwDeleteKey [0xB897CA12]
SSDT            \??\C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys                                                                ZwDeleteValueKey [0xB897CA3C]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                 ZwDuplicateObject [0xBAD7A348]
SSDT            \??\C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys                                                                ZwEnumerateKey [0xB897CE6A]
SSDT            \??\C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys                                                                ZwEnumerateValueKey [0xB897CEE0]
SSDT            \??\C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys                                                                ZwFlushKey [0xB897C9E8]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                 ZwFreeVirtualMemory [0xBAD71D62]
SSDT            \??\C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys                                                                ZwLoadKey [0xB897CF58]
SSDT            \??\C:\Program Files\Softwin\BitDefender10\bdfsdrv.sys                                                                ZwOpenFile [0xB8744F1F]
SSDT            \??\C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys                                                                ZwOpenKey [0xB897C91C]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                 ZwOpenProcess [0xBAD7A284]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                 ZwOpenThread [0xBAD7A2EA]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                 ZwProtectVirtualMemory [0xBAD71DFA]
SSDT            \??\C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys                                                                ZwQueryKey [0xB897CEA6]
SSDT            \??\C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys                                                                ZwQueryValueKey [0xB897CF1C]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                 ZwRenameKey [0xBAD7AE48]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                 ZwRestoreKey [0xBAD7A952]
SSDT            \??\C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys                                                                ZwSetValueKey [0xB897CAE9]
SSDT            \??\C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys                                                                ZwUnloadKey [0xB897CF86]

---- Kernel code sections - GMER 1.0.15 ----

.text           ntoskrnl.exe!_abnormal_termination + 188                                                                              804E27E4 4 Bytes  [E8, C9, 97, B8]
.text           ntoskrnl.exe!_abnormal_termination + 24C                                                                              804E28A8 4 Bytes  JMP 92BAD7A2 
.text           ntoskrnl.exe!_abnormal_termination + 428                                                                              804E2A84 4 Bytes  [E9, CA, 97, B8]
init            C:\WINDOWS\system32\drivers\ALCXSENS.SYS                                                                              entry point in "init" section [0xF6F7C7F0]

---- User code sections - GMER 1.0.15 ----

.text           C:\Program Files\Softwin\BitDefender10\vsserv.exe[200] ntdll.dll!RtlDosSearchPath_U + 1D1                             7C9171AA 1 Byte  [62]
.text           C:\Program Files\Softwin\BitDefender10\vsserv.exe[200] kernel32.dll!GetBinaryTypeW + 80                               7C868C2C 1 Byte  [62]
.text           C:\Program Files\Softwin\BitDefender10\bdagent.exe[460] ntdll.dll!RtlDosSearchPath_U + 1D1                            7C9171AA 1 Byte  [62]
.text           C:\Program Files\Softwin\BitDefender10\bdagent.exe[460] kernel32.dll!LoadLibraryA                                     7C801D7B 5 Bytes  JMP 00923090 C:\WINDOWS\system32\sockspy.dll
.text           C:\Program Files\Softwin\BitDefender10\bdagent.exe[460] kernel32.dll!GetBinaryTypeW + 80                              7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\system32\ctfmon.exe[468] ntdll.dll!RtlDosSearchPath_U + 1D1                                                7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\system32\ctfmon.exe[468] kernel32.dll!LoadLibraryA                                                         7C801D7B 5 Bytes  JMP 10003090 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\ctfmon.exe[468] kernel32.dll!GetBinaryTypeW + 80                                                  7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\System32\smss.exe[556] ntdll.dll!RtlDosSearchPath_U + 1D1                                                  7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\system32\csrss.exe[612] ntdll.dll!RtlDosSearchPath_U + 1D1                                                 7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\system32\csrss.exe[612] KERNEL32.dll!GetBinaryTypeW + 80                                                   7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!RtlDosSearchPath_U + 1D1                                              7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!LoadLibraryA                                                       7C801D7B 5 Bytes  JMP 10003090 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!GetBinaryTypeW + 80                                                7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\system32\winlogon.exe[640] WS2_32.dll!sendto                                                               71A52F51 5 Bytes  JMP 10002D10 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\winlogon.exe[640] WS2_32.dll!recvfrom                                                             71A52FF7 5 Bytes  JMP 10002CA0 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\winlogon.exe[640] WS2_32.dll!closesocket                                                          71A53E2B 5 Bytes  JMP 10003060 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\winlogon.exe[640] WS2_32.dll!bind                                                                 71A54480 5 Bytes  JMP 10003020 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\winlogon.exe[640] WS2_32.dll!connect                                                              71A54A07 5 Bytes  JMP 10002DA0 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\winlogon.exe[640] WS2_32.dll!send                                                                 71A54C27 5 Bytes  JMP 10002AA0 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\winlogon.exe[640] WS2_32.dll!gethostbyname                                                        71A55355 5 Bytes  JMP 10002D70 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\winlogon.exe[640] WS2_32.dll!listen                                                               71A58CD3 5 Bytes  JMP 10002A60 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\winlogon.exe[640] WS2_32.dll!accept                                                               71A61040 5 Bytes  JMP 10002F30 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!RtlDosSearchPath_U + 1D1                                              7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!LoadLibraryA                                                       7C801D7B 5 Bytes  JMP 10003090 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!GetBinaryTypeW + 80                                                7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!RtlDosSearchPath_U + 1D1                                                 7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!LoadLibraryA                                                          7C801D7B 5 Bytes  JMP 10003090 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!GetBinaryTypeW + 80                                                   7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\system32\lsass.exe[696] WS2_32.dll!sendto                                                                  71A52F51 5 Bytes  JMP 10002D10 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\lsass.exe[696] WS2_32.dll!recvfrom                                                                71A52FF7 5 Bytes  JMP 10002CA0 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\lsass.exe[696] WS2_32.dll!closesocket                                                             71A53E2B 5 Bytes  JMP 10003060 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\lsass.exe[696] WS2_32.dll!bind                                                                    71A54480 5 Bytes  JMP 10003020 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\lsass.exe[696] WS2_32.dll!connect                                                                 71A54A07 5 Bytes  JMP 10002DA0 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\lsass.exe[696] WS2_32.dll!send                                                                    71A54C27 5 Bytes  JMP 10002AA0 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\lsass.exe[696] WS2_32.dll!gethostbyname                                                           71A55355 5 Bytes  JMP 10002D70 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\lsass.exe[696] WS2_32.dll!listen                                                                  71A58CD3 5 Bytes  JMP 10002A60 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\lsass.exe[696] WS2_32.dll!accept                                                                  71A61040 5 Bytes  JMP 10002F30 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\svchost.exe[880] ntdll.dll!RtlDosSearchPath_U + 1D1                                               7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[880] kernel32.dll!GetBinaryTypeW + 80                                                 7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[948] ntdll.dll!RtlDosSearchPath_U + 1D1                                               7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!GetBinaryTypeW + 80                                                 7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1008] ntdll.dll!RtlDosSearchPath_U + 1D1                                              7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!GetBinaryTypeW + 80                                                7C868C2C 1 Byte  [62]
.text           C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe[1040] ntdll.dll!RtlDosSearchPath_U + 1D1  7C9171AA 1 Byte  [62]
.text           C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe[1040] kernel32.dll!GetBinaryTypeW + 80    7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\System32\svchost.exe[1208] ntdll.dll!RtlDosSearchPath_U + 1D1                                              7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\System32\svchost.exe[1208] kernel32.dll!GetBinaryTypeW + 80                                                7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1256] ntdll.dll!RtlDosSearchPath_U + 1D1                                              7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!GetBinaryTypeW + 80                                                7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!RtlDosSearchPath_U + 1D1                                              7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1420] kernel32.dll!GetBinaryTypeW + 80                                                7C868C2C 1 Byte  [62]
.text           C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe[1472] ntdll.dll!RtlDosSearchPath_U + 1D1       7C9171AA 1 Byte  [62]
.text           C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe[1472] kernel32.dll!LoadLibraryA                7C801D7B 5 Bytes  JMP 006A3090 C:\WINDOWS\system32\sockspy.dll
.text           C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe[1472] kernel32.dll!GetBinaryTypeW + 80         7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1564] ntdll.dll!RtlDosSearchPath_U + 1D1                                              7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!GetBinaryTypeW + 80                                                7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\System32\alg.exe[1628] ntdll.dll!RtlDosSearchPath_U + 1D1                                                  7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\System32\alg.exe[1628] kernel32.dll!LoadLibraryA                                                           7C801D7B 5 Bytes  JMP 10003090 C:\WINDOWS\System32\sockspy.dll
.text           C:\WINDOWS\System32\alg.exe[1628] kernel32.dll!GetBinaryTypeW + 80                                                    7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\System32\alg.exe[1628] WS2_32.dll!sendto                                                                   71A52F51 5 Bytes  JMP 10002D10 C:\WINDOWS\System32\sockspy.dll
.text           C:\WINDOWS\System32\alg.exe[1628] WS2_32.dll!recvfrom                                                                 71A52FF7 5 Bytes  JMP 10002CA0 C:\WINDOWS\System32\sockspy.dll
.text           C:\WINDOWS\System32\alg.exe[1628] WS2_32.dll!closesocket                                                              71A53E2B 5 Bytes  JMP 10003060 C:\WINDOWS\System32\sockspy.dll
.text           C:\WINDOWS\System32\alg.exe[1628] WS2_32.dll!bind                                                                     71A54480 5 Bytes  JMP 10003020 C:\WINDOWS\System32\sockspy.dll
.text           C:\WINDOWS\System32\alg.exe[1628] WS2_32.dll!connect                                                                  71A54A07 5 Bytes  JMP 10002DA0 C:\WINDOWS\System32\sockspy.dll
.text           C:\WINDOWS\System32\alg.exe[1628] WS2_32.dll!send                                                                     71A54C27 5 Bytes  JMP 10002AA0 C:\WINDOWS\System32\sockspy.dll
.text           C:\WINDOWS\System32\alg.exe[1628] WS2_32.dll!gethostbyname                                                            71A55355 5 Bytes  JMP 10002D70 C:\WINDOWS\System32\sockspy.dll
.text           C:\WINDOWS\System32\alg.exe[1628] WS2_32.dll!listen                                                                   71A58CD3 5 Bytes  JMP 10002A60 C:\WINDOWS\System32\sockspy.dll
.text           C:\WINDOWS\System32\alg.exe[1628] WS2_32.dll!accept                                                                   71A61040 5 Bytes  JMP 10002F30 C:\WINDOWS\System32\sockspy.dll
.text           C:\WINDOWS\system32\EXPLORER.EXE[1820] ntdll.dll!RtlDosSearchPath_U + 1D1                                             7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\system32\EXPLORER.EXE[1820] kernel32.dll!LoadLibraryA                                                      7C801D7B 5 Bytes  JMP 10003090 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\EXPLORER.EXE[1820] kernel32.dll!GetBinaryTypeW + 80                                               7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\Explorer.EXE[1836] ntdll.dll!RtlDosSearchPath_U + 1D1                                                      7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\Explorer.EXE[1836] kernel32.dll!LoadLibraryA                                                               7C801D7B 5 Bytes  JMP 10003090 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\Explorer.EXE[1836] kernel32.dll!GetBinaryTypeW + 80                                                        7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\Explorer.EXE[1836] WS2_32.dll!sendto                                                                       71A52F51 5 Bytes  JMP 10002D10 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\Explorer.EXE[1836] WS2_32.dll!recvfrom                                                                     71A52FF7 5 Bytes  JMP 10002CA0 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\Explorer.EXE[1836] WS2_32.dll!closesocket                                                                  71A53E2B 5 Bytes  JMP 10003060 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\Explorer.EXE[1836] WS2_32.dll!bind                                                                         71A54480 5 Bytes  JMP 10003020 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\Explorer.EXE[1836] WS2_32.dll!connect                                                                      71A54A07 5 Bytes  JMP 10002DA0 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\Explorer.EXE[1836] WS2_32.dll!send                                                                         71A54C27 5 Bytes  JMP 10002AA0 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\Explorer.EXE[1836] WS2_32.dll!gethostbyname                                                                71A55355 5 Bytes  JMP 10002D70 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\Explorer.EXE[1836] WS2_32.dll!listen                                                                       71A58CD3 5 Bytes  JMP 10002A60 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\Explorer.EXE[1836] WS2_32.dll!accept                                                                       71A61040 5 Bytes  JMP 10002F30 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\spoolsv.exe[1956] ntdll.dll!RtlDosSearchPath_U + 1D1                                              7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\system32\spoolsv.exe[1956] kernel32.dll!GetBinaryTypeW + 80                                                7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\system32\wuauclt.exe[2708] ntdll.dll!RtlDosSearchPath_U + 1D1                                              7C9171AA 1 Byte  [62]
.text           C:\WINDOWS\system32\wuauclt.exe[2708] kernel32.dll!LoadLibraryA                                                       7C801D7B 5 Bytes  JMP 10003090 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\wuauclt.exe[2708] kernel32.dll!GetBinaryTypeW + 80                                                7C868C2C 1 Byte  [62]
.text           C:\WINDOWS\system32\wuauclt.exe[2708] WS2_32.dll!sendto                                                               71A52F51 5 Bytes  JMP 10002D10 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\wuauclt.exe[2708] WS2_32.dll!recvfrom                                                             71A52FF7 5 Bytes  JMP 10002CA0 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\wuauclt.exe[2708] WS2_32.dll!closesocket                                                          71A53E2B 5 Bytes  JMP 10003060 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\wuauclt.exe[2708] WS2_32.dll!bind                                                                 71A54480 5 Bytes  JMP 10003020 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\wuauclt.exe[2708] WS2_32.dll!connect                                                              71A54A07 5 Bytes  JMP 10002DA0 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\wuauclt.exe[2708] WS2_32.dll!send                                                                 71A54C27 5 Bytes  JMP 10002AA0 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\wuauclt.exe[2708] WS2_32.dll!gethostbyname                                                        71A55355 5 Bytes  JMP 10002D70 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\wuauclt.exe[2708] WS2_32.dll!listen                                                               71A58CD3 5 Bytes  JMP 10002A60 C:\WINDOWS\system32\sockspy.dll
.text           C:\WINDOWS\system32\wuauclt.exe[2708] WS2_32.dll!accept                                                               71A61040 5 Bytes  JMP 10002F30 C:\WINDOWS\system32\sockspy.dll
.text           C:\Documents and Settings\Fil\Pulpit\5jtwyrwx.exe[3288] ntdll.dll!RtlDosSearchPath_U + 1D1                            7C9171AA 1 Byte  [62]
.text           C:\Documents and Settings\Fil\Pulpit\5jtwyrwx.exe[3288] kernel32.dll!LoadLibraryA                                     7C801D7B 5 Bytes  JMP 10003090 C:\WINDOWS\system32\sockspy.dll
.text           C:\Documents and Settings\Fil\Pulpit\5jtwyrwx.exe[3288] kernel32.dll!GetBinaryTypeW + 80                              7C868C2C 1 Byte  [62]

---- Devices - GMER 1.0.15 ----

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                                                bdfsdrv.sys
AttachedDevice  \Driver\Tcpip \Device\Ip                                                                                              aswFW.SYS (avast! Filtering TDI driver/AVAST Software)
AttachedDevice  \Driver\Tcpip \Device\Ip                                                                                              aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                                             aswFW.SYS (avast! Filtering TDI driver/AVAST Software)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                                             aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice  \Driver\Tcpip \Device\Udp                                                                                             aswFW.SYS (avast! Filtering TDI driver/AVAST Software)
AttachedDevice  \Driver\Tcpip \Device\Udp                                                                                             aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                                           aswFW.SYS (avast! Filtering TDI driver/AVAST Software)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                                           aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

---- Files - GMER 1.0.15 ----

File            C:\WINDOWS\Temp\win13AE.tmp                                                                                           0 bytes
File            C:\WINDOWS\Temp\win13A7.tmp                                                                                           0 bytes
File            C:\WINDOWS\Temp\win13A8.tmp                                                                                           0 bytes
File            C:\WINDOWS\Temp\win13A9.tmp                                                                                           0 bytes
File            C:\WINDOWS\Temp\win13AA.tmp                                                                                           0 bytes
File            C:\WINDOWS\Temp\win13AB.tmp                                                                                           0 bytes

---- EOF - GMER 1.0.15 ----
