There is a rootkit malware on my Vista computer called Alureo and it's being detected on this particular partition:
MBR: \PHYSICALDRIVE0\Partition 3
I only recall attracting this virus a couple of weeks ago prior to downloading MSE and Avast while browsing. I have recently uninstalled both programs. No program that I've used so far has been successful in removing Alureo.
Per the request to fulfill the 5-step preliminary removal instructions I have the Malwarebytes log file, and the Gmer log file, but whenever I try to run the DDS file it just seems to run a scan but after 20 minutes there are still no log files popping up and if I try to interrupt my computer stalls and I have to force a reboot. Any help would be appreciated:
Malewarebytes log file
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org
Database version: v2012.03.20.07
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Dawon :: DAWON-PC [administrator]
3/20/2012 1:21:38 PM
mbam-log-2012-03-20 (13-21-38).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 267369
Time elapsed: 8 minute(s), 16 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
First half of Gmer log file
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-03-20 15:23:38
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\0000005f WDC_WD32 rev.01.0
Running: tykegnrd.exe; Driver: C:\Users\Dawon\AppData\Local\Temp\pwloapog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x91027DF8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0x9274FA5A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAssignProcessToJobObject [0x9102885E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x9102D2E4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x9102D330]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x9102D422]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x9102D252]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x9102D374]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x9102D29A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x9102D3DC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x91027E44]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0x9274FB34]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x91027AD6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x91027E90]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x9102AD1C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x91028B02]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x9102D30E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x9102D352]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x9102D446]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x9102D278]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x9102D3AE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x9102D2C2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x9102D400]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0x9274FCA0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x910289CE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x91027EDC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x91027F28]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x91027B46]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x91027CEA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x91027C92]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x91027D5A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwTerminateProcess [0x9274FD60]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x91027F74]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwWriteVirtualMemory [0x9274FBE0]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x92765D92]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 10D 81CC1890 4 Bytes [F8, 7D, 02, 91] {CLC ; JGE 0x5; XCHG ECX, EAX}
.text ntkrnlpa.exe!KeSetEvent + 131 81CC18B4 4 Bytes [5A, FA, 74, 92] {POP EDX; CLI ; JZ 0xffffffffffffff96}
.text ntkrnlpa.exe!KeSetEvent + 191 81CC1914 4 Bytes JMP 8454779A
.text ntkrnlpa.exe!KeSetEvent + 1D1 81CC1954 8 Bytes [E4, D2, 02, 91, 30, D3, 02, ...] {IN AL, 0xd2; ADD DL, [ECX-0x6efd2cd0]}
.text ntkrnlpa.exe!KeSetEvent + 1DD 81CC1960 4 Bytes [22, D4, 02, 91]
.text ...
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 81DEC62F 5 Bytes JMP 92762C8C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject 81E45543 5 Bytes JMP 9276474C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 110 81E4EE68 4 Bytes CALL 910291B5 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 121 81E52ADC 4 Bytes CALL 910291CB \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 81EA6DCA 7 Bytes JMP 92765D96 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[628] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[628] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[628] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\csrss.exe[636] KERNEL32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000601F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000603FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] USER32.dll!SetWindowsHookExA 76856322 5 Bytes JMP 00070600
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] USER32.dll!SetWindowsHookExW 768587AD 5 Bytes JMP 00070804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] USER32.dll!UnhookWindowsHookEx 768598DB 5 Bytes JMP 00070A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] USER32.dll!SetWinEventHook 76859F3A 5 Bytes JMP 000701F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] USER32.dll!UnhookWinEvent 7685C06F 5 Bytes JMP 000703FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000803FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00080600
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00081014
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00080804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00080A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00080C0C
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00080E10
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000801F8
.text C:\Windows\system32\wininit.exe[688] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[688] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[688] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000503FC
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00050600
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00051014
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00050804
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00050A08
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00050C0C
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00050E10
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000501F8
.text C:\Windows\system32\wininit.exe[688] USER32.dll!SetWindowsHookExA 76856322 5 Bytes JMP 00060600
.text C:\Windows\system32\wininit.exe[688] USER32.dll!SetWindowsHookExW 768587AD 5 Bytes JMP 00060804
.text C:\Windows\system32\wininit.exe[688] USER32.dll!UnhookWindowsHookEx 768598DB 5 Bytes JMP 00060A08
.text C:\Windows\system32\wininit.exe[688] USER32.dll!SetWinEventHook 76859F3A 5 Bytes JMP 000601F8
.text C:\Windows\system32\wininit.exe[688] USER32.dll!UnhookWinEvent 7685C06F 5 Bytes JMP 000603FC
.text C:\Windows\system32\csrss.exe[696] KERNEL32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\services.exe[732] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\system32\services.exe[732] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\system32\services.exe[732] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\services.exe[732] USER32.dll!SetWindowsHookExA 76856322 5 Bytes JMP 00080600
.text C:\Windows\system32\services.exe[732] USER32.dll!SetWindowsHookExW 768587AD 5 Bytes JMP 00080804
.text C:\Windows\system32\services.exe[732] USER32.dll!UnhookWindowsHookEx 768598DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\services.exe[732] USER32.dll!SetWinEventHook 76859F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\services.exe[732] USER32.dll!UnhookWinEvent 7685C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\lsass.exe[748] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\system32\lsass.exe[748] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\system32\lsass.exe[748] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000B03FC
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 000B0600
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 000B1014
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 000B0804
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 000B0A08
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 000B0C0C
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 000B0E10
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000B01F8
.text C:\Windows\system32\lsass.exe[748] USER32.dll!SetWindowsHookExA 76856322 5 Bytes JMP 000C0600
.text C:\Windows\system32\lsass.exe[748] USER32.dll!SetWindowsHookExW 768587AD 5 Bytes JMP 000C0804
.text C:\Windows\system32\lsass.exe[748] USER32.dll!UnhookWindowsHookEx 768598DB 5 Bytes JMP 000C0A08
.text C:\Windows\system32\lsass.exe[748] USER32.dll!SetWinEventHook 76859F3A 5 Bytes JMP 000C01F8
.text C:\Windows\system32\lsass.exe[748] USER32.dll!UnhookWinEvent 7685C06F 5 Bytes JMP 000C03FC
.text C:\Windows\system32\lsm.exe[760] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\system32\lsm.exe[760] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\system32\lsm.exe[760] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000701F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 001501F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 001503FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 001703FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00170600
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00171014
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00170804
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00170A08
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00170C0C
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00170E10
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 001701F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] USER32.dll!SetWindowsHookExA 76856322 5 Bytes JMP 00180600
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] USER32.dll!SetWindowsHookExW 768587AD 5 Bytes JMP 00180804
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] USER32.dll!UnhookWindowsHookEx 768598DB 5 Bytes JMP 00180A08
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] USER32.dll!SetWinEventHook 76859F3A 5 Bytes JMP 001801F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] USER32.dll!UnhookWinEvent 7685C06F 5 Bytes JMP 001803FC
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 001401F8
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 001403FC
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 001603FC
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00160600
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00161014
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00160804
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00160A08
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00160C0C
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00160E10
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 001601F8
.text C:\Windows\system32\winlogon.exe[836] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[836] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[836] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000603FC
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00060600
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00061014
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00060804
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00060A08
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00060C0C
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00060E10
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000601F8
.text C:\Windows\system32\winlogon.exe[836] USER32.dll!SetWindowsHookExA 76856322 5 Bytes JMP 00070600
.text C:\Windows\system32\winlogon.exe[836] USER32.dll!SetWindowsHookExW 768587AD 5 Bytes JMP 00070804
.text C:\Windows\system32\winlogon.exe[836] USER32.dll!UnhookWindowsHookEx 768598DB 5 Bytes JMP 00070A08
.text C:\Windows\system32\winlogon.exe[836] USER32.dll!SetWinEventHook 76859F3A 5 Bytes JMP 000701F8
.text C:\Windows\system32\winlogon.exe[836] USER32.dll!UnhookWinEvent 7685C06F 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[900] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[900] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[900] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000901F8
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000903FC
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000B03FC
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 000B0600
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 000B1014
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 000B0804
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 000B0A08
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 000B0C0C
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 000B0E10
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000B01F8
.text C:\Windows\system32\svchost.exe[948] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[948] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1020] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1020] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1020] USER32.dll!SetWindowsHookExA 76856322 5 Bytes JMP 00100600
.text C:\Windows\system32\svchost.exe[1020] USER32.dll!SetWindowsHookExW 768587AD 5 Bytes JMP 00100804
.text C:\Windows\system32\svchost.exe[1020] USER32.dll!UnhookWindowsHookEx 768598DB 5 Bytes JMP 00100A08
.text C:\Windows\system32\svchost.exe[1020] USER32.dll!SetWinEventHook 76859F3A 5 Bytes JMP 001001F8
.text C:\Windows\system32\svchost.exe[1020] USER32.dll!UnhookWinEvent 7685C06F 5 Bytes JMP 001003FC
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1080] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfig2A
MBR: \PHYSICALDRIVE0\Partition 3
I only recall attracting this virus a couple of weeks ago prior to downloading MSE and Avast while browsing. I have recently uninstalled both programs. No program that I've used so far has been successful in removing Alureo.
Per the request to fulfill the 5-step preliminary removal instructions I have the Malwarebytes log file, and the Gmer log file, but whenever I try to run the DDS file it just seems to run a scan but after 20 minutes there are still no log files popping up and if I try to interrupt my computer stalls and I have to force a reboot. Any help would be appreciated:
Malewarebytes log file
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org
Database version: v2012.03.20.07
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Dawon :: DAWON-PC [administrator]
3/20/2012 1:21:38 PM
mbam-log-2012-03-20 (13-21-38).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 267369
Time elapsed: 8 minute(s), 16 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
First half of Gmer log file
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-03-20 15:23:38
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\0000005f WDC_WD32 rev.01.0
Running: tykegnrd.exe; Driver: C:\Users\Dawon\AppData\Local\Temp\pwloapog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x91027DF8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0x9274FA5A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAssignProcessToJobObject [0x9102885E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x9102D2E4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x9102D330]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x9102D422]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x9102D252]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x9102D374]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x9102D29A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x9102D3DC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x91027E44]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0x9274FB34]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x91027AD6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x91027E90]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x9102AD1C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x91028B02]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x9102D30E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x9102D352]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x9102D446]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x9102D278]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x9102D3AE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x9102D2C2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x9102D400]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0x9274FCA0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x910289CE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x91027EDC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x91027F28]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x91027B46]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x91027CEA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x91027C92]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x91027D5A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwTerminateProcess [0x9274FD60]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x91027F74]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwWriteVirtualMemory [0x9274FBE0]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x92765D92]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 10D 81CC1890 4 Bytes [F8, 7D, 02, 91] {CLC ; JGE 0x5; XCHG ECX, EAX}
.text ntkrnlpa.exe!KeSetEvent + 131 81CC18B4 4 Bytes [5A, FA, 74, 92] {POP EDX; CLI ; JZ 0xffffffffffffff96}
.text ntkrnlpa.exe!KeSetEvent + 191 81CC1914 4 Bytes JMP 8454779A
.text ntkrnlpa.exe!KeSetEvent + 1D1 81CC1954 8 Bytes [E4, D2, 02, 91, 30, D3, 02, ...] {IN AL, 0xd2; ADD DL, [ECX-0x6efd2cd0]}
.text ntkrnlpa.exe!KeSetEvent + 1DD 81CC1960 4 Bytes [22, D4, 02, 91]
.text ...
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 81DEC62F 5 Bytes JMP 92762C8C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject 81E45543 5 Bytes JMP 9276474C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 110 81E4EE68 4 Bytes CALL 910291B5 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 121 81E52ADC 4 Bytes CALL 910291CB \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 81EA6DCA 7 Bytes JMP 92765D96 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[628] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[628] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[628] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[628] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\csrss.exe[636] KERNEL32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000601F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000603FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] USER32.dll!SetWindowsHookExA 76856322 5 Bytes JMP 00070600
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] USER32.dll!SetWindowsHookExW 768587AD 5 Bytes JMP 00070804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] USER32.dll!UnhookWindowsHookEx 768598DB 5 Bytes JMP 00070A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] USER32.dll!SetWinEventHook 76859F3A 5 Bytes JMP 000701F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] USER32.dll!UnhookWinEvent 7685C06F 5 Bytes JMP 000703FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000803FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00080600
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00081014
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00080804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00080A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00080C0C
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00080E10
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[644] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000801F8
.text C:\Windows\system32\wininit.exe[688] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[688] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[688] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000503FC
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00050600
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00051014
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00050804
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00050A08
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00050C0C
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00050E10
.text C:\Windows\system32\wininit.exe[688] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000501F8
.text C:\Windows\system32\wininit.exe[688] USER32.dll!SetWindowsHookExA 76856322 5 Bytes JMP 00060600
.text C:\Windows\system32\wininit.exe[688] USER32.dll!SetWindowsHookExW 768587AD 5 Bytes JMP 00060804
.text C:\Windows\system32\wininit.exe[688] USER32.dll!UnhookWindowsHookEx 768598DB 5 Bytes JMP 00060A08
.text C:\Windows\system32\wininit.exe[688] USER32.dll!SetWinEventHook 76859F3A 5 Bytes JMP 000601F8
.text C:\Windows\system32\wininit.exe[688] USER32.dll!UnhookWinEvent 7685C06F 5 Bytes JMP 000603FC
.text C:\Windows\system32\csrss.exe[696] KERNEL32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\services.exe[732] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\system32\services.exe[732] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\system32\services.exe[732] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\services.exe[732] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\services.exe[732] USER32.dll!SetWindowsHookExA 76856322 5 Bytes JMP 00080600
.text C:\Windows\system32\services.exe[732] USER32.dll!SetWindowsHookExW 768587AD 5 Bytes JMP 00080804
.text C:\Windows\system32\services.exe[732] USER32.dll!UnhookWindowsHookEx 768598DB 5 Bytes JMP 00080A08
.text C:\Windows\system32\services.exe[732] USER32.dll!SetWinEventHook 76859F3A 5 Bytes JMP 000801F8
.text C:\Windows\system32\services.exe[732] USER32.dll!UnhookWinEvent 7685C06F 5 Bytes JMP 000803FC
.text C:\Windows\system32\lsass.exe[748] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\system32\lsass.exe[748] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\system32\lsass.exe[748] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000B03FC
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 000B0600
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 000B1014
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 000B0804
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 000B0A08
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 000B0C0C
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 000B0E10
.text C:\Windows\system32\lsass.exe[748] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000B01F8
.text C:\Windows\system32\lsass.exe[748] USER32.dll!SetWindowsHookExA 76856322 5 Bytes JMP 000C0600
.text C:\Windows\system32\lsass.exe[748] USER32.dll!SetWindowsHookExW 768587AD 5 Bytes JMP 000C0804
.text C:\Windows\system32\lsass.exe[748] USER32.dll!UnhookWindowsHookEx 768598DB 5 Bytes JMP 000C0A08
.text C:\Windows\system32\lsass.exe[748] USER32.dll!SetWinEventHook 76859F3A 5 Bytes JMP 000C01F8
.text C:\Windows\system32\lsass.exe[748] USER32.dll!UnhookWinEvent 7685C06F 5 Bytes JMP 000C03FC
.text C:\Windows\system32\lsm.exe[760] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\system32\lsm.exe[760] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\system32\lsm.exe[760] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\lsm.exe[760] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000701F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 001501F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 001503FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 001703FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00170600
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00171014
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00170804
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00170A08
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00170C0C
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00170E10
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 001701F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] USER32.dll!SetWindowsHookExA 76856322 5 Bytes JMP 00180600
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] USER32.dll!SetWindowsHookExW 768587AD 5 Bytes JMP 00180804
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] USER32.dll!UnhookWindowsHookEx 768598DB 5 Bytes JMP 00180A08
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] USER32.dll!SetWinEventHook 76859F3A 5 Bytes JMP 001801F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[780] USER32.dll!UnhookWinEvent 7685C06F 5 Bytes JMP 001803FC
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 001401F8
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 001403FC
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 001603FC
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00160600
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00161014
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00160804
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00160A08
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00160C0C
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00160E10
.text C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe[808] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 001601F8
.text C:\Windows\system32\winlogon.exe[836] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[836] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[836] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000603FC
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00060600
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00061014
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00060804
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00060A08
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00060C0C
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00060E10
.text C:\Windows\system32\winlogon.exe[836] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000601F8
.text C:\Windows\system32\winlogon.exe[836] USER32.dll!SetWindowsHookExA 76856322 5 Bytes JMP 00070600
.text C:\Windows\system32\winlogon.exe[836] USER32.dll!SetWindowsHookExW 768587AD 5 Bytes JMP 00070804
.text C:\Windows\system32\winlogon.exe[836] USER32.dll!UnhookWindowsHookEx 768598DB 5 Bytes JMP 00070A08
.text C:\Windows\system32\winlogon.exe[836] USER32.dll!SetWinEventHook 76859F3A 5 Bytes JMP 000701F8
.text C:\Windows\system32\winlogon.exe[836] USER32.dll!UnhookWinEvent 7685C06F 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[900] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[900] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[900] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[900] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000901F8
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000903FC
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000B03FC
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 000B0600
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 000B1014
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 000B0804
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 000B0A08
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 000B0C0C
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 000B0E10
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000B01F8
.text C:\Windows\system32\svchost.exe[948] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[948] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1020] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\system32\svchost.exe[1020] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000703FC
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00070600
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00071014
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00070804
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00070A08
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!ChangeServiceConfig2A 76737099 5 Bytes JMP 00070C0C
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!ChangeServiceConfig2W 767371E1 5 Bytes JMP 00070E10
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!CreateServiceA 767372A1 5 Bytes JMP 000701F8
.text C:\Windows\system32\svchost.exe[1020] USER32.dll!SetWindowsHookExA 76856322 5 Bytes JMP 00100600
.text C:\Windows\system32\svchost.exe[1020] USER32.dll!SetWindowsHookExW 768587AD 5 Bytes JMP 00100804
.text C:\Windows\system32\svchost.exe[1020] USER32.dll!UnhookWindowsHookEx 768598DB 5 Bytes JMP 00100A08
.text C:\Windows\system32\svchost.exe[1020] USER32.dll!SetWinEventHook 76859F3A 5 Bytes JMP 001001F8
.text C:\Windows\system32\svchost.exe[1020] USER32.dll!UnhookWinEvent 7685C06F 5 Bytes JMP 001003FC
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!LdrLoadDll 76DD9378 5 Bytes JMP 000501F8
.text C:\Windows\System32\svchost.exe[1080] ntdll.dll!LdrUnloadDll 76DEB680 5 Bytes JMP 000503FC
.text C:\Windows\System32\svchost.exe[1080] kernel32.dll!GetBinaryTypeW + 70 754C2467 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!CreateServiceW 766F9EB4 5 Bytes JMP 000703FC
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!DeleteService 766FA07E 5 Bytes JMP 00070600
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!SetServiceObjectSecurity 76736CD9 5 Bytes JMP 00071014
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfigA 76736DD9 5 Bytes JMP 00070804
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfigW 76736F81 5 Bytes JMP 00070A08
.text C:\Windows\System32\svchost.exe[1080] ADVAPI32.dll!ChangeServiceConfig2A