![]() |
TR/Rootkit.Gen in fuodwd.sys be mir den TR/Rootkit.Gen eingefangen sitzt in der Datei (laut Antivir) C:\windows\system32\drivers\fuodwd.sys und kann nicht gelöscht oder sonst wie bearbeitet werden (gesicherter Modus/eingabeaufforderun usw) Der Hijacker hat folgendes ausgeworfen : HiJackthis Logfile: Code: Logfile of Trend Micro HijackThis v2.0.4 Hoffe habe alle Forenregeln beachtet, und mir kann jemand helfen Thx |
Guten Abend. Ich möchte gerne mal was ausprobieren: Norton Power Eraser - Anleitung NPE ist ein Tool zum Entfernen von Crime- und Scareware welche sich hartnäckig vor anderen Virenscannern versteckt und durch PopUps oder andere Meldungen die Arbeit am Computer massiv behindert. Die Scanmethoden sind sehr aggressiv daher sollte das Tool nicht leichfertig benutzt werden. Funde sollten erst dann gelöscht werden wenn ein Helfer dies ausdrücklich empfohlen hat. Bei falscher oder leichtsinniger Benutzung drohen Datenverlust und Systeminstabilität! Inhalt:
Download und Initiallisierung
http://img215.imageshack.us/img215/5...stellungen.png Scan
Posten des logfiles
|
So habe alles gemacht und die Protokoll Datei als zip angehängt Hoffe das es so klappt thx schonmal |
Anleitung Avenger (by swandog46) Lade dir das Tool Avenger und speichere es auf dem Desktop
Code: Files to delete:
GMER - Rootkit Detection
Master Boot Record überprüfen: Lade dir die mbr.exe von gmer auf den Desktop und führe die Datei mit Administrator-Rechten aus. Poste das log! Sollte ein MBR Rootkit gefunden worde sein, das wird im log durch den Ausdruck Zitat:
Downloade dir dafür die mbr.bat.txt von BataAlexander und speichere sie neben der mbr.exe auf dem Desktop. Ändere die Endung der mbr.txt.bat in mbr.bat Eine vernünftige Ordneransicht ist dafür nötig. Dann führe die mbr.bat. durch einen Doppelklick aus. Dabei muss sich die mbr.exe von gmer ebenfalls auf dem Desktop befinden! Der MBR wird bereinigt und es erscheint ein log. Poste auch diese log! Dateien Online überprüfen lassen: * Lasse dir auch die versteckten Dateien anzeigen! * Rufe die Seite Virustotal auf. * Dort suche über den "Durchsuchen"-Button folgende Datei raus und lade sie durch Druck auf den "Senden der Datei"-Button hoch. Zitat:
* Sollte die Datei bereits analysiert worden sein so lasse sie unbedingt trotzdem nocheinmal analysieren! * Poste im Anschluss das Ergebnis der Auswertung, alles abkopieren und in einen Beitrag einfügen. |
So habe hoffentlich alles gemacht, wenn etwas fehlen sollte bitte sagen: mbr: Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, hxxp://www.gmer.net device: opened successfully user: error reading MBR kernel: error reading MBR VirusTotal: Die Datei wurde bereits analysiert: MD5: 0b8f2126e86e783d72cfb5dcdcb39735 First received: 2009.08.28 01:29:40 UTC Datum 2010.05.14 09:48:20 UTC [>16D] Ergebnisse 0/41 Permalink: analisis/341b42b33bcf248207d05d8d87398ad6566ad3c16b3bfb680fcd0cc77fd69db9-1273830500 avnger: Logfile of The Avenger Version 2.0, (c) by Swandog46 hxxp://swandog46.geekstogo.com Platform: Windows Vista ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! File "c:\windows\system32\mxakhgcz.dll" deleted successfully. Registry value "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|skb" deleted successfully. Completed script processing. ******************* Finished! Terminate. gmerscan part 1: GMER 1.0.15.15281 - hxxp://www.gmer.net Rootkit scan 2010-05-31 10:24:48 Windows 6.1.7600 Running: 6j8ediop.exe; Driver: C:\Users\MIA\AppData\Local\Temp\ufldypow.sys ---- System - GMER 1.0.15 ---- INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8243DAF8 INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8243D104 INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8243D3F4 INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 824262D8 INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82425898 INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8243D1DC INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8243D958 INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8243D6F8 INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8243DF2C INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8243E1A8 ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82056599 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 8207AF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} ? System32\Drivers\fuodwd.sys Ein an das System angeschlossenes Gerät funktioniert nicht. ! .text peauth.sys A707BC9D 28 Bytes [5E, BE, A5, 43, 8D, 0F, F0, ...] .text peauth.sys A707BCC1 28 Bytes [5E, BE, A5, 43, 8D, 0F, F0, ...] PAGE peauth.sys A7081E20 101 Bytes [66, 17, E4, 3E, DC, 8A, 3D, ...] PAGE peauth.sys A708202C 102 Bytes [01, 63, 06, 55, 3C, 25, 21, ...] ---- User code sections - GMER 1.0.15 ---- .text C:\Windows\system32\svchost.exe[1028] ntdll.dll!NtProtectVirtualMemory 770C5360 5 Bytes JMP 002D000A .text C:\Windows\system32\svchost.exe[1028] ntdll.dll!NtWriteVirtualMemory 770C5EE0 5 Bytes JMP 002E000A .text C:\Windows\system32\svchost.exe[1028] ntdll.dll!KiUserExceptionDispatcher 770C6448 5 Bytes JMP 002C000A .text C:\Windows\system32\svchost.exe[1028] ole32.dll!CoCreateInstance 76F757FC 5 Bytes JMP 0038000A .text C:\Windows\system32\taskhost.exe[1768] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\taskhost.exe[1768] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\taskhost.exe[1768] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\taskhost.exe[1768] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\taskhost.exe[1768] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\taskhost.exe[1768] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Windows\system32\taskhost.exe[1768] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\taskhost.exe[1768] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\taskhost.exe[1768] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\taskhost.exe[1768] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\Explorer.EXE[2088] ntdll.dll!NtProtectVirtualMemory 770C5360 5 Bytes JMP 0028000A .text C:\Windows\Explorer.EXE[2088] ntdll.dll!NtWriteVirtualMemory 770C5EE0 5 Bytes JMP 0029000A .text C:\Windows\Explorer.EXE[2088] ntdll.dll!KiUserExceptionDispatcher 770C6448 5 Bytes JMP 0016000A .text C:\Windows\Explorer.EXE[2088] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\Explorer.EXE[2088] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\Explorer.EXE[2088] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\Explorer.EXE[2088] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\Explorer.EXE[2088] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Windows\Explorer.EXE[2088] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\Explorer.EXE[2088] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\Explorer.EXE[2088] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\Explorer.EXE[2088] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\FastUserSwitching.exe[3040] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\FastUserSwitching.exe[3040] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\FastUserSwitching.exe[3040] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\FastUserSwitching.exe[3040] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\FastUserSwitching.exe[3040] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\FastUserSwitching.exe[3040] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Program Files\Pegatron\Hotkey\FastUserSwitching.exe[3040] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\FastUserSwitching.exe[3040] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\FastUserSwitching.exe[3040] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\FastUserSwitching.exe[3040] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\CyberLink\YouCam\YouCamTray.exe[3096] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\CyberLink\YouCam\YouCamTray.exe[3096] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\CyberLink\YouCam\YouCamTray.exe[3096] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\CyberLink\YouCam\YouCamTray.exe[3096] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\CyberLink\YouCam\YouCamTray.exe[3096] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\CyberLink\YouCam\YouCamTray.exe[3096] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Program Files\CyberLink\YouCam\YouCamTray.exe[3096] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\CyberLink\YouCam\YouCamTray.exe[3096] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\CyberLink\YouCam\YouCamTray.exe[3096] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\CyberLink\YouCam\YouCamTray.exe[3096] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3140] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3140] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3140] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3140] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3140] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3140] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3140] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3140] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3140] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3140] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\PHControl.exe[3168] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\PHControl.exe[3168] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\PHControl.exe[3168] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\PHControl.exe[3168] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\PHControl.exe[3168] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\PHControl.exe[3168] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Program Files\Pegatron\Hotkey\PHControl.exe[3168] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\PHControl.exe[3168] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\PHControl.exe[3168] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Pegatron\Hotkey\PHControl.exe[3168] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxtray.exe[3224] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxtray.exe[3224] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxtray.exe[3224] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxtray.exe[3224] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxtray.exe[3224] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxtray.exe[3224] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Windows\System32\igfxtray.exe[3224] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxtray.exe[3224] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxtray.exe[3224] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxtray.exe[3224] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\hkcmd.exe[3260] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\hkcmd.exe[3260] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\hkcmd.exe[3260] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\hkcmd.exe[3260] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\hkcmd.exe[3260] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\hkcmd.exe[3260] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Windows\System32\hkcmd.exe[3260] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\hkcmd.exe[3260] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\hkcmd.exe[3260] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\hkcmd.exe[3260] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxpers.exe[3308] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxpers.exe[3308] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxpers.exe[3308] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxpers.exe[3308] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxpers.exe[3308] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxpers.exe[3308] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Windows\System32\igfxpers.exe[3308] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxpers.exe[3308] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxpers.exe[3308] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\System32\igfxpers.exe[3308] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\iTunes\iTunesHelper.exe[3376] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\iTunes\iTunesHelper.exe[3376] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\iTunes\iTunesHelper.exe[3376] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\iTunes\iTunesHelper.exe[3376] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\iTunes\iTunesHelper.exe[3376] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\iTunes\iTunesHelper.exe[3376] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Program Files\iTunes\iTunesHelper.exe[3376] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\iTunes\iTunesHelper.exe[3376] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\iTunes\iTunesHelper.exe[3376] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\iTunes\iTunesHelper.exe[3376] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\igfxsrvc.exe[3388] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\igfxsrvc.exe[3388] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\igfxsrvc.exe[3388] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\igfxsrvc.exe[3388] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\igfxsrvc.exe[3388] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\igfxsrvc.exe[3388] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Windows\system32\igfxsrvc.exe[3388] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\igfxsrvc.exe[3388] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\igfxsrvc.exe[3388] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Windows\system32\igfxsrvc.exe[3388] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Users\MIA\Downloads\6j8ediop.exe[3396] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Users\MIA\Downloads\6j8ediop.exe[3396] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Users\MIA\Downloads\6j8ediop.exe[3396] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Users\MIA\Downloads\6j8ediop.exe[3396] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Users\MIA\Downloads\6j8ediop.exe[3396] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Users\MIA\Downloads\6j8ediop.exe[3396] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Users\MIA\Downloads\6j8ediop.exe[3396] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Users\MIA\Downloads\6j8ediop.exe[3396] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Users\MIA\Downloads\6j8ediop.exe[3396] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Users\MIA\Downloads\6j8ediop.exe[3396] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3424] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3424] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3424] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3424] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3424] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3424] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3424] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3424] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3424] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3424] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3464] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3464] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3464] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3464] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3464] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3464] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3464] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3464] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3464] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3464] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Windows Sidebar\sidebar.exe[3520] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Windows Sidebar\sidebar.exe[3520] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Windows Sidebar\sidebar.exe[3520] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Windows Sidebar\sidebar.exe[3520] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Windows Sidebar\sidebar.exe[3520] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Windows Sidebar\sidebar.exe[3520] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Program Files\Windows Sidebar\sidebar.exe[3520] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Windows Sidebar\sidebar.exe[3520] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Windows Sidebar\sidebar.exe[3520] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Windows Sidebar\sidebar.exe[3520] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[3592] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[3592] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[3592] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[3592] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[3592] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[3592] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[3592] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[3592] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[3592] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[3592] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe[3620] kernel32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe[3620] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe[3620] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe[3620] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe[3620] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe[3620] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe[3620] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe[3620] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe[3620] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe[3620] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe[3732] KERNEL32.dll!VirtualProtect 758A50AB 5 Bytes JMP 660047B5 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe[3732] USER32.dll!SetWindowPlacement 759A8169 5 Bytes JMP 660343DC C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe[3732] USER32.dll!MoveWindow 759AA8C4 5 Bytes JMP 660346D7 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe[3732] USER32.dll!DeferWindowPos 759AC338 5 Bytes JMP 66033D58 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe[3732] USER32.dll!SetWindowPos 759B3581 2 Bytes JMP 66034826 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe[3732] USER32.dll!SetWindowPos + 3 759B3584 2 Bytes [68, F0] .text C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe[3732] USER32.dll!GetWindowRect 759B7450 5 Bytes JMP 660349B2 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe[3732] USER32.dll!EndPaint 759B7B73 5 Bytes JMP 66002C09 C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe[3732] USER32.dll!BeginPaint 759B7B87 5 Bytes JMP 66002C0E C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) .text C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe[3732] USER32.dll!GetWindowPlacement 759D6BD0 5 Bytes JMP 6603452D C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) |
gmerscan part 2: ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe[1760] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75125D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe[1760] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75125D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe[1760] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75125D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe[1760] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75125D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe[1760] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75125D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe[1760] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75125D3D] C:\Windows\system32\apphelp.dll (Clientbibliothek für Anwendungskompatibilität/Microsoft Corporation) IAT C:\Windows\system32\taskhost.exe[1768] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [66058C0B] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\system32\taskhost.exe[1768] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [66058BA0] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\system32\taskhost.exe[1768] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [66058BA0] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\system32\taskhost.exe[1768] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [66058C0B] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\system32\taskhost.exe[1768] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExA] [66058B43] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\system32\taskhost.exe[1768] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [66058C0B] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\system32\taskhost.exe[1768] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [66058BA0] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\system32\taskhost.exe[1768] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [66058B43] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\system32\taskhost.exe[1768] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [66058C0B] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\system32\taskhost.exe[1768] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [66058BA0] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\system32\Dwm.exe[2076] @ C:\Windows\system32\ole32.dll [USER32.dll!GetSysColor] [6605BAED] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\system32\Dwm.exe[2076] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [6605BAED] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\system32\Dwm.exe[2076] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColor] [6605BAED] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\system32\Dwm.exe[2076] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\system32\Dwm.exe[2076] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!CreateRectRgn] [66009EF3] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\Explorer.EXE [KERNEL32.dll!LoadLibraryExA] [66058B43] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\Explorer.EXE [KERNEL32.dll!LoadLibraryW] [66058C0B] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\Explorer.EXE [KERNEL32.dll!LoadLibraryA] [66058BA0] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\Explorer.EXE [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\Explorer.EXE [USER32.dll!UpdateLayeredWindow] [66059343] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\Explorer.EXE [USER32.dll!UpdateLayeredWindowIndirect] [66058C5D] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\Explorer.EXE [USER32.dll!EndPaint] [66059DD7] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\Explorer.EXE [USER32.dll!LoadImageW] [6600ABEE] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\Explorer.EXE [USER32.dll!BeginPaint] [66059AB8] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\Explorer.EXE [USER32.dll!DrawTextW] [6605C0F9] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [66058BA0] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [66058C0B] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExA] [66058B43] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [66058C0B] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [66058BA0] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [66058B43] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\SHELL32.dll [USER32.dll!LoadImageW] [6600ABEE] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DrawTextW] [6605C0F9] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\SHELL32.dll [USER32.dll!BeginPaint] [66059AB8] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\SHELL32.dll [USER32.dll!EndPaint] [66059DD7] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!CreateCompatibleDC] [6605BC58] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [66058BA0] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [66058C0B] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [66058C0B] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [66058BA0] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\Explorer.EXE[2088] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryExA] [66058B43] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Pegatron\Hotkey\FastUserSwitching.exe[3040] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Pegatron\Hotkey\FastUserSwitching.exe[3040] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Pegatron\Hotkey\FastUserSwitching.exe[3040] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!CreateCompatibleDC] [6605BC58] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\CyberLink\YouCam\YouCamTray.exe[3096] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\CyberLink\YouCam\YouCamTray.exe[3096] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\CyberLink\YouCam\YouCamTray.exe[3096] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!CreateCompatibleDC] [6605BC58] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3140] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3140] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3140] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!CreateCompatibleDC] [6605BC58] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Pegatron\Hotkey\PHControl.exe[3168] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Pegatron\Hotkey\PHControl.exe[3168] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Pegatron\Hotkey\PHControl.exe[3168] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!CreateCompatibleDC] [6605BC58] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\System32\igfxtray.exe[3224] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\System32\igfxtray.exe[3224] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\System32\igfxtray.exe[3224] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!CreateCompatibleDC] [6605BC58] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\System32\hkcmd.exe[3260] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\System32\hkcmd.exe[3260] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\System32\hkcmd.exe[3260] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!CreateCompatibleDC] [6605BC58] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\System32\igfxpers.exe[3308] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\System32\igfxpers.exe[3308] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Windows\System32\igfxpers.exe[3308] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!CreateCompatibleDC] [6605BC58] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\iTunes\iTunesHelper.exe[3376] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\iTunes\iTunesHelper.exe[3376] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\iTunes\iTunesHelper.exe[3376] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!CreateCompatibleDC] [6605BC58] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3424] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3424] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[3424] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!CreateCompatibleDC] [6605BC58] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3464] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3464] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3464] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!CreateCompatibleDC] [6605BC58] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Windows Sidebar\sidebar.exe[3520] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Windows Sidebar\sidebar.exe[3520] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Windows Sidebar\sidebar.exe[3520] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!CreateCompatibleDC] [6605BC58] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[3592] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[3592] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[3592] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!CreateCompatibleDC] [6605BC58] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe[3620] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe[3620] @ C:\Windows\system32\SHELL32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe[3620] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!CreateCompatibleDC] [6605BC58] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe[3732] @ C:\Windows\system32\shell32.dll [USER32.dll!GetWindowDC] [66033E76] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe[3732] @ C:\Windows\system32\shell32.dll [USER32.dll!FillRect] [6605BB09] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) IAT C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe[3732] @ C:\Windows\system32\shell32.dll [GDI32.dll!CreateCompatibleDC] [6605BC58] C:\Program Files\Stardock\MyColors\WBLIND.dll (WindowBlinds/Stardock Corporation) ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 84F83CC8 AttachedDevice \FileSystem\Ntfs \Ntfs BdFileSpy.sys Device \Driver\ACPI_HAL \Device\00000047 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation) Device -> \Driver\atapi \Device\Harddisk0\DR0 84C90EC5 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002243ee27c4 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002243faceb1 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002243faceb1@001fe4520ebd 0x65 0x5F 0x44 0x8C ... Reg HKLM\SYSTEM\CurrentControlSet\services\fuodwd@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\fuodwd@Start 0 Reg HKLM\SYSTEM\CurrentControlSet\services\fuodwd@ErrorControl 0 Reg HKLM\SYSTEM\CurrentControlSet\services\fuodwd@Group Boot Bus Extender Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002243ee27c4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002243faceb1 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002243faceb1@001fe4520ebd 0x65 0x5F 0x44 0x8C ... Reg HKLM\SYSTEM\ControlSet002\services\fuodwd@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\fuodwd@Start 0 Reg HKLM\SYSTEM\ControlSet002\services\fuodwd@ErrorControl 0 Reg HKLM\SYSTEM\ControlSet002\services\fuodwd@Group Boot Bus Extender Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{617A4722-CD54-4FA4-A57E-720841921D98} Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{617A4722-CD54-4FA4-A57E-720841921D98} Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{617A4722-CD54-4FA4-A57E-720841921D98}@Path \Microsoft\Windows Defender\MP Scheduled Scan Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{617A4722-CD54-4FA4-A57E-720841921D98}@Triggers 0x15 0x00 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{617A4722-CD54-4FA4-A57E-720841921D98}@DynamicInfo 0x03 0x00 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Defender\MP Scheduled Scan@Id {617A4722-CD54-4FA4-A57E-720841921D98} ---- Files - GMER 1.0.15 ---- File C:\Windows\system32\drivers\atapi.sys suspicious modification ---- EOF - GMER 1.0.15 ---- |
2 Treffer. Bevor wir die bereinigen möchte ich mir etwas angucken: Poste bitte ein OSAM log. Und leg dir schonmal deine Windows CD parat. |
OSAM Logfile: Code: Report of OSAM: Autorun Manager v5.0.11926.0 If You have questions or want to get some help, You can visit Online Solutions :: Index |
Mist, finde die blöde disk nicht, hoffe bekomen dasn! evt auch ohne hi |
Deaktiviere mit OSAM folgende Einträge: Zitat:
Sag mal hattest du mal Bullguard drauf? Da sind noch super viele Einträge übrig. Deinstalliere den ganzen Mist bitte indem so vorgehst: http://www.bullguard.com/support/pro...uninstall.aspx Das Removal Tool findet sich ganz unten auf den Seite. Zitat:
Wäre besser wenn du sie finden würdest. Ansonsten mache bitte das hier: http://www.trojaner-board.de/82358-t...tml#post640150 und poste uns den Bericht. |
Habe alle datein deaktiverit, ging nicht sofort (easyway) Musste einmal runterfahren, hoffe hater gemacht und bullguard habe ich komplett deinstaliert. mache jetzt den tdsskiller, weil disk ist nicht auffindbar, aber wollt evt. sowieso xp draufmachen wenn system sauber ist |
tdsskiller scan hat überall 0 ergeben |
Zitat:
Poste bitte ein neues gmer, HJT und OSAM log. |
Hier schomal der osamlog: OSAM Logfile: Code: Report of OSAM: Autorun Manager v5.0.11926.0 If You have questions or want to get some help, You can visit hxxp://forum.online-solutions. |
Hier der Hijacklog: HiJackthis Logfile: Code: Logfile of Trend Micro HijackThis v2.0.4 |
Alle Zeitangaben in WEZ +1. Es ist jetzt 14:51 Uhr. |
Copyright ©2000-2025, Trojaner-Board