Danke für die antwort! Hab jetzt das programm durchlaufen lassen (spybot und gmer) und hier nun das ergebnis
Muss es leider in 4 posts aufteilen! Also sry!
GMER 1.0.15.15077 [37fx8hot.exe] - GMER - Rootkit Detector and Remover
Rootkit scan 2009-08-22 20:45:03
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT sppx.sys ZwCreateKey [0xF74B70E0]
SSDT sppx.sys ZwEnumerateKey [0xF74D5CA2]
SSDT sppx.sys ZwEnumerateValueKey [0xF74D6030]
SSDT sppx.sys ZwOpenKey [0xF74B70C0]
SSDT sppx.sys ZwQueryKey [0xF74D6108]
SSDT sppx.sys ZwQueryValueKey [0xF74D5F88]
SSDT sppx.sys ZwSetValueKey [0xF74D619A]
INT 0x62 ? 8636EBF8
INT 0x63 ? 86135BF8
INT 0x82 ? 8636EBF8
INT 0x83 ? 86135BF8
INT 0xA4 ? 86135BF8
INT 0xB4 ? 86135BF8
---- Kernel code sections - GMER 1.0.15 ----
? sppx.sys Das System kann die angegebene Datei nicht finden. !
.text USBPORT.SYS!DllUnload F660E8AC 5 Bytes JMP 861351D8
.text a9zx6qq4.SYS F643A386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text a9zx6qq4.SYS F643A3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text a9zx6qq4.SYS F643A3C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text a9zx6qq4.SYS F643A3C9 1 Byte [2E]
.text a9zx6qq4.SYS F643A3C9 11 Bytes [2E, 00, 00, 00, 5C, 02, 00, ...] {ADD CS:[EAX], AL; ADD [EDX+EAX+0x0], BL; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\Programme\Windows Live\Messenger\MsnMsgr.Exe[336] kernel32.dll!LoadResource 7C80A055 7 Bytes JMP 28001E20 C:\Programme\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Programme\Windows Live\Messenger\MsnMsgr.Exe[336] kernel32.dll!FindResourceExW 7C80AD28 7 Bytes JMP 28001C60 C:\Programme\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Programme\Windows Live\Messenger\MsnMsgr.Exe[336] kernel32.dll!FindResourceW 7C80BC6E 7 Bytes JMP 28001BE0 C:\Programme\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Programme\Windows Live\Messenger\MsnMsgr.Exe[336] kernel32.dll!SizeofResource 7C80BD09 7 Bytes JMP 28001EE0 C:\Programme\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Programme\Windows Live\Messenger\MsnMsgr.Exe[336] kernel32.dll!FindResourceA 7C80BF29 7 Bytes JMP 28001CF0 C:\Programme\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Programme\Windows Live\Messenger\MsnMsgr.Exe[336] kernel32.dll!LockResource 7C80CD37 5 Bytes JMP 28001F50 C:\Programme\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Programme\Windows Live\Messenger\MsnMsgr.Exe[336] kernel32.dll!CreateEventA 7C8308B5 5 Bytes JMP 28001840 C:\Programme\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Programme\Windows Live\Messenger\MsnMsgr.Exe[336] kernel32.dll!FindResourceExA 7C835FA8 7 Bytes JMP 28001D80 C:\Programme\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Programme\Windows Live\Messenger\MsnMsgr.Exe[336] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes JMP 0056DBBD C:\Programme\Windows Live\Messenger\MsnMsgr.Exe (Windows Live Messenger/Microsoft Corporation)
.text C:\Programme\Windows Live\Messenger\MsnMsgr.Exe[336] kernel32.dll!OutputDebugStringW 7C85B405 5 Bytes JMP 28001FB0 C:\Programme\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Programme\Windows Live\Messenger\MsnMsgr.Exe[336] ADVAPI32.dll!CryptDeriveKey 77DB9FFD 7 Bytes JMP 28001000 C:\Programme\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Programme\Windows Live\Messenger\MsnMsgr.Exe[336] ADVAPI32.dll!CryptDecrypt 77DBA129 7 Bytes JMP 28001060 C:\Programme\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Programme\Windows Live\Messenger\MsnMsgr.Exe[336] USER32.dll!PeekMessageW 7E36929B 5 Bytes JMP 280046C0 C:\Programme\Messenger Plus! Live\MsgPlusLive1.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Programme\Windows Live\Messenger\MsnMsgr.Exe[336] USER32.dll!SetWindowPlacement 7E36DE46 5 Bytes
