mit GM meinte ich den Gmer Scanner ;)
naja hier mal die loggs;
Btw. da man maximal 25000 Zeichen schreiben kann, musste ich das in 3 Threads aufteilen.
Gmer
Anmerkung:
Hatte leider Windows Live + plus an.
Beim ersten scannen hatte ich die nicht an, und dort wurde auch keinen eintrag über msn etc. geschrieben.
Jedoch hab ich diese trotzdem mal NICHT ausgelassen. Code:
GMER 1.0.15.14939 - http://www.gmer.net
Rootkit scan 2009-03-20 22:14:02
Windows 6.0.6001 Service Pack 1
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] kernel32.dll!FindResourceExA 765808DD 7 Bytes JMP 28001D80 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] kernel32.dll!FindResourceA 765809A5 5 Bytes JMP 28001CF0 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] kernel32.dll!CreateEventA 76594AD8 5 Bytes JMP 28001840 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] kernel32.dll!LockResource 76597F1F 5 Bytes JMP 28001F50 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] kernel32.dll!FindResourceExW 7659813B 1 Byte [E9]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] kernel32.dll!FindResourceExW 7659813B 7 Bytes JMP 28001C60 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] kernel32.dll!LoadResource 76598213 7 Bytes JMP 28001E20 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] kernel32.dll!FindResourceW 765997C7 5 Bytes JMP 28001BE0 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] kernel32.dll!SizeofResource 765997E5 7 Bytes JMP 28001EE0 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] ADVAPI32.dll!CryptDeriveKey 7680E6F6 7 Bytes JMP 28001000 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] ADVAPI32.dll!CryptDecrypt 7680E8D9 7 Bytes JMP 28001060 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] USER32.dll!SetWindowPlacement 76C379BB 5 Bytes JMP 28005DC0 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] USER32.dll!SetWindowRgn 76C395E2 7 Bytes JMP 28005F00 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] USER32.dll!LoadImageW 76C3D61D 5 Bytes JMP 28006690 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] USER32.dll!LoadIconW 76C3EC94 5 Bytes JMP 28006880 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] USER32.dll!CreateWindowExW 76C43D67 5 Bytes JMP 28003CA0 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] USER32.dll!GetWindowLongW 76C4F67F 7 Bytes JMP 28006A20 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] USER32.dll!PeekMessageW 76C4FD9F 5 Bytes JMP 280045E0 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] USER32.dll!TrackPopupMenuEx 76C60F4D 5 Bytes JMP 28004EC0 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] USER32.dll!CreateDialogParamW 76C61C58 5 Bytes JMP 28006040 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] USER32.dll!MessageBoxIndirectW 76C8D56B 5 Bytes JMP 28006230 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] WS2_32.dll!closesocket 7663330C 5 Bytes JMP 2800BC20 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] WS2_32.dll!recv 7663343A 5 Bytes JMP 2800B440 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] WS2_32.dll!WSASend 76634496 5 Bytes JMP 2800B9E0 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] WS2_32.dll!send 7663659B 5 Bytes JMP 2800B800 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] WS2_32.dll!WSARecv 76638400 5 Bytes JMP 2800B5E0 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] SHELL32.dll!Shell_NotifyIconW 76D7C808 5 Bytes JMP 28003400 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] ole32.dll!CoRegisterClassObject 762E45AC 5 Bytes JMP 28002360 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] ole32.dll!CoInitializeEx 7631B89A 5 Bytes JMP 28002260 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] ole32.dll!CoCreateInstance 7631E188 5 Bytes JMP 28002600 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] WININET.dll!HttpOpenRequestA 767406D6 5 Bytes JMP 2800A2C0 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] WININET.dll!InternetCloseHandle 7674607B 5 Bytes JMP 2800A600 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] WININET.dll!InternetReadFile 7674A067 5 Bytes JMP 2800A450 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] WININET.dll!HttpSendRequestA 767508C5 3 Bytes JMP 2800A530 D:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Patchou)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[820] WININET.dll!HttpSendRequestA + 4 767508C9 1 Byte [B1]
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00805a4616ab
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00805a4616ab@0014a704be96 0x7D 0x37 0xF9 0x8C ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00805a4616ab
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00805a4616ab@0014a704be96 0x7D 0x37 0xF9 0x8C ... RegSearch:
Anmerkung:
Sonst hat das Programm leider nichts gefunden...
Weiß leider nicht, ob das normal ist. Code:
Windows Registry Editor Version 5.00
; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.6.0
; Results at 21.03.2009 13:21:25 for strings:
; 'a75aed00-d7bf-11d1-9947-00c0cf98bbc9'
; Strings excluded from search:
; 'a75aed00-d7bf-11d1-9947-00c0cf98bbc9'
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS
; End Of The Log... |