![]() |
|
Plagegeister aller Art und deren Bekämpfung: Firefox: Unerwünschte WerbungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #10 |
![]() ![]() | ![]() Firefox: Unerwünschte Werbung TDSSKiller-Report: 20:33:45:120 3168 TDSS rootkit removing tool 2.2.8.1 Mar 22 2010 10:43:04 20:33:45:120 3168 ================================================================================ 20:33:45:120 3168 SystemInfo: 20:33:45:120 3168 OS Version: 5.1.2600 ServicePack: 3.0 20:33:45:120 3168 Product type: Workstation 20:33:45:120 3168 ComputerName: ÄTSCH 20:33:45:120 3168 UserName: Jens 20:33:45:120 3168 Windows directory: C:\WINDOWS 20:33:45:120 3168 Processor architecture: Intel x86 20:33:45:120 3168 Number of processors: 1 20:33:45:120 3168 Page size: 0x1000 20:33:45:130 3168 Boot type: Normal boot 20:33:45:130 3168 ================================================================================ 20:33:45:130 3168 UnloadDriverW: NtUnloadDriver error 1 20:33:45:130 3168 ForceUnloadDriverW: UnloadDriverW(klmd21) error 1 20:33:45:140 3168 LoadDriverW: Driver already loaded 20:33:45:140 3168 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system 20:33:45:140 3168 wfopen_ex: MyNtCreateFileW error 32 (C0000043) 20:33:45:140 3168 wfopen_ex: Trying to KLMD file open 20:33:45:140 3168 wfopen_ex: File opened ok (Flags 2) 20:33:45:140 3168 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software 20:33:45:140 3168 wfopen_ex: MyNtCreateFileW error 32 (C0000043) 20:33:45:140 3168 wfopen_ex: Trying to KLMD file open 20:33:45:140 3168 wfopen_ex: File opened ok (Flags 2) 20:33:45:140 3168 Initialize success 20:33:45:140 3168 20:33:45:140 3168 Scanning Services ... 20:33:45:511 3168 Raw services enum returned 389 services 20:33:45:521 3168 20:33:45:521 3168 Scanning Kernel memory ... 20:33:45:521 3168 Devices to scan: 3 20:33:45:521 3168 20:33:45:521 3168 Driver Name: Disk 20:33:45:521 3168 IRP_MJ_CREATE : F77D4BB0 20:33:45:521 3168 IRP_MJ_CREATE_NAMED_PIPE : 804FA88E 20:33:45:521 3168 IRP_MJ_CLOSE : F77D4BB0 20:33:45:521 3168 IRP_MJ_READ : F77CED1F 20:33:45:521 3168 IRP_MJ_WRITE : F77CED1F 20:33:45:521 3168 IRP_MJ_QUERY_INFORMATION : 804FA88E 20:33:45:521 3168 IRP_MJ_SET_INFORMATION : 804FA88E 20:33:45:521 3168 IRP_MJ_QUERY_EA : 804FA88E 20:33:45:521 3168 IRP_MJ_SET_EA : 804FA88E 20:33:45:521 3168 IRP_MJ_FLUSH_BUFFERS : F77CF2E2 20:33:45:521 3168 IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E 20:33:45:521 3168 IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E 20:33:45:521 3168 IRP_MJ_DIRECTORY_CONTROL : 804FA88E 20:33:45:521 3168 IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E 20:33:45:521 3168 IRP_MJ_DEVICE_CONTROL : F77CF3BB 20:33:45:521 3168 IRP_MJ_INTERNAL_DEVICE_CONTROL : F77D2F28 20:33:45:521 3168 IRP_MJ_SHUTDOWN : F77CF2E2 20:33:45:521 3168 IRP_MJ_LOCK_CONTROL : 804FA88E 20:33:45:521 3168 IRP_MJ_CLEANUP : 804FA88E 20:33:45:521 3168 IRP_MJ_CREATE_MAILSLOT : 804FA88E 20:33:45:521 3168 IRP_MJ_QUERY_SECURITY : 804FA88E 20:33:45:521 3168 IRP_MJ_SET_SECURITY : 804FA88E 20:33:45:521 3168 IRP_MJ_POWER : F77D0C82 20:33:45:521 3168 IRP_MJ_SYSTEM_CONTROL : F77D599E 20:33:45:521 3168 IRP_MJ_DEVICE_CHANGE : 804FA88E 20:33:45:521 3168 IRP_MJ_QUERY_QUOTA : 804FA88E 20:33:45:521 3168 IRP_MJ_SET_QUOTA : 804FA88E 20:33:45:531 3168 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1 20:33:45:531 3168 20:33:45:531 3168 Driver Name: Disk 20:33:45:531 3168 IRP_MJ_CREATE : F77D4BB0 20:33:45:531 3168 IRP_MJ_CREATE_NAMED_PIPE : 804FA88E 20:33:45:531 3168 IRP_MJ_CLOSE : F77D4BB0 20:33:45:531 3168 IRP_MJ_READ : F77CED1F 20:33:45:531 3168 IRP_MJ_WRITE : F77CED1F 20:33:45:531 3168 IRP_MJ_QUERY_INFORMATION : 804FA88E 20:33:45:531 3168 IRP_MJ_SET_INFORMATION : 804FA88E 20:33:45:531 3168 IRP_MJ_QUERY_EA : 804FA88E 20:33:45:531 3168 IRP_MJ_SET_EA : 804FA88E 20:33:45:531 3168 IRP_MJ_FLUSH_BUFFERS : F77CF2E2 20:33:45:531 3168 IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E 20:33:45:531 3168 IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E 20:33:45:531 3168 IRP_MJ_DIRECTORY_CONTROL : 804FA88E 20:33:45:531 3168 IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E 20:33:45:531 3168 IRP_MJ_DEVICE_CONTROL : F77CF3BB 20:33:45:531 3168 IRP_MJ_INTERNAL_DEVICE_CONTROL : F77D2F28 20:33:45:531 3168 IRP_MJ_SHUTDOWN : F77CF2E2 20:33:45:541 3168 IRP_MJ_LOCK_CONTROL : 804FA88E 20:33:45:541 3168 IRP_MJ_CLEANUP : 804FA88E 20:33:45:541 3168 IRP_MJ_CREATE_MAILSLOT : 804FA88E 20:33:45:541 3168 IRP_MJ_QUERY_SECURITY : 804FA88E 20:33:45:541 3168 IRP_MJ_SET_SECURITY : 804FA88E 20:33:45:541 3168 IRP_MJ_POWER : F77D0C82 20:33:45:541 3168 IRP_MJ_SYSTEM_CONTROL : F77D599E 20:33:45:541 3168 IRP_MJ_DEVICE_CHANGE : 804FA88E 20:33:45:541 3168 IRP_MJ_QUERY_QUOTA : 804FA88E 20:33:45:541 3168 IRP_MJ_SET_QUOTA : 804FA88E 20:33:45:541 3168 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1 20:33:45:541 3168 20:33:45:541 3168 Driver Name: atapi 20:33:45:541 3168 IRP_MJ_CREATE : 87B41AC8 20:33:45:541 3168 IRP_MJ_CREATE_NAMED_PIPE : 87B41AC8 20:33:45:541 3168 IRP_MJ_CLOSE : 87B41AC8 20:33:45:541 3168 IRP_MJ_READ : 87B41AC8 20:33:45:541 3168 IRP_MJ_WRITE : 87B41AC8 20:33:45:541 3168 IRP_MJ_QUERY_INFORMATION : 87B41AC8 20:33:45:541 3168 IRP_MJ_SET_INFORMATION : 87B41AC8 20:33:45:541 3168 IRP_MJ_QUERY_EA : 87B41AC8 20:33:45:541 3168 IRP_MJ_SET_EA : 87B41AC8 20:33:45:541 3168 IRP_MJ_FLUSH_BUFFERS : 87B41AC8 20:33:45:541 3168 IRP_MJ_QUERY_VOLUME_INFORMATION : 87B41AC8 20:33:45:541 3168 IRP_MJ_SET_VOLUME_INFORMATION : 87B41AC8 20:33:45:541 3168 IRP_MJ_DIRECTORY_CONTROL : 87B41AC8 20:33:45:541 3168 IRP_MJ_FILE_SYSTEM_CONTROL : 87B41AC8 20:33:45:541 3168 IRP_MJ_DEVICE_CONTROL : 87B41AC8 20:33:45:541 3168 IRP_MJ_INTERNAL_DEVICE_CONTROL : 87B41AC8 20:33:45:541 3168 IRP_MJ_SHUTDOWN : 87B41AC8 20:33:45:541 3168 IRP_MJ_LOCK_CONTROL : 87B41AC8 20:33:45:541 3168 IRP_MJ_CLEANUP : 87B41AC8 20:33:45:541 3168 IRP_MJ_CREATE_MAILSLOT : 87B41AC8 20:33:45:541 3168 IRP_MJ_QUERY_SECURITY : 87B41AC8 20:33:45:541 3168 IRP_MJ_SET_SECURITY : 87B41AC8 20:33:45:541 3168 IRP_MJ_POWER : 87B41AC8 20:33:45:541 3168 IRP_MJ_SYSTEM_CONTROL : 87B41AC8 20:33:45:541 3168 IRP_MJ_DEVICE_CHANGE : 87B41AC8 20:33:45:541 3168 IRP_MJ_QUERY_QUOTA : 87B41AC8 20:33:45:541 3168 IRP_MJ_SET_QUOTA : 87B41AC8 20:33:45:541 3168 Driver "atapi" infected by TDSS rootkit! 20:33:45:541 3168 C:\WINDOWS\system32\drivers\tsk5A.tmp - Verdict: 3 20:33:45:541 3168 20:33:45:541 3168 Completed 20:33:45:541 3168 20:33:45:541 3168 Results: 20:33:45:541 3168 Memory objects infected / cured / cured on reboot: 1 / 0 / 0 20:33:45:541 3168 Registry objects infected / cured / cured on reboot: 0 / 0 / 0 20:33:45:541 3168 File objects infected / cured / cured on reboot: 0 / 0 / 0 20:33:45:541 3168 20:33:45:541 3168 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system 20:33:45:541 3168 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software 20:33:45:541 3168 UnloadDriverW: NtUnloadDriver error 1 20:33:45:541 3168 KLMD(ARK) unloaded successfully |
Themen zu Firefox: Unerwünschte Werbung |
fenster, firefox, gesuch, gesuchte, irgendetwas, klick, malewarebytes, schei, tagen, umgeleitet, unerwünschte, unerwünschte werbung, werbeseite, werbeseiten, werbun, werbung, zusätzliches, öffnet, öfters |