![]() |
|
Plagegeister aller Art und deren Bekämpfung: Firefox leitet ungewollt um, Antivirenprogramme werden blockiertWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
![]() ![]() | ![]() Firefox leitet ungewollt um, Antivirenprogramme werden blockiert Okay, hier der Report von RootRepeal: Code:
ATTFilter ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2010/01/20 17:38 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ------------------- Name: dump_iaStor.sys Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys Address: 0xA0722000 Size: 892928 File Visible: No Signed: - Status: - Name: PCI_PNP4422 Image Path: \Driver\PCI_PNP4422 Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xA02C3000 Size: 49152 File Visible: No Signed: - Status: - Name: spmg.sys Image Path: spmg.sys Address: 0xF7386000 Size: 1052672 File Visible: No Signed: - Status: - Name: sptd Image Path: \Driver\sptd Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Hidden/Locked Files ------------------- Path: c:\windows\temp\mcmsc_xhxydguwsmhhfid Status: Allocation size mismatch (API: 4096, Raw: 0) Path: c:\windows\temp\sqlite_ozcemi6xfctteyh Status: Allocation size mismatch (API: 4096, Raw: 0) SSDT ------------------- #: 041 Function Name: NtCreateKey Status: Hooked by "spmg.sys" at address 0xf73870e0 #: 071 Function Name: NtEnumerateKey Status: Hooked by "spmg.sys" at address 0xf73a5ca4 #: 073 Function Name: NtEnumerateValueKey Status: Hooked by "spmg.sys" at address 0xf73a6032 #: 119 Function Name: NtOpenKey Status: Hooked by "spmg.sys" at address 0xf73870c0 #: 160 Function Name: NtQueryKey Status: Hooked by "spmg.sys" at address 0xf73a610a #: 177 Function Name: NtQueryValueKey Status: Hooked by "spmg.sys" at address 0xf73a5f8a #: 247 Function Name: NtSetValueKey Status: Hooked by "spmg.sys" at address 0xf73a619c Stealth Objects ------------------- Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP] Process: System Address: 0x865671f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP] Process: System Address: 0x85b1a1f8 Size: 121 Object: Hidden Code [Driver: usbstor, IRP_MJ_CREATE] Process: System Address: 0x852b0500 Size: 121 Object: Hidden Code [Driver: usbstor, IRP_MJ_CLOSE] Process: System Address: 0x852b0500 Size: 121 Object: Hidden Code [Driver: usbstor, IRP_MJ_READ] Process: System Address: 0x852b0500 Size: 121 Object: Hidden Code [Driver: usbstor, IRP_MJ_WRITE] Process: System Address: 0x852b0500 Size: 121 Object: Hidden Code [Driver: usbstor, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x852b0500 Size: 121 Object: Hidden Code [Driver: usbstor, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x852b0500 Size: 121 Object: Hidden Code [Driver: usbstor, IRP_MJ_POWER] Process: System Address: 0x852b0500 Size: 121 Object: Hidden Code [Driver: usbstor, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x852b0500 Size: 121 Object: Hidden Code [Driver: usbstor, IRP_MJ_PNP] Process: System Address: 0x852b0500 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE] Process: System Address: 0x859e81f8 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE] Process: System Address: 0x859e81f8 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x859e81f8 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x859e81f8 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER] Process: System Address: 0x859e81f8 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x859e81f8 Size: 121 Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP] Process: System Address: 0x859e81f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE] Process: System Address: 0x865691f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ] Process: System Address: 0x865691f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE] Process: System Address: 0x865691f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x865691f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x865691f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x865691f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN] Process: System Address: 0x865691f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP] Process: System Address: 0x865691f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER] Process: System Address: 0x865691f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x865691f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP] Process: System Address: 0x865691f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE] Process: System Address: 0x854c41f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE] Process: System Address: 0x854c41f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x854c41f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x854c41f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP] Process: System Address: 0x854c41f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP] Process: System Address: 0x854c41f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE] Process: System Address: 0x85a8a1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE] Process: System Address: 0x85a8a1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x85a8a1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x85a8a1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER] Process: System Address: 0x85a8a1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x85a8a1f8 Size: 121 Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP] Process: System Address: 0x85a8a1f8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA] Process: System Address: 0x857d44d8 Size: 121 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP] Process: System Address: 0x857d44d8 Size: 121 ==EOF== ![]() edit: firefox neu installiert, läuft trotzdem nicht. IE auch nicht... Geändert von Feitan (20.01.2010 um 18:37 Uhr) |
![]() | #2 | |
![]() ![]() ![]() ![]() | ![]() Firefox leitet ungewollt um, Antivirenprogramme werden blockiert Wieder nichts... Ok, wir haben da noch diesen Registryeintrag im Nacken, erstmal den weg. Speichere bitte die Datei aus dem Anhang auf dem Desktop und führe sie mit Doppelklick aus, Abfrage bestätigen. Die Datei kann danach gelöscht werden. Nu gut, versuchen wir es mit der "Schwarm-Intelligenz", vielleicht ist sie schlauer als ich. Überprüfe deinen Rechner mit PrevX. Falls etwas gefunden wird, kann man mit Tools -> Save Scan Result einen Log erstellen. Allerdings wird dort alles geloggt, was zu viel ist. Die Funde stehen normalerweise in den ersten paar Zeilen, poste diese bitte hier. Zitat:
![]() |
![]() | #3 |
![]() ![]() | ![]() Firefox leitet ungewollt um, Antivirenprogramme werden blockiert Die reg-Datei will nicht.
__________________"...\regi.reg kann nicht importiert werden. Die angegebene Datei ist keine Registrierungsdatei. Registrierungsdateien können nur innerhalb des Registrierungseditors importiert werden." Soll ich das andere Programm trotzdem schon ausführen? Oh, das ist ja das Netbook, was befallen ist. Ich benutze grad einen anderen Rechner und ziehe die Programme und logs per USB-Stick hin und her... oder ist das irgendwie falsch? |
![]() | #4 | |
![]() ![]() ![]() ![]() | ![]() Firefox leitet ungewollt um, Antivirenprogramme werden blockiert Hech, ich hab's irgendwie mit diesen .reg Dateien. Im Anhang ist eine neue. Zitat:
![]() |
![]() | #5 |
![]() ![]() | ![]() Firefox leitet ungewollt um, Antivirenprogramme werden blockiert Das sind dann die [B]-Dateien? Code:
ATTFilter Prevx Scan Log - Version v3.0.5.50 Log Generated: 20/1/2010 23:43, Type: 0,1 Windows XP Home Service Pack 3 (Build 2600) 32bit|1031 Hostname: NAME-V5T2TIMFKD Some non-malicious files are not included in this log. Heuristics Settings: Age: 1, Pop: 1, Heu: 2 (Dir: 1) Last Scan: Wed 2010-01-20 23:42:04 Westeuropäische Normalzeit. Number of Scans: 1. Last Scan Duration: 13 minutes 10 seconds. [B] c:\dokumente und einstellungen\gina\desktop\microsoft office 2007 portable german\microsoft office word 2007.exe [PX5: A1C468BDE7F3AB0AD75D00C7B027FA009BFE29FF] Malware Group: High Risk Cloaked Malware [B] c:\dokumente und einstellungen\gina\desktop\microsoft office 2007 portable german\microsoft office picture manager.exe [PX5: 6CC4FB33D537533D8FD00006D5E61E00BDEEC5E3] Malware Group: High Risk Cloaked Malware |
![]() | #6 |
![]() ![]() ![]() ![]() | ![]() Firefox leitet ungewollt um, Antivirenprogramme werden blockiert Wenn es sonst nichts angezeigt wurde, nachdem der Scan fertig war, dann sind sie es. Lade bitte diese zwei Dateien bei VirusTotal hoch, und poste die Links zu den Ergebnissen. Sieht mir so ein bisschen nach falschen Alarmen aus... |
![]() | #7 |
![]() ![]() ![]() ![]() | ![]() Firefox leitet ungewollt um, Antivirenprogramme werden blockiert Und benenne die Dateien bitte um, bevor du sie auf den anderen Rechner schleppst, also z.B. microsoft office word 2007.exe.vir |
![]() |
Themen zu Firefox leitet ungewollt um, Antivirenprogramme werden blockiert |
asus, avira, blockiert, dateien, firefox, hijack, hijackthis, hintergrund, home, installation, javaupdate, langsam, leitet, malware, malwarebytes, musik, nicht öffnen, programme, registerkarte, rootkit, sehr langsam, seite, seiten, sekunden, system, warning, windows, windows xp |