Zadejte hledaný výraz...

Pomoc s vírusom/??

maybe8
verified
rating uzivatele
5. 6. 2012 15:28:09
Zdravím, potreboval by som pomoc
ospravedlňujem neviem kam som to mal dať..
problém:
otvorím prehliadač(ktorýkoľvek) a skoro na každej druhej stránke sa mi zobrazí reklama..
vyzerá nejak takto:
http://imgupload.sk/viewer.php?file=0ccqevbzo11sjvx9m7ak.png
proste v pravom dolnom rohu je reklama(dá sa aj zavrieť)
odkiaľ sa tam berie naozaj neviem
nemôžem sa dopátrať či to ide cez nejaký program(vírus) alebo ako preskúmal som prvok smeruje to sem - resp. do skoro každej stránky pridá tento kód
to vygeneruje rôzne veci ako aj tento iframe
fakt si neviem rady čo s tým lebo je to dosť otravné
nestalo sa to už niekomu?
ďakujem za pomoc
5. 6. 2012 15:28:09
https://webtrh.cz/diskuse/pomoc-s-virusom#reply771908
Obrať se sem - forum.viry.cz, tam ti pomohou. Pravděpodobně to bude nějaký trojan. Každopádně pořídit si antivirus a přestat chodit na neznámé warez/porno stránky.
5. 6. 2012 16:14:38
https://webtrh.cz/diskuse/pomoc-s-virusom#reply771907
BjornR1989
verified
rating uzivatele
2. 7. 2012 13:33:02
*I just registered to be able to reply to this post.*
Problem as described by client:
"Cannot go to Google"
Problem according to Google Chrome webbrowser:
"105 ERR_NAME_NOT_RESOLVED, cannot resolve DNS for google.com" (or anything with Google in it for that matter)
Note that every other website seems to work just fine.
Wireshark shows outgoing DNS queries to all configured DNS servers but each one of them returns an ICMP 70 Destination unreachable (Port unreachable) message and i don't really know why.
I know my network and DNS is good.
Example of the malicious code:
Iframe HTML:
From my findings these ads are indeed loaded in an iframe which is somehow injected after a webpage is loaded.
It seems to only be shown on websites with Google Analytics.
The path to the Javascript file of Google Analytics is http://google-analytics.com/ga.js BUT on an (if i can call it this way) infected system the contents of this file differ from the "real" GA JS file.
I myself am at the moment trying to find out what causes this to happen.
The HTTP request for ga.js is sent to a server located at 77.125.87.149 which does NOT resolve to the GA domain but (apparantly) somewhere in Israel.
** update: This "media network" or call it an "advertising network" named TLVMedia is located at Haarbaa 21, 64739 Jaffa-Tel Aviv, Tel Aviv, Israel
** Why would they fake GA? To force ads on people?
Update: Reverted to an old system restore point, Avast suddenly blocked all Google sites.
Update: In one of the posts on http://forum.avast.com/index.php?topic=96836.0 a program called tdsskiller is offered. Download it here from the Kaspersky website: http://support.kaspersky.com/downloads/utils/tdsskiller.exe
I ran Kaspersky anti-rootkit software, it found four threats of which one was high risk, let's see if it solved it.
Kaspersky TDSSKiller detected Rloader.a in Wdf01000.sys
It did!
The ads are gone and the pc seems to work much faster again.
Though this post is getting older by the day, i'll post updates for as long as i have patience in examining this.
2. 7. 2012 13:33:02
https://webtrh.cz/diskuse/pomoc-s-virusom#reply771906
McFly
verified
rating uzivatele
(4 hodnocení)
2. 7. 2012 16:48:19
Good job, BjornR1989 ;-)
2. 7. 2012 16:48:19
https://webtrh.cz/diskuse/pomoc-s-virusom#reply771905
rpet
verified
rating uzivatele
(1 hodnocení)
3. 7. 2012 19:11:22
yeah... very professional job, Bjorn... btw how did you reading content in our language?? -:)
3. 7. 2012 19:11:22
https://webtrh.cz/diskuse/pomoc-s-virusom#reply771904
BjornR1989
verified
rating uzivatele
7. 7. 2012 00:14:59
Thanks but in the end the solution was out there on a forum and Google found it for me.
I don't think i would have found the cause of the problem by myself.
Thanks go out to the people at Kaspersky.
@rpet:
I did not understand what was written here and only reached this page by searching for the exact code as posted.
Machine translation isn't what it should be but thanks to it, the first message made much more sense to me.
Try it: http://translate.google.com
7. 7. 2012 00:14:59
https://webtrh.cz/diskuse/pomoc-s-virusom#reply771903
rpet
verified
rating uzivatele
(1 hodnocení)
7. 7. 2012 10:42:41
cheers man ;) but i don't need it... for me is better learn language 'on the street'... :D
7. 7. 2012 10:42:41
https://webtrh.cz/diskuse/pomoc-s-virusom#reply771902
krnac
verified
rating uzivatele
(14 hodnocení)
7. 7. 2012 10:54:54
I can know what the software from Kaspersky?
7. 7. 2012 10:54:54
https://webtrh.cz/diskuse/pomoc-s-virusom#reply771901
TLV Media
verified
rating uzivatele
9. 7. 2012 08:10:22
Hello guys, following Bjorn's good job looking at this, it seems that one of our media partners is abusing our ad system, resulting in pop-up ads or injected ads to appear on your PC . You may have recently installed or downloaded an abusive software that causes this nuisance, and we'd like to help you get rid of it. In order to block these ads from appearing, please send us any information that can help identify the source, such as the URL you see on the ads or the name of any software you've recently installed. You can send info to contact@tlvmedia.com
We apologize for your inconvenience and will do our best to resolve this quickly. In the meantime, programs such as Bjorn recommended can help remove the unwanted ads. Thanks, TLV Media
9. 7. 2012 08:10:22
https://webtrh.cz/diskuse/pomoc-s-virusom#reply771900
Pro odpověď se přihlašte.
Přihlásit