Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
Unzählige Pop-up-Fenster wollen sich öffnen und netutils-Problem
Code:
ATTFilter
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 14-01-2017
durchgeführt von Fabsn (14-01-2017 22:34:13) Run:2
Gestartet von C:\Users\Fabsn\Desktop
Geladene Profile: Fabsn (Verfügbare Profile: Albert & Sandra & Fabsn)
Start-Modus: Normal
==============================================
fixlist Inhalt:
*****************
start
CloseProcesses:
C:\WINDOWS\system32\sstmp
C:\WINDOWS\SysWOW64\sstmp
C:\WINDOWS\rsrcs.dll
EmptyTemp:
end
*****************
Prozess erfolgreich geschlossen.
C:\WINDOWS\system32\sstmp => erfolgreich verschoben
C:\WINDOWS\SysWOW64\sstmp => erfolgreich verschoben
C:\WINDOWS\rsrcs.dll => erfolgreich verschoben
=========== EmptyTemp: ==========
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9120258 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 6450 B
Edge => 0 B
Chrome => 0 B
Firefox => 10125616 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 128 B
LocalService => 5714 B
NetworkService => 0 B
TEMP => 0 B
Albert => 0 B
Sandra => 0 B
Fabsn => 4151368 B
RecycleBin => 0 B
EmptyTemp: => 22.3 MB temporäre Dateien entfernt.
================================
Das System musste neu gestartet werden.
==== Ende von Fixlog 22:34:18 ====
HitmanPro 3.7.15.281
www.hitmanpro.com
Computer name . . . . : DESKTOP-G05R34I
Windows . . . . . . . : 10.0.0.14393.X64/4
User name . . . . . . : DESKTOP-G05R34I\Fabsn
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free
Scan date . . . . . . : 2017-01-15 00:46:51
Scan mode . . . . . . : Normal
Scan duration . . . . : 5m 44s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 0
Traces . . . . . . . : 6
Objects scanned . . . : 1.984.097
Files scanned . . . . : 73.830
Remnants scanned . . : 690.032 files / 1.220.235 keys
Suspicious files ____________________________________________________________
C:\Users\Fabsn\Desktop\FRST-OlderVersion\FRST64.exe
Size . . . . . . . : 2.419.200 bytes
Age . . . . . . . : 5.3 days (2017-01-09 17:37:17)
Entropy . . . . . : 7.6
SHA-256 . . . . . : FA3DF823E5B6D52B2361EF2FDE0F3343F9916D08B3C1C47DBFA436A6C932738D
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
C:\Users\Fabsn\Desktop\FRST64.exe
Size . . . . . . . : 2.419.200 bytes
Age . . . . . . . : 0.1 days (2017-01-14 22:33:05)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 54E26DD548EF617005D204C0386E42B3E4060C26C52F21C6F6307273FBB93F5B
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
C:\Users\Fabsn\Downloads\FRST64(1).exe
Size . . . . . . . : 2.419.200 bytes
Age . . . . . . . : 4.3 days (2017-01-10 17:37:43)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 0B4E2E914C2BE30FF539A204F1BE480058F1BDAAE2483C0C960EB4A2CFAA2C4A
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
C:\Windows\System32\DriverStore\FileRepository\c0309270.inf_amd64_47c09dd18e1ee4c5\atidxx32.dll
Size . . . . . . . : 11.017.760 bytes
Age . . . . . . . : 38.1 days (2016-12-07 23:22:50)
Entropy . . . . . : 6.2
SHA-256 . . . . . : B473A31619BC479CD436C7323E534FF02F0439D2F23438DDBA36A94B71E9BD77
Product . . . . . : Advanced Micro Devices, Inc. Radeon DirectX 11 Driver
Publisher . . . . : Advanced Micro Devices, Inc.
Description . . . : atidxx32.dll
Version . . . . . : 8.17.10.0708
Copyright . . . . : Copyright (C) 1998-2011 AMD Inc.
RSA Key Size . . . : 1024
LanguageID . . . . : 1033
Authenticode . . . : Invalid
Fuzzy . . . . . . : 22.0
Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
The file is in use by one or more active processes.
Potential Unwanted Programs _________________________________________________
HKLM\SOFTWARE\Classes\CLSID\{35F4BB37-03C5-41DE-85AF-7C301390C7EC}\ (ContentProtector)
Themen zu Unzählige Pop-up-Fenster wollen sich öffnen und netutils-Problem
Zum Thema Unzählige Pop-up-Fenster wollen sich öffnen und netutils-Problem - Code:
Alles auswählen Aufklappen ATTFilter
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 14-01-2017
durchgeführt von Fabsn (14-01-2017 22:34:13) Run:2
Gestartet von C:\Users\Fabsn\Desktop
Geladene Profile: Fabsn (Verfügbare Profile: Albert & - Unzählige Pop-up-Fenster wollen sich öffnen und netutils-Problem...