![]() |
|
Plagegeister aller Art und deren Bekämpfung: Malware auch über File PonyWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #28 |
![]() ![]() ![]() | ![]() Malware auch über File Pony Hi, sieht auf den ersten Blick gut aus. Warnung zu crystal disk kam jetzt nicht mehr. Ich hab wohl eine Zeile vergessen! siehe hier: C:\Users\\Downloads\CrystalDiskInfo*.exe Sorry, mein Fehler - wenn es wichtig ist; vielleicht ist es ja korrigierbar. Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 07-09-2014 Ran by xxxxxxxxxxxxx at 2014-09-08 15:06:54 Run:3 Running from C:\Users\xxxxxxxxxxxxx\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** start R2 OkayFreedom VPN Starter Service; C:\Program Files\OkayFreedom\OkayFreedomService.exe [318304 2014-04-09] (Steganos Software GmbH) C:\Program Files\OkayFreedom C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OkayFreedom C:\Users\xxxxxxxxxxxxx\Public\Desktop\OkayFreedom.lnk C:\Users\xxxxxxxxxxxxx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\OkayFreedom.lnk C:\Users\xxxxxxxxxxxxx\AppData\Roaming\Steganos VPN C:\Users\xxxxxxxxxxxxx\Downloads\okayfreedom*.exe C:\Program Files\CrystalDiskInfo C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo C:\Users\\Downloads\CrystalDiskInfo*.exe DeleteKey: HKEY_CURRENT_USER\Software\Steganos DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OkayFreedomClient.exe DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F3FB10C-7175-4D38-9335-3488B89C12AF} DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Steganos DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CrystalDiskInfo_is1 DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3C572D1-0819-46D4-AF31-EA9C649FD127} Task: {6E0D43EB-3061-4159-836A-0A0F66220D33} - System32\Tasks\{203449C6-FF10-4581-9FD5-0AF4416BCD8C} => C:\Program Files\OkayFreedom\OkayFreedomClient.exe [2014-04-09] (Steganos Software GmbH) Task: {C3C572D1-0819-46D4-AF31-EA9C649FD127} - System32\Tasks\CrystalDiskInfo => C:\Program Files\CrystalDiskInfo\DiskInfo.exe [2013-04-21] (Crystal Dew World) Task: {CAFB1298-1C49-4861-A5B4-6DAAA93A64E3} - System32\Tasks\{BCC6FFC3-7EC5-4AEB-8724-2A53C39C0135} => C:\Program Files\OkayFreedom\OkayFreedomClient.exe [2014-04-09] (Steganos Software GmbH) Reboot: end ***************** OkayFreedom VPN Starter Service => Service stopped successfully. OkayFreedom VPN Starter Service => Service deleted successfully. C:\Program Files\OkayFreedom => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OkayFreedom => Moved successfully. "C:\Users\xxxxxxxxxxxxx\Public\Desktop\OkayFreedom.lnk" => File/Directory not found. C:\Users\xxxxxxxxxxxxx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\OkayFreedom.lnk => Moved successfully. C:\Users\xxxxxxxxxxxxx\AppData\Roaming\Steganos VPN => Moved successfully. C:\Users\xxxxxxxxxxxxx\Downloads\okayfreedom*.exe => Moved successfully. C:\Program Files\CrystalDiskInfo => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo => Moved successfully. "C:\Users\\Downloads\CrystalDiskInfo*.exe" => File/Directory not found. HKEY_CURRENT_USER\Software\Steganos => Failed to delete key at first attempt (Error: C0000121), see next line. HKEY_CURRENT_USER\Software\Steganos => Key Deleted Successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OkayFreedomClient.exe => Key Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3F3FB10C-7175-4D38-9335-3488B89C12AF} => Key Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Steganos => Failed to delete key at first attempt (Error: C0000121), see next line. HKEY_LOCAL_MACHINE\SOFTWARE\Steganos => Key Deleted Successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CrystalDiskInfo_is1 => Key Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3C572D1-0819-46D4-AF31-EA9C649FD127} => Key Deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6E0D43EB-3061-4159-836A-0A0F66220D33}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6E0D43EB-3061-4159-836A-0A0F66220D33}" => Key deleted successfully. C:\Windows\System32\Tasks\{203449C6-FF10-4581-9FD5-0AF4416BCD8C} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{203449C6-FF10-4581-9FD5-0AF4416BCD8C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C3C572D1-0819-46D4-AF31-EA9C649FD127}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3C572D1-0819-46D4-AF31-EA9C649FD127}" => Key not found. C:\Windows\System32\Tasks\CrystalDiskInfo => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CrystalDiskInfo" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CAFB1298-1C49-4861-A5B4-6DAAA93A64E3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CAFB1298-1C49-4861-A5B4-6DAAA93A64E3}" => Key deleted successfully. C:\Windows\System32\Tasks\{BCC6FFC3-7EC5-4AEB-8724-2A53C39C0135} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BCC6FFC3-7EC5-4AEB-8724-2A53C39C0135}" => Key deleted successfully. The system needed a reboot. ==== End of Fixlog ==== |