Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
mensch ich seh nix, alles ist schwarz...sag mir, in welchem ordner ich den log finde
was soll ich in das cmd fenster eingeben?
malwarebytes hat nix gefunden, ich hab vorhin schon alleine damit gescannt, meine tools werdens eit jahren gefunden und ich ignorirer sie. Es springt auf diesen kack nicht an.
sorry aber erst war hier alles schwarz und danach hab ich hier mehrer ordner mit Malwarebytes, alle, die ich angesammelt hab im laufe der zeit...so, windows tool wurde gelöscht und der neue scan ist sauber....aber ich glaub nicht, das hier alles sauber ist.
Scan started
Database versions:
main: v2017.10.19.07
rootkit: v2017.10.14.01
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 41193005
Partition information:
Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 324550656
Partition is bootable
Partition file system is NTFS
Partition 1 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 324552704 Numsec = 115001712
Partition is not bootable
Partition file system is NTFS
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Disk Size: 250059350016 bytes
Sector size: 512 bytes
Partition 0 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 4208640 Numsec = 439554416
Partition is not bootable
Partition file system is NTFS
Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Disk Size: 250059350016 bytes
Sector size: 512 bytes
Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 163840000
Partition is not bootable
Partition file system is NTFS
Partition 1 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 163842048 Numsec = 163840000
Partition is not bootable
Partition file system is NTFS
Partition 2 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 327682048 Numsec = 642797568
Partition is not bootable
Partition file system is NTFS
Partition 3 type is Extended with LBA (0xf)
Partition is NOT ACTIVE.
Partition starts at LBA: 970479616 Numsec = 983042048
Partition is not bootable
Disk Size: 1000204886016 bytes
Sector size: 512 bytes
Done!
Infected: C:\Users\No TRound\Documents\Windows 7 Activation.exe --> [HackTool.WinActivator]
Infected: C:\Users\No TRound\USB INHALTE+\Windows 7 Activation.exe --> [HackTool.WinActivator]
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.7C" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.83" is compressed (flags = 1)
Infected: C:\Users\No TRound\Documents\Classified.exe --> [Worm.Daprosy]
Scan finished
Creating System Restore point...
Cleaning up...
Removal successful. No system shutdown is required.
=======================================
Scan started
Database versions:
main: v2017.10.19.07
rootkit: v2017.10.14.01
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 41193005
Partition information:
Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 324550656
Partition is bootable
Partition file system is NTFS
Partition 1 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 324552704 Numsec = 115001712
Partition is not bootable
Partition file system is NTFS
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Disk Size: 250059350016 bytes
Sector size: 512 bytes
Done!
Drive 1
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 93700
Partition information:
Partition 0 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 4208640 Numsec = 439554416
Partition is not bootable
Partition file system is NTFS
Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Disk Size: 250059350016 bytes
Sector size: 512 bytes
Done!
Drive 2
Scanning MBR on drive 2...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 958F9EB0
Partition information:
Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 163840000
Partition is not bootable
Partition file system is NTFS
Partition 1 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 163842048 Numsec = 163840000
Partition is not bootable
Partition file system is NTFS
Partition 2 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 327682048 Numsec = 642797568
Partition is not bootable
Partition file system is NTFS
Partition 3 type is Extended with LBA (0xf)
Partition is NOT ACTIVE.
Partition starts at LBA: 970479616 Numsec = 983042048
Partition is not bootable
Disk Size: 1000204886016 bytes
Sector size: 512 bytes
Partition 0 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 256 Numsec = 976751744
Partition is not bootable
Partition file system is NTFS
Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Disk Size: 4000787013632 bytes
Sector size: 4096 bytes
Done!
Infected: C:\Users\No TRound\USB INHALTE+\Windows 7 Activation.exe --> [HackTool.WinActivator]
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.7C" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.83" is compressed (flags = 1)
Scan finished
Creating System Restore point...
Cleaning up...
Removal scheduling successful. System shutdown needed.
System shutdown occurred
=======================================
Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 324550656
Partition is bootable
Partition file system is NTFS
Partition 1 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 324552704 Numsec = 115001712
Partition is not bootable
Partition file system is NTFS
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Disk Size: 250059350016 bytes
Sector size: 512 bytes
Partition 0 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 4208640 Numsec = 439554416
Partition is not bootable
Partition file system is NTFS
Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Disk Size: 250059350016 bytes
Sector size: 512 bytes
Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 163840000
Partition is not bootable
Partition file system is NTFS
Partition 1 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 163842048 Numsec = 163840000
Partition is not bootable
Partition file system is NTFS
Partition 2 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 327682048 Numsec = 642797568
Partition is not bootable
Partition file system is NTFS
Partition 3 type is Extended with LBA (0xf)
Partition is NOT ACTIVE.
Partition starts at LBA: 970479616 Numsec = 983042048
Partition is not bootable
Disk Size: 1000204886016 bytes
Sector size: 512 bytes
Done!
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.79" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.7C" is compressed (flags = 1)
File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-B3C69CAF57C7A72C332A009AC3F5FB79AF8F9F44.bin.83" is compressed (flags = 1)
Scan finished
Physical Sectors Detected: 0
(No malicious items detected)
(end)
auf die schnelle beim googlen wird vor dem windows sound.teil gewarnt und dort wird auch erwähnt, dass das teil schlecht/kaum gefunden wird...und warum hab ich schwarzen bildschirm mit cmd? War das vielleicht ein nicht geglückter Krypto-dingbums in dem ich hätte das passwort eingeben sollen?
Ich hab ne idee wo das ding her sein könnte aber wichtig ist ja ich glaub nicht das alles ok ist oder wie siehst du das?
Installiere Windows neu und fertig. Illegale Windows-Installationen werden hier eh nicht supportet. Völlig egal ob da was sauber ist oder nicht. Illegal ist illegal.
Tu dir einen Gefallen und nimm gleich Windows 10, Anleitung für die Neuinstallation gibt es hier im Anleitungsbereich.
__________________ Logfiles bitte immer in CODE-Tags posten
das ding soll angebich ein miner sein, trotzdem wäre es mal interessant, was dazu zu sagen, damit man schlauer wird.
na toll das hab ich jetzt davon, dass ich so blöd bin und auf Nachfrage den screenshot vom windows activator poste obwohl ich ganz genau weiss, dass das teil nichts damit zu tun hat. Super Hilfe. Danke dann auch ganz dolle.
Hier gibts generell keine Hilfe wenn wir hier mitbekommen, dass das Windows gecrackt ist. Wenn es nur ein gecracktes Spiel oder Programm wäre, das hättest du deinstallieren können.
Wenn du kein Geld für ne Betriebssystem-Lizenz ausgeben willst, musst du sowas wie Ubuntu MATE verwenden...
__________________ Logfiles bitte immer in CODE-Tags posten