hitmanpro log:
Code:
Alles auswählen Aufklappen ATTFilter
Code:
Alles auswählen Aufklappen ATTFilter
HitmanPro 3.7.15.281
www.hitmanpro.com
Computer name . . . . : DRDRAVEN
Windows . . . . . . . : 6.3.0.9600.X64/4
User name . . . . . . : DRDRAVEN\mohsin
UAC . . . . . . . . . : Enabled
License . . . . . . . : Trial (11 days left)
Scan date . . . . . . : 2017-01-25 15:55:08
Scan mode . . . . . . : Normal
Scan duration . . . . : 8m 52s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : Yes
Threats . . . . . . . : 3
Traces . . . . . . . : 117
Objects scanned . . . : 2.172.369
Files scanned . . . . : 78.761
Remnants scanned . . : 683.980 files / 1.409.628 keys
Malware _____________________________________________________________________
C:\Program Files\Farming Simulator 17\x64\steam_api64.dll -> PendingDelete
Size . . . . . . . : 1.694.212 bytes
Age . . . . . . . : 64.9 days (2016-11-21 17:07:09)
Entropy . . . . . : 7.6
SHA-256 . . . . . : F710714481D626AA5872EDA2542AC90F0587DED91A8A8B92FC84011DA830F9FE
> Bitdefender . . . : Application.Crack.PEW
Fuzzy . . . . . . : 116.0
C:\Users\mohsin\AppData\Local\Microsoft\Windows\INetCache\IE\07K7D63W\Launcher[1].dll -> Quarantined
Size . . . . . . . : 527.360 bytes
Age . . . . . . . : 4.7 days (2017-01-20 22:23:01)
Entropy . . . . . : 6.6
SHA-256 . . . . . : E58EE4B95374D066135A104C0B707235BA0C9420737CC3231A3D60412F67AD98
> Bitdefender . . . : Gen:Variant.Graftor.275001
Fuzzy . . . . . . : 108.0
Forensic Cluster
-1.4s C:\Users\mohsin\Downloads\Settings.dat
0.0s C:\Users\mohsin\AppData\Local\Microsoft\Windows\INetCache\IE\07K7D63W\Launcher[1].dll
C:\Users\mohsin\Downloads\Launcher.dll -> Quarantined
Size . . . . . . . : 527.360 bytes
Age . . . . . . . : 4.7 days (2017-01-20 22:20:54)
Entropy . . . . . : 6.6
SHA-256 . . . . . : E58EE4B95374D066135A104C0B707235BA0C9420737CC3231A3D60412F67AD98
> Bitdefender . . . : Gen:Variant.Graftor.275001
Fuzzy . . . . . . : 108.0
Forensic Cluster
0.0s C:\Users\mohsin\Downloads\Launcher.dll
0.6s C:\Users\mohsin\Downloads\EAITFE.dll
1.0s C:\Users\mohsin\Downloads\ctb.dat
Suspicious files ____________________________________________________________
C:\Users\mohsin\Downloads\FRST64.exe
Size . . . . . . . : 2.420.736 bytes
Age . . . . . . . : 0.1 days (2017-01-25 14:09:58)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 945C56ADCD33C43D4D6954E99B4427C92C0528C797B08783CD9BE3E9D95A5299
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Forensic Cluster
0.0s C:\Users\mohsin\Downloads\FRST64.exe
1.1s C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_009595
1.4s C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_009596
1.4s C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_009597
1.4s C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_009598
2.9s C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00959b
Cookies _____________________________________________________________________
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:137852403.log.optimizely.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:abmr.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:acxiom-online.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.360yield.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.turn.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad2.adfarm1.adition.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad4.adfarm1.adition.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:adaptv.advertising.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:adbrn.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:addthis.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:adfarm1.adition.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:adform.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:adingo.jp
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:adnxs.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.creative-serving.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.linkedin.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.programattik.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.smartstream.tv
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.stickyadstv.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:adscale.de
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:adsrvr.org
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:adsymptotic.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtech.de
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtechjp.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:adx.adform.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:agkn.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:angsrvr.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:atemda.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:bidr.io
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:bidswitch.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:bluekai.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:c.appier.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:cdn.taboola.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:chango.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:connexity.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:contextweb.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:crwdcntrl.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:de17a.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:default.atemda.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:demdex.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:des.smartclip.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:dotomi.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:dpm.demdex.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:dsp.linksynergy.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ebayinc.demdex.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:emjcd.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:erne.co
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:everesttech.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:eyeviewads.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:flashtalking.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:gssprt.jp
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:gwallet.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ibillboard.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ih.adscale.de
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:imrworldwide.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ipredictive.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:krxd.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:lijit.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:linksynergy.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:m6r.eu
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:match.adsby.bidtheatre.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:match.rundsp.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:mathtag.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:metrigo.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ml314.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:mookie1.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:nexac.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:openx.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:optimizely.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:outbrain.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:owneriq.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:pixel.rubiconproject.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:po.st
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:pool.admedo.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:pubmatic.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:revsci.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:rfihub.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:rlcdn.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ru4.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:rubiconproject.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:rvty.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:scorecardresearch.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:simpli.fi
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:sitescout.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:skimresources.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:smartadserver.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:stags.bluekai.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:stat.media
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:stats.paypal.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:sxp.smartclip.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:taboola.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:tap-t.rubiconproject.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:tap2-cdn.rubiconproject.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:tidaltv.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.adform.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:trc.taboola.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:tremorhub.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:tubemogul.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:turn.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:univide.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:visualdna.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:w55c.net
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:wtp101.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:ww251.smartadserver.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.googleadservices.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:www8.smartadserver.com
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:yadro.ru
C:\Users\mohsin\AppData\Local\Google\Chrome\User Data\Default\Cookies:yieldlab.net