Das ist der Log von heute. Die ganze Datei kann ich leider nicht anhängen, da es viel zu groß ist. Hier wird anscheinend vom ersten Scan bis zum letzten Scan immer alles gespeichert. Code:
2016-05-29T13:30:50.942Z initialized!
Signature updated on 05-29-2016 15:30:50
Product Version: 4.9.10586.0
Service Version: 4.9.10586.0
Engine Version: 1.1.12805.0
AS Signature Version: 1.223.133.0
AV Signature Version: 1.223.133.0
************************************************************
Signature updated via MicrosoftUpdateServer on 05-29-2016 15:30:50
************************************************************
2016-05-29T13:30:51.161Z Process scan (postsignatureupdatescan) started.
2016-05-29T13:30:52.958Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1)
2016-05-29T13:30:52.958Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1)
2016-05-29T13:30:59.662Z Process scan (postsignatureupdatescan) completed.
2016-05-29T13:33:18.657Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1)
2016-05-29T13:33:18.657Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1)
Internal signature match:subtype=Lowfi, sigseq=0x0000157E87DF6C52, signame=ALF:Lowfi:Win32/Bagsu!rfn, cached=false, resource="\\?\C:\Program Files (x86)\ASUS\GPU Tweak\LiveUpdate.dll"
Internal signature match:subtype=Lowfi, sigseq=0x00000555691EDDBB, signame=#Lowfi:RPF:OpclogClassifier:95, cached=false, resource="\\?\C:\Program Files (x86)\NETTV4\NetTV+Player4.exe->(UPX)->(VFS:b2e.exe)"
Internal signature match:subtype=Lowfi, sigseq=0x00000555691EDDBB, signame=#Lowfi:RPF:OpclogClassifier:95, cached=false, resource="\\?\C:\Program Files (x86)\NETTV4\NetTV+Player4.exe->(UPX)->(VFS:b2e.exe)"
Internal signature match:subtype=Lowfi, sigseq=0x00000555691EDDBB, signame=#Lowfi:RPF:OpclogClassifier:95, cached=true, resource="\\?\C:\Program Files (x86)\NETTV4\NetTV+Player4.exe->(UPX)->(VFS:b2e.exe)"
Internal signature match:subtype=Lowfi, sigseq=0x00000555691EDDBB, signame=#Lowfi:RPF:OpclogClassifier:95, cached=true, resource="\\?\C:\Program Files (x86)\NETTV4\NetTV+Player4.exe->(UPX)->(VFS:b2e.exe)"
Internal signature match:subtype=Lowfi, sigseq=0x00000555691EDDBB, signame=#Lowfi:RPF:OpclogClassifier:95, cached=true, resource="\\?\C:\Program Files (x86)\NETTV4\NetTV+Player4.exe->(UPX)->(VFS:b2e.exe)"
Dynamic Signature has been received
Dynamic Signature Type:Signature Update
Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f66e77578602bb77526c8524edf1bb748e33d91a
Dynamic Signature Compilation Timestamp:05-29-2016 15:41:48
Persistence Type:VDM Version
Source Version:282432763133953
Expiration Version:282432763133953
2016-05-29T13:41:47.652Z Dynamic signature received
Internal signature match:subtype=Lowfi, sigseq=0x0000157E87DF6C52, signame=ALF:Lowfi:Win32/Bagsu!rfn, cached=false, resource="\\?\C:\Program Files (x86)\ASUS\GPU Tweak\LiveUpdate.dll"
Internal signature match:subtype=Lowfi, sigseq=0x00000555691EDDBB, signame=#Lowfi:RPF:OpclogClassifier:95, cached=false, resource="\\?\C:\Program Files (x86)\NETTV4\NetTV+Player4.exe->(UPX)->(VFS:b2e.exe)"
Internal signature match:subtype=Lowfi, sigseq=0x0000157E87DF6C52, signame=ALF:Lowfi:Win32/Bagsu!rfn, cached=false, resource="\\?\C:\Program Files (x86)\ASUS\GPU Tweak\LiveUpdate.dll"
Internal signature match:subtype=Lowfi, sigseq=0x0000157E87DF6C52, signame=ALF:Lowfi:Win32/Bagsu!rfn, cached=false, resource="\\?\C:\Program Files (x86)\ASUS\GPU Tweak\LiveUpdate.dll"
Internal signature match:subtype=Lowfi, sigseq=0x00000555691EDDBB, signame=#Lowfi:RPF:OpclogClassifier:95, cached=false, resource="\\?\C:\Program Files (x86)\NETTV4\NetTV+Player4.exe->(UPX)->(VFS:b2e.exe)"
Internal signature match:subtype=Lowfi, sigseq=0x0000157E87DF6C52, signame=ALF:Lowfi:Win32/Bagsu!rfn, cached=false, resource="\\?\C:\Program Files (x86)\ASUS\GPU Tweak\LiveUpdate.dll"
Internal signature match:subtype=Lowfi, sigseq=0x0000157E87DF6C52, signame=ALF:Lowfi:Win32/Bagsu!rfn, cached=false, resource="\\?\C:\Program Files (x86)\ASUS\GPU Tweak\LiveUpdate.dll"
Internal signature match:subtype=Lowfi, sigseq=0x00000555691EDDBB, signame=#Lowfi:RPF:OpclogClassifier:95, cached=false, resource="\\?\C:\Program Files (x86)\NETTV4\NetTV+Player4.exe->(UPX)->(VFS:b2e.exe)"
Internal signature match:subtype=Lowfi, sigseq=0x0000157E87DF6C52, signame=ALF:Lowfi:Win32/Bagsu!rfn, cached=false, resource="\\?\C:\Program Files (x86)\ASUS\GPU Tweak\LiveUpdate.dll"
2016-05-29T13:44:54.977Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1)
2016-05-29T13:44:54.981Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1)
Internal signature match:subtype=Lowfi, sigseq=0x00000555691EDDBB, signame=#Lowfi:RPF:OpclogClassifier:95, cached=false, resource="\\?\C:\Program Files (x86)\NETTV4\NetTV+Player4.exe->(UPX)->(VFS:b2e.exe)"
Internal signature match:subtype=Lowfi, sigseq=0x00000555691EDDBB, signame=#Lowfi:RPF:OpclogClassifier:95, cached=false, resource="\\?\C:\Program Files (x86)\NETTV4\NetTV+Player4.exe->(UPX)->(VFS:b2e.exe)"
Internal signature match:subtype=Lowfi, sigseq=0x0000157E87DF6C52, signame=ALF:Lowfi:Win32/Bagsu!rfn, cached=false, resource="\\?\C:\Program Files (x86)\ASUS\GPU Tweak\LiveUpdate.dll"
Internal signature match:subtype=Lowfi, sigseq=0x00000555691EDDBB, signame=#Lowfi:RPF:OpclogClassifier:95, cached=false, resource="\\?\C:\Program Files (x86)\NETTV4\NetTV+Player4.exe->(UPX)->(VFS:b2e.exe)"
Internal signature match:subtype=Lowfi, sigseq=0x0000157E87DF6C52, signame=ALF:Lowfi:Win32/Bagsu!rfn, cached=false, resource="\\?\C:\Program Files (x86)\ASUS\GPU Tweak\LiveUpdate.dll"
2016-05-29T13:45:25.686Z DETECTIONEVENT Trojan:Win32/Maltule.C!cl containerfile:C:\Program Files (x86)\NETTV4\NetTV+Player4.exe;file:C:\Program Files (x86)\NETTV4\NetTV+Player4.exe->(UPX)->(VFS:b2e.exe);file:C:\Users\m1ck3y\Desktop\Nettv+ Player 4.lnk;
2016-05-29T13:45:25.688Z DETECTION_ADD Trojan:Win32/Maltule.C!cl containerfile:C:\Program Files (x86)\NETTV4\NetTV+Player4.exe
2016-05-29T13:45:25.688Z DETECTION_ADD Trojan:Win32/Maltule.C!cl file:C:\Program Files (x86)\NETTV4\NetTV+Player4.exe->(UPX)->(VFS:b2e.exe)
2016-05-29T13:45:25.688Z DETECTION_ADD Trojan:Win32/Maltule.C!cl file:C:\Users\m1ck3y\Desktop\Nettv+ Player 4.lnk
Begin Resource Scan
Scan ID:{89585047-A1D5-4A5D-A075-60F52A562A9C}
Scan Source:7
Start Time:05-29-2016 15:41:47
End Time:05-29-2016 15:45:25
Explicit resource to scan
Resource Schema:file
Resource Path:C:\Users\m1ck3y\Desktop\Nettv+ Player 4.lnk
Explicit resource to scan
Resource Schema:queryfilertsig
Resource Path:C:\Program Files (x86)\ASUS\GPU Tweak\LiveUpdate.dll
Explicit resource to scan
Resource Schema:queryfilertsig
Resource Path:C:\Program Files (x86)\NETTV4\NetTV+Player4.exe->(UPX)->(VFS:b2e.exe)
Explicit resource to scan
Resource Schema:regkey
Resource Path:HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\SHAREDDLLS\\C:\Program Files (x86)\ASUS\GPU Tweak\LiveUpdate.dll
Explicit resource to scan
Resource Schema:shareddll
Resource Path:HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\SHAREDDLLS\\C:\Program Files (x86)\ASUS\GPU Tweak\LiveUpdate.dll
Result Count:3
Threat Name:Trojan:Win32/Maltule.C!cl
ID:2147709295
Severity:5
Number of Resources:3
Resource Schema:file
Resource Path:C:\Users\m1ck3y\Desktop\Nettv+ Player 4.lnk
Extended Info:0
Resource Schema:file
Resource Path:C:\Program Files (x86)\NETTV4\NetTV+Player4.exe->(UPX)->(VFS:b2e.exe)
Extended Info:42227756479049
Resource Schema:containerfile
Resource Path:C:\Program Files (x86)\NETTV4\NetTV+Player4.exe
Extended Info:0
Unknown File
Identifier:14841062229922545662
Number of Resources:1
Resource Schema:file
Resource Path:C:\Users\m1ck3y\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Extended Info:0
Unknown File
Identifier:8478281726672502782
Number of Resources:3
Resource Schema:regkey
Resource Path:HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\SHAREDDLLS\\C:\Program Files (x86)\ASUS\GPU Tweak\LiveUpdate.dll
Extended Info:0
Resource Schema:shareddll
Resource Path:HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\SHAREDDLLS\\C:\Program Files (x86)\ASUS\GPU Tweak\LiveUpdate.dll
Extended Info:0
Resource Schema:queryfilertsig
Resource Path:C:\Program Files (x86)\ASUS\GPU Tweak\LiveUpdate.dll
Extended Info:23633189629010
End Scan
************************************************************ |