Sie sind auf Seite 1von 12

Switches begin

Switches end
Starting v4.2.0.27
FBUserToken: '1527062570892468'
FBLocale: 'en_US'
FBAttackId: '601246363339485'
User is Admin: NO
Vista or Higher: YES
IsWow64: NO
GetWorkDir: C:\Users\hp\AppData\Local\Temp\FBScanner_078942607
Trying to start with Admin rights ...: Failed
InitReport
SendReport_Init
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_INIT",}&report_sig=BE40
D6EE5B9F256F5E45F79F4BD0B156&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
# product=FBAV
# version=8
# FBAV_user_token=1527062570892468
# FBAV_user_locale=en_US
# FBAV_attack_id=601246363339485
# FBAV_status=0
# flags=0
# ESET.exe=4.3.0.27
# EOSSerial=284cd12d71cdc74d8b3d939b65bf7620
# end=init
# utc_time=2015-01-24 21:54:10
# local_time=2015-01-25 03:24:10 (+0530, India Standard Time)
# country="United States"
# osver=6.1.7601 NT Service Pack 1
INIT report NOT sent to ESET
ExtractEsetsApi OK
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 0
,}&report_sig=2B743F651544C758D4C21A49EB3CF23E&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Updating
Update Init
Update Download
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 0
,}&report_sig=2B743F651544C758D4C21A49EB3CF23E&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
,}&report_sig=3DC900E65697E57238D5A919F32752B0&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
,}&report_sig=3DC900E65697E57238D5A919F32752B0&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 2

,}&report_sig=75A0CE906A36623A73C4ED76B6A0217A&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 3
,}&report_sig=3F8375609AB7F90439B42912269A53FD&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 3
,}&report_sig=3F8375609AB7F90439B42912269A53FD&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 4
,}&report_sig=4BFD76DD577F0A652BC5A263F1463DD6&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
,}&report_sig=B83D224A31F8D89576CEF0F835090260&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 6
,}&report_sig=6549E52B04F5AEF9EC9A5F5686A2AE29&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 7
,}&report_sig=FBACAFCD06E447A3452AD6479A1B4251&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
,}&report_sig=41DE667BE4B40B28EB51B069C37E545B&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 9
,}&report_sig=4240B5BB56D2736A78A996E9141278B3&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
0,}&report_sig=AC171CBE639BC332E608EF298CB67001&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
0,}&report_sig=AC171CBE639BC332E608EF298CB67001&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
1,}&report_sig=BCDB4B1E044BB807B717AF2307EE0CF5&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}

Request query: 1443300579261932/malware_scanner


Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
1,}&report_sig=BCDB4B1E044BB807B717AF2307EE0CF5&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
2,}&report_sig=EBDD954BFD00365A56399C4CE273139A&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
3,}&report_sig=866AF33B0280EA61B17A3A36D3449D78&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
3,}&report_sig=866AF33B0280EA61B17A3A36D3449D78&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
4,}&report_sig=65F462285C29B03D265EE11A1AC06AB6&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
5,}&report_sig=214BAC5B4A2FF8500EE94FF24946FD5C&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
5,}&report_sig=214BAC5B4A2FF8500EE94FF24946FD5C&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
5,}&report_sig=214BAC5B4A2FF8500EE94FF24946FD5C&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
5,}&report_sig=214BAC5B4A2FF8500EE94FF24946FD5C&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
6,}&report_sig=88B6B60B4797206A650127491C5C7B8E&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}

Request query: 1443300579261932/malware_scanner


Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
6,}&report_sig=88B6B60B4797206A650127491C5C7B8E&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
7,}&report_sig=A5A9BE6F2A1A54CB1A36A5DCE822AC6D&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
7,}&report_sig=A5A9BE6F2A1A54CB1A36A5DCE822AC6D&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
7,}&report_sig=A5A9BE6F2A1A54CB1A36A5DCE822AC6D&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
7,}&report_sig=A5A9BE6F2A1A54CB1A36A5DCE822AC6D&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
8,}&report_sig=F03CDC54B63E3A0EDB6743119E6F2AFD&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
9,}&report_sig=A1EE68F783791D7539778E705CD79F6A&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
9,}&report_sig=A1EE68F783791D7539778E705CD79F6A&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Update Finalize
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 2
0,}&report_sig=BCCE58E7B42B5B9894C1B0A33C679EB8&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Updated modules version: 22164
# product=FBAV
# version=8
# FBAV_user_token=1527062570892468
# FBAV_user_locale=en_US

# FBAV_attack_id=601246363339485
# FBAV_status=0
# flags=0
# ESET.exe=4.3.0.27
# end=Updated
# utc_time=2015-01-24 21:54:10
# local_time=2015-01-25 03:24:10 (+0530, India Standard Time)
# country="United States"
# osver=6.1.7601 NT Service Pack 1
UPDATED report sent to ESET
Initialize Scan
Scan
Scanner engine: 22164
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 2
2,}&report_sig=6D15D3E1FF90784432A863B9D218F145&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Scanner engine: 22164
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 2
7,}&report_sig=6028852688785C2E911B144B006EF253&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 2
7,}&report_sig=6028852688785C2E911B144B006EF253&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 2
7,}&report_sig=6028852688785C2E911B144B006EF253&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_DATA","event_type": "DE
TECTED","sample_name": "a variant of Win32/Systweak.A potentially unwanted appli
cation","sample_id": "a variant of Win32/Systweak.A potentially unwanted applica
tion","sample_hashes": {"SHA1": "476AB86A5F3B1A5EF750FDF2692599CEFF7CE6A7",},}&r
eport_sig=8E954A52A1EBE1872D818EF7D29916D3&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_DATA","event_type": "CL
EANUP_FAILURE","sample_name": "a variant of Win32/Systweak.A potentially unwante
d application","sample_id": "a variant of Win32/Systweak.A potentially unwanted
application","sample_hashes": {"SHA1": "476AB86A5F3B1A5EF750FDF2692599CEFF7CE6A7
",},}&report_sig=2AAF46AC0528A5B69F60A29579392730&fwd_ip=127.0.0.1&version=4.2.0
.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 2
7,}&report_sig=6028852688785C2E911B144B006EF253&fwd_ip=127.0.0.1&version=4.2.0.2
7

Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 2
7,}&report_sig=6028852688785C2E911B144B006EF253&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 4
7,}&report_sig=1C551C5EEA8098D9D2626A4BB51F0FE4&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7

Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_DATA","event_type": "DE
TECTED","sample_name": "a variant of Win32/InstallCore.SO potentially unwanted a
pplication","sample_id": "a variant of Win32/InstallCore.SO potentially unwanted
application","sample_hashes": {"SHA1": "C5C3B9C16C14ED7E253E09B9690A6C40685CCD8
3",},}&report_sig=BD9C2B0EE815B876F661EB330E17F587&fwd_ip=127.0.0.1&version=4.2.
0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_DATA","event_type": "CL
EANUP_SUCCESS","sample_name": "a variant of Win32/InstallCore.SO potentially unw
anted application","sample_id": "a variant of Win32/InstallCore.SO potentially u
nwanted application","sample_hashes": {"SHA1": "C5C3B9C16C14ED7E253E09B9690A6C40
685CCD83",},}&report_sig=C985905769BC50790DF1DF2C1786BAF8&fwd_ip=127.0.0.1&versi
on=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_DATA","event_type": "DE
TECTED","sample_name": "Win32/Toolbar.Inbox.C potentially unwanted application,W
in32/Toolbar.Crawler.B potentially unwanted application","sample_id": "Win32/Too

lbar.Inbox.C potentially unwanted application,Win32/Toolbar.Crawler.B potentiall


y unwanted application","sample_hashes": {"SHA1": "C5CB778FDB15F8BF49F800252FDF1
0A47D94FE71",},}&report_sig=5A5FED9926BC032ED16AF5515DBB09BC&fwd_ip=127.0.0.1&ve
rsion=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_DATA","event_type": "CL
EANUP_SUCCESS","sample_name": "Win32/Toolbar.Inbox.C potentially unwanted applic
ation,Win32/Toolbar.Crawler.B potentially unwanted application","sample_id": "Wi
n32/Toolbar.Inbox.C potentially unwanted application,Win32/Toolbar.Crawler.B pot
entially unwanted application","sample_hashes": {"SHA1": "C5CB778FDB15F8BF49F800
252FDF10A47D94FE71",},}&report_sig=42697617357B3367B63DE4AE25D9D656&fwd_ip=127.0
.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 5
4,}&report_sig=F25394395619176A460CA62754A9E136&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8

0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_DATA","event_type": "DE
TECTED","sample_name": "Win32/BrowseFox.C potentially unwanted application","sam
ple_id": "Win32/BrowseFox.C potentially unwanted application","sample_hashes": {
"SHA1": "8A470D3B6D4110C8AFFE374B9A118BF00B61B8BA",},}&report_sig=781B104FC6CEC4
15FD668E656B0B2103&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_DATA","event_type": "CL
EANUP_FAILURE","sample_name": "Win32/BrowseFox.C potentially unwanted applicatio
n","sample_id": "Win32/BrowseFox.C potentially unwanted application","sample_has
hes": {"SHA1": "8A470D3B6D4110C8AFFE374B9A118BF00B61B8BA",},}&report_sig=F52E166
026B349CCE0359C4D0459C9D0&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7

Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 8
0,}&report_sig=E2A70107B3D066CEC3BFB72625E01640&fwd_ip=127.0.0.1&version=4.2.0.2
7
Response: {"status":true}
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_PROGRESS","progress": 1
00,}&report_sig=38179CAEFE86A682F37B9182AAB91D97&fwd_ip=127.0.0.1&version=4.2.0.
27
Response: {"status":true}
Reporting
# product=FBAV
# version=8
# FBAV_user_token=1527062570892468
# FBAV_user_locale=en_US
# FBAV_attack_id=601246363339485
# FBAV_status=0
# flags=0
# ESET.exe=4.3.0.27
# EOSSerial=284cd12d71cdc74d8b3d939b65bf7620
# engine=22164
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# sfx_checked=true
# utc_time=2015-01-24 21:54:10
# local_time=2015-01-25 03:24:10 (+0530, India Standard Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 733285 173766843 0 0
# compatibility_mode_1='360 Total Security'
# compatibility_mode=16385 16777213 87 100 0 4418760 0 0
# scanned=19508
# found=4
# cleaned=2
# scan_time=491
sh=476AB86A5F3B1A5EF750FDF2692599CEFF7CE6A7 ft=1 fh=0000000000004718 vn="a varia
nt of Win32/Systweak.A potentially unwanted application (error while cleaning (A
ccess denied))" ac=I fn="C:\Windows\system32\roboot.exe"
sh=BF995A87B7E8F553A886D828AC01ACF390207C75 ft=0 fh=000000000000005c vn="" ac=S

fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmi
ghlieiainnegkcijnfilokake\0.7_0\main.html"
sh=FFE9A28CDE2E130F64CCB51A76DF3A453464BE19 ft=0 fh=000000000000005b vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmi
ghlieiainnegkcijnfilokake\0.7_0\main.js"
sh=80218B4949D12776D180A1D16FB0B361098D62AE ft=0 fh=00000000000022d6 vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\audio\1_short_Open_16_16.wav"
sh=63B4DB928082EC80C5CA856392018673D42463A1 ft=0 fh=00000000000503f4 vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\_platform_specific\x86-32_\hotword-x86-32
.nexe"
sh=F80AD350D18799D5984136E86FF674AE53388469 ft=0 fh=0000000000042cdf vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\_platform_specific\x86-32_\hotword.data"
sh=A983EAE59018B97231ED0BA0603B2F4E7ED61679 ft=0 fh=0000000000007835 vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\audio-input-compiled.js"
sh=517868387BE9CB110A4A2EECC40C4B2B3E4A0456 ft=0 fh=000000000000d731 vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\audio-manager-compiled.js"
sh=E9AC73C61B24B3057DED594D4AC461261BBC1332 ft=0 fh=00000000000000af vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\audio_input.html"
sh=317F30B5305B815E33ED3916DA6DF8623E1787DE ft=0 fh=0000000000000114 vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\background.html"
sh=A68180DDCC19CD3AC32AC29BFC89CFB5F8062CBF ft=0 fh=00000000000076db vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\content-bundle-compiled.js"
sh=5A435DF92FCD4FC94CB61B08D58EA220296D9BF2 ft=0 fh=00000000000000ed vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\hotword_.nmf"
sh=0690EDD04BA5A7B07CD98F5AED493298BEC73810 ft=0 fh=00000000000000f3 vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\hotword_de.nmf"
sh=C8D0D84F2AC2310C67C91328FCE2C88E6B1E0CB7 ft=0 fh=00000000000000fc vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\hotword_en-gb.nmf"
sh=6A4DE94A8C600DF9F37236CD926B4941E14D6990 ft=0 fh=00000000000000f3 vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\hotword_fr.nmf"
sh=59EC46C14BE5D5C87A7B08C0B1240CB9AB0EA3FA ft=0 fh=00000000000000f3 vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\hotword_ru.nmf"
sh=236F65887D6748CD19F84D5B3F0E285432FEDB7A ft=0 fh=0000000000002abe vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\options-compiled.js"
sh=66DCDDF8A09F02F7F02E9081958C7FE309CAF57C ft=0 fh=0000000000004c36 vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\options.css"
sh=BA8543268A49CC942CD9DB7EE516B59B35D66AEF ft=0 fh=0000000000000a83 vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhg
boaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\options.html"
sh=D826396D497574B5A8DA6BB6369D8B227DC3C83C ft=0 fh=00000000002e2beb vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\bghgbjh
ohnijgldgihjmmdgmjceaikag\1_0\Cached Theme.pak"
sh=A4AC74DD258E8E0689034FAA1B15A5C7C56DC3BB ft=0 fh=00000000000006cd vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkke
gccagdldgiimedpiccmgmieda\0.0.6.1_1\css\craw_window.css"

sh=8B4EAA74D31EED5B0BABA3CA5460201F6B10DA46 ft=0 fh=000000000000032a vn="" ac=S


fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkke
gccagdldgiimedpiccmgmieda\0.0.6.1_1\html\craw_window.html"
sh=D591287E341F1E6A5EDA97D95AB240CF2841955F ft=0 fh=000000000001ee95 vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkke
gccagdldgiimedpiccmgmieda\0.0.6.1_1\craw_background.js"
sh=7526791878FE91ED075382C2B432A43A47EE7DCD ft=0 fh=00000000000264e7 vn="" ac=S
fn="C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkke
gccagdldgiimedpiccmgmieda\0.0.6.1_1\craw_window.js"
sh=C5C3B9C16C14ED7E253E09B9690A6C40685CCD83 ft=1 fh=00000000000b6558 vn="a varia
nt of Win32/InstallCore.SO potentially unwanted application (cleaned by deleting
)" ac=C fn="C:\Users\hp\Downloads\software\FreeYouTubeDownloaderIC.exe"
sh=C5CB778FDB15F8BF49F800252FDF10A47D94FE71 ft=1 fh=0000000000271ba8 vn="Win32/T
oolbar.Inbox.C potentially unwanted application,Win32/Toolbar.Crawler.B potentia
lly unwanted application (deleted)" ac=C fn="C:\Users\hp\Downloads\CustomizableS
etup.exe"
sh=8A470D3B6D4110C8AFFE374B9A118BF00B61B8BA ft=1 fh=000000000003f360 vn="Win32/B
rowseFox.C potentially unwanted application (error while deleting (Access denied
))" ac=I fn="C:\Program Files\Hold Page\HoldPageUninstall.exe"
EOS report sent
Request query: 1443300579261932/malware_scanner
Request body: access_token=1443300579261932|cfedb1bd1113405e097902a8602d76ed&use
r_token=1527062570892468&report={"report_type": "SCANNER_COMPLETE",}&report_sig=
9C734DE4A183E52F911281E9D10DE4BF&fwd_ip=127.0.0.1&version=4.2.0.27
Response: {"status":true}
FB Complete sent
Finalizing
Cleaning up
RecursiveRemoveDirectoryAndAllFiles: C:\Users\hp\AppData\Local\Temp\FBScanner_07
8942607\Modules\

Das könnte Ihnen auch gefallen