Provera

Provera

offline
  • v358 
  • Novi MyCity građanin
  • Pridružio: 29 Dec 2014
  • Poruke: 16

Pozdrav. Nakon pokretanja AIMP-a 3 , reagovao je Avast i ocistio infekciju (bar tako on javlja Very Happy )

Juce sam apdejtovao ovu aplikaiju i pokretao sam je par puta i sve je bilo u redu, do sada. Hteo bih da proverim da li ima jos neke infekcije.
Evo frst izvestaja:




Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-09-2015
Ran by v358win (administrator) on V358 (16-09-2015 21:53:18)
Running from C:\Users\v358win\Desktop
Loaded Profiles: v358win (Available Profiles: v358win)
Platform: Windows 8.1 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: [Link mogu videti samo ulogovani korisnici]

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Windows (R) Win 7 DDK provider) C:\Program Files\Bluetooth Suite\AdminService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Atheros) C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Qualcomm®Atheros®) C:\Program Files\Bluetooth Suite\BtvStack.exe
() C:\Program Files\Bluetooth Suite\ActivateDesktop.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Code::Blocks Team) C:\Program Files (x86)\CodeBlocks\codeblocks.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-13] (NVIDIA Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6111824 2015-09-11] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files\Bluetooth Suite\BtvStack.exe [132736 2013-09-25] (Qualcomm®Atheros®)
HKU\S-1-5-21-452044520-4055168981-2684586079-1001\...\Run: [MCShield Monitor] => C:\Program Files\MCShield\mcshieldrtm.exe [650816 2014-04-11] (MyCity)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [178632 2014-12-13] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [165760 2014-12-13] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-09-11] (AVAST Software)
Startup: C:\Users\v358win\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2015-07-06] ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\..\Interfaces\{272D2EFE-DF27-44A1-ADD6-5D06E5ED12BA}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{BC3D4F58-8957-4C14-AC22-13B78CD65EB2}: [DhcpNameServer] 8.8.8.8

Internet Explorer:
==================
HKU\S-1-5-21-452044520-4055168981-2684586079-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = [Link mogu videti samo ulogovani korisnici]
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-07-09] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-09-11] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-07-09] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-09-11] (AVAST Software)

FireFox:
========
FF ProfilePath: C:\Users\v358win\AppData\Roaming\Mozilla\Firefox\Profiles\394tdg6h.default-1435962957077
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-07-09] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-07-09] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-31] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-31] (Google Inc.)
FF Extension: Qualys BrowserCheck - C:\Users\v358win\AppData\Roaming\Mozilla\Firefox\Profiles\394tdg6h.default-1435962957077\Extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D} [2015-07-09]
FF Extension: Simple RSS Reader (SRR) - C:\Users\v358win\AppData\Roaming\Mozilla\Firefox\Profiles\394tdg6h.default-1435962957077\Extensions\{A5475360-A7EA-437b-9A79-29208F476940}.xpi [2015-07-11]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-12-29]
StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe

Chrome:
=======
CHR Profile: C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 2
CHR Extension: (Google новчаник) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-24]
CHR Profile: C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 5
CHR Profile: C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6
CHR Extension: (Google документи) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-24]
CHR Extension: (Google диск) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-24]
CHR Extension: (YouTube) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-24]
CHR Extension: (Google Search) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-24]
CHR Extension: (Google документи офлајн) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-02]
CHR Extension: (AdBlock) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-09-05]
CHR Extension: (Плаћања у Chrome веб-продавници) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-24]
CHR Extension: (Gmail) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-24]
CHR Extension: (RSS Feed Reader) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp [2015-08-25]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-03-21]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-21]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AtherosSvc; C:\Program Files\Bluetooth Suite\adminservice.exe [312448 2013-09-25] (Windows (R) Win 7 DDK provider) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-11] (AVAST Software)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2014-02-20] (Microsoft Corporation) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [318568 2014-10-20] (Intel Corporation)
S4 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [22744 2014-10-15] (Microsoft Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
S4 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
S4 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed]
S4 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2014-07-22] (Microsoft Corporation)
S4 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S4 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-09-25] (Atheros) [File not signed]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AndnetBus; C:\Windows\System32\drivers\lgandnetbus64.sys [20992 2015-01-21] (LG Electronics Inc.)
S3 AndNetDiag; C:\Windows\system32\DRIVERS\lgandnetdiag64.sys [30720 2015-01-26] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\system32\DRIVERS\lgandnetmodem64.sys [37376 2015-01-26] (LG Electronics Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-09-11] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-09-11] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-09-11] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-09-11] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048344 2015-09-11] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-09-11] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-09-11] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-09-11] (AVAST Software)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [4221952 2014-09-18] (Qualcomm Atheros Communications, Inc.)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-25] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
R3 DAdderFltr; C:\Windows\system32\drivers\dadder.sys [12672 2007-08-02] (Razer (Asia-Pacific) Pte Ltd)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R2 IntelHaxm; C:\Windows\system32\DRIVERS\IntelHaxm.sys [84992 2015-01-30] (Intel Corporation)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
U5 RTSPER; C:\Windows\System32\Drivers\RTSPER.sys [465624 2014-12-30] (Realsil Semiconductor Corporation)
S3 rzdaendpt; C:\Windows\System32\drivers\rzdaendpt.sys [33448 2014-12-30] (Razer Inc)
S3 rzvkeyboard; C:\Windows\System32\drivers\rzvkeyboard.sys [31912 2014-12-30] (Razer Inc)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation)
S3 sthid; C:\Windows\System32\drivers\sthid.sys [21216 2015-03-04] (Splashtop Inc.)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
R1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [117768 2015-08-13] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [146072 2015-08-13] (Oracle Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [34760 2013-08-22] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [265056 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
S3 VMSMP; \SystemRoot\system32\DRIVERS\vmswitch.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-16 21:53 - 2015-09-16 21:53 - 00014951 _____ C:\Users\v358win\Desktop\FRST.txt
2015-09-16 21:11 - 2015-09-16 21:11 - 00003978 _____ C:\Users\v358win\Desktop\FasadaV1.cpp
2015-09-16 21:11 - 2015-09-16 21:11 - 00000297 _____ C:\Users\v358win\Desktop\Untitled2.cpp
2015-09-16 20:44 - 2015-09-16 21:53 - 00000000 ____D C:\FRST
2015-09-16 20:43 - 2015-09-16 20:43 - 02191360 _____ (Farbar) C:\Users\v358win\Desktop\FRST64.exe
2015-09-16 16:35 - 2015-09-16 16:35 - 00003348 _____ C:\Users\v358win\Desktop\Fasada.cpp
2015-09-16 15:44 - 2015-09-16 15:50 - 00000022 _____ C:\Users\v358win\Desktop\New Text Document.txt
2015-09-16 15:04 - 2015-09-16 16:03 - 00000000 ____D C:\Users\v358win\workspace
2015-09-16 14:55 - 2015-09-16 14:55 - 00000000 ____D C:\Users\v358win\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GCC 5.1.0
2015-09-16 14:54 - 2015-09-16 14:55 - 00000000 ____D C:\MinGW
2015-09-16 12:18 - 2015-09-16 20:24 - 00035300 _____ C:\Windows\WindowsUpdate.log
2015-09-16 00:10 - 2015-09-16 00:26 - 891009133 _____ C:\Users\v358win\Desktop\Hammock - Departure Songs (Full Album).mp4
2015-09-12 22:05 - 2015-09-12 22:05 - 00582272 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-11 13:36 - 2015-09-11 13:36 - 00378880 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-09-11 13:36 - 2015-09-11 13:36 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-09-09 23:51 - 2015-09-13 11:35 - 00002198 _____ C:\Users\v358win\Desktop\primeri za patterne.txt
2015-09-04 12:25 - 2015-09-04 12:26 - 00000000 ____D C:\Users\v358win\Documents\NFS Most Wanted
2015-09-04 12:06 - 2015-09-04 12:06 - 00003182 _____ C:\Windows\System32\Tasks\{BB39BBF1-4283-4A06-99B2-29ACA47051AD}
2015-09-04 12:05 - 2015-09-04 12:05 - 00003032 _____ C:\Windows\System32\Tasks\{93069650-E0D8-4C14-B6BD-E8382E033415}
2015-09-04 00:48 - 2015-09-04 00:48 - 00005676 _____ C:\Users\v358win\Desktop\lista3.cpp
2015-09-01 16:56 - 2015-09-01 16:57 - 00000000 ____D C:\Users\v358win\Desktop\mreze
2015-08-31 22:55 - 2015-08-31 22:55 - 00000762 _____ C:\Users\v358win\Desktop\liste2.cpp
2015-08-25 17:47 - 2015-09-04 19:44 - 00000000 ____D C:\Users\v358win\VirtualBox VMs
2015-08-25 17:42 - 2015-09-04 19:45 - 00000000 ____D C:\Users\v358win\.VirtualBox
2015-08-25 17:41 - 2015-08-25 17:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2015-08-25 17:41 - 2015-08-13 18:24 - 00960808 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2015-08-25 17:41 - 2015-08-13 18:24 - 00138904 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2015-08-23 13:24 - 2007-08-02 17:33 - 00012672 _____ (Razer (Asia-Pacific) Pte Ltd) C:\Windows\system32\Drivers\dadder.sys
2015-08-23 13:24 - 2007-05-07 18:19 - 00085504 _____ (Razer USA Ltd.) C:\Windows\SysWOW64\DeathAdder64.cpl

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-16 21:15 - 2014-12-29 21:03 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-452044520-4055168981-2684586079-1001
2015-09-16 21:00 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\sru
2015-09-16 20:48 - 2015-02-10 15:17 - 00000000 ____D C:\Users\v358win\AppData\Roaming\CodeBlocks
2015-09-16 20:35 - 2014-12-29 20:59 - 00003918 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{5612B485-2F60-425A-970D-56EC9D4E6179}
2015-09-16 20:27 - 2014-12-29 21:02 - 00000916 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-16 20:27 - 2014-12-29 21:02 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-16 20:25 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-16 20:24 - 2014-12-30 18:53 - 00000000 ____D C:\Users\v358win\AppData\Roaming\BitTorrent
2015-09-16 20:24 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-09-16 15:06 - 2014-12-30 18:59 - 00000000 ____D C:\Users\v358win\AppData\Local\Eclipse
2015-09-16 15:04 - 2014-12-29 20:54 - 00000000 ____D C:\Users\v358win
2015-09-16 12:19 - 2014-12-29 20:56 - 00000000 __RDO C:\Users\v358win\SkyDrive
2015-09-14 16:35 - 2014-12-29 21:10 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-09-12 09:20 - 2013-09-30 06:14 - 00913650 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-12 00:58 - 2014-12-31 14:59 - 00000000 ____D C:\Users\v358win\Documents\Bluetooth Folder
2015-09-11 17:59 - 2014-12-30 19:02 - 00000000 ____D C:\Users\v358win\AppData\Roaming\Notepad++
2015-09-11 17:59 - 2014-12-30 19:02 - 00000000 ____D C:\Program Files\Notepad++
2015-09-11 14:49 - 2015-02-07 02:07 - 00000000 ____D C:\Users\v358win\AppData\Local\CrashDumps
2015-09-11 13:36 - 2014-12-29 21:10 - 01048344 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2015-09-11 13:36 - 2014-12-29 21:10 - 00447944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-09-11 13:36 - 2014-12-29 21:10 - 00274808 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-09-11 13:36 - 2014-12-29 21:10 - 00150672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-09-11 13:36 - 2014-12-29 21:10 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-09-11 13:36 - 2014-12-29 21:10 - 00090968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-09-11 13:36 - 2014-12-29 21:10 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-09-11 13:36 - 2014-12-29 21:10 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-09-01 00:11 - 2015-03-14 12:32 - 00000000 ____D C:\Users\v358win\Documents\Visual Studio 2013
2015-08-31 12:22 - 2014-12-29 21:02 - 00003888 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-31 12:22 - 2014-12-29 21:02 - 00003652 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-29 12:28 - 2015-01-15 22:40 - 00000000 ____D C:\Users\v358win\AppData\Roaming\MiniLyrics
2015-08-28 22:25 - 2014-12-31 15:03 - 00000000 ____D C:\Users\v358win\AppData\Roaming\Atheros
2015-08-23 13:24 - 2015-05-10 08:55 - 00000000 ____D C:\Program Files (x86)\Razer
2015-08-23 13:24 - 2014-12-30 17:59 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information

==================== Files in the root of some directories =======

2015-06-12 18:53 - 2015-06-12 18:53 - 0000218 _____ () C:\Users\v358win\AppData\Local\recently-used.xbel
2015-06-16 17:31 - 2015-07-22 15:28 - 0007599 _____ () C:\Users\v358win\AppData\Local\Resmon.ResmonCfg
2014-12-30 18:01 - 2014-12-30 18:01 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\v358win\AppData\Local\Temp\UniC01F.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-09-10 12:32

==================== End of FRST.txt ============================






[Link mogu videti samo ulogovani korisnici]



offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

Pozdrav v358,

Da li si uopste procitao sta ti to avast! Shield prijavljuje kada si pokrenio AIMP? Detekcija je lazna (FP a.k.a Falce Positive) i odnosi se na radni AIMP direktorijum;
C:\program files\aimp3

Sto se tice postavljenih izvestaja, nema tragova aktivne infekcije. Mozes obrisati alat i njegov C:\FRST radni folder.

Sto se tice avast!-a, vrati detekciju i prijavi kao FP putem AV obrazca ili prijavi putem web forme, sekcija Report a Virus.
[Link mogu videti samo ulogovani korisnici]



Ko je trenutno na forumu
 

Ukupno su 972 korisnika na forumu :: 60 registrovanih, 6 sakrivenih i 906 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: acov34, Areal84, Asparagus, Ba4e, Banovo Brdo, bbrasnjo3, brufen, BUDDAR70, BWG, Cicumile, cojapop, Crazzer, cyprus, dacanaldo, dane007, Dejan_vw, Denaya, Doc, eagle.rs, Electron, Fabius, FileFinder, Gogi_avio, goranjovic, icemilos, Jerry Drake, Jose, klepesina, kolle.the.kid, Koča, Lazarus, Macalone, maCvele, Marko1238, Metanoja, Mi lao shu, Milan A. Nikolic, milbos, mist-mist, Najax, opt1, Oscar2, pceklic, PrincipL, RajkoB, RAKITNICA, samo opusteno, shaja1, sistem22, Slingshot, synergia, tihi-posmatrac, troki1971, tvlada, vathra, voja64, vuksa72, yrraf, zeka013, zziko