Provera

Provera

offline
  • v358 
  • Novi MyCity građanin
  • Pridružio: 29 Dec 2014
  • Poruke: 16

Pozdrav. Nakon pokretanja AIMP-a 3 , reagovao je Avast i ocistio infekciju (bar tako on javlja Very Happy )

Juce sam apdejtovao ovu aplikaiju i pokretao sam je par puta i sve je bilo u redu, do sada. Hteo bih da proverim da li ima jos neke infekcije.
Evo frst izvestaja:




Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-09-2015
Ran by v358win (administrator) on V358 (16-09-2015 21:53:18)
Running from C:\Users\v358win\Desktop
Loaded Profiles: v358win (Available Profiles: v358win)
Platform: Windows 8.1 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: [Link mogu videti samo ulogovani korisnici]

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Windows (R) Win 7 DDK provider) C:\Program Files\Bluetooth Suite\AdminService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Atheros) C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Qualcomm®Atheros®) C:\Program Files\Bluetooth Suite\BtvStack.exe
() C:\Program Files\Bluetooth Suite\ActivateDesktop.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Code::Blocks Team) C:\Program Files (x86)\CodeBlocks\codeblocks.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-13] (NVIDIA Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6111824 2015-09-11] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files\Bluetooth Suite\BtvStack.exe [132736 2013-09-25] (Qualcomm®Atheros®)
HKU\S-1-5-21-452044520-4055168981-2684586079-1001\...\Run: [MCShield Monitor] => C:\Program Files\MCShield\mcshieldrtm.exe [650816 2014-04-11] (MyCity)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [178632 2014-12-13] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [165760 2014-12-13] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-09-11] (AVAST Software)
Startup: C:\Users\v358win\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2015-07-06] ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\..\Interfaces\{272D2EFE-DF27-44A1-ADD6-5D06E5ED12BA}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{BC3D4F58-8957-4C14-AC22-13B78CD65EB2}: [DhcpNameServer] 8.8.8.8

Internet Explorer:
==================
HKU\S-1-5-21-452044520-4055168981-2684586079-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = [Link mogu videti samo ulogovani korisnici]
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-07-09] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-09-11] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-07-09] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-09-11] (AVAST Software)

FireFox:
========
FF ProfilePath: C:\Users\v358win\AppData\Roaming\Mozilla\Firefox\Profiles\394tdg6h.default-1435962957077
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-07-09] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-07-09] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-31] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-31] (Google Inc.)
FF Extension: Qualys BrowserCheck - C:\Users\v358win\AppData\Roaming\Mozilla\Firefox\Profiles\394tdg6h.default-1435962957077\Extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D} [2015-07-09]
FF Extension: Simple RSS Reader (SRR) - C:\Users\v358win\AppData\Roaming\Mozilla\Firefox\Profiles\394tdg6h.default-1435962957077\Extensions\{A5475360-A7EA-437b-9A79-29208F476940}.xpi [2015-07-11]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-12-29]
StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe

Chrome:
=======
CHR Profile: C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 2
CHR Extension: (Google новчаник) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-24]
CHR Profile: C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 5
CHR Profile: C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6
CHR Extension: (Google документи) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-24]
CHR Extension: (Google диск) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-24]
CHR Extension: (YouTube) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-24]
CHR Extension: (Google Search) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-24]
CHR Extension: (Google документи офлајн) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-02]
CHR Extension: (AdBlock) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-09-05]
CHR Extension: (Плаћања у Chrome веб-продавници) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-24]
CHR Extension: (Gmail) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-24]
CHR Extension: (RSS Feed Reader) - C:\Users\v358win\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp [2015-08-25]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-03-21]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-21]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AtherosSvc; C:\Program Files\Bluetooth Suite\adminservice.exe [312448 2013-09-25] (Windows (R) Win 7 DDK provider) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-11] (AVAST Software)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2014-02-20] (Microsoft Corporation) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [318568 2014-10-20] (Intel Corporation)
S4 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [22744 2014-10-15] (Microsoft Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
S4 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
S4 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed]
S4 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2014-07-22] (Microsoft Corporation)
S4 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S4 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-09-25] (Atheros) [File not signed]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AndnetBus; C:\Windows\System32\drivers\lgandnetbus64.sys [20992 2015-01-21] (LG Electronics Inc.)
S3 AndNetDiag; C:\Windows\system32\DRIVERS\lgandnetdiag64.sys [30720 2015-01-26] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\system32\DRIVERS\lgandnetmodem64.sys [37376 2015-01-26] (LG Electronics Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-09-11] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-09-11] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-09-11] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-09-11] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048344 2015-09-11] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-09-11] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-09-11] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-09-11] (AVAST Software)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [4221952 2014-09-18] (Qualcomm Atheros Communications, Inc.)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-25] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
R3 DAdderFltr; C:\Windows\system32\drivers\dadder.sys [12672 2007-08-02] (Razer (Asia-Pacific) Pte Ltd)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R2 IntelHaxm; C:\Windows\system32\DRIVERS\IntelHaxm.sys [84992 2015-01-30] (Intel Corporation)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
U5 RTSPER; C:\Windows\System32\Drivers\RTSPER.sys [465624 2014-12-30] (Realsil Semiconductor Corporation)
S3 rzdaendpt; C:\Windows\System32\drivers\rzdaendpt.sys [33448 2014-12-30] (Razer Inc)
S3 rzvkeyboard; C:\Windows\System32\drivers\rzvkeyboard.sys [31912 2014-12-30] (Razer Inc)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation)
S3 sthid; C:\Windows\System32\drivers\sthid.sys [21216 2015-03-04] (Splashtop Inc.)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
R1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [117768 2015-08-13] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [146072 2015-08-13] (Oracle Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [34760 2013-08-22] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [265056 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
S3 VMSMP; \SystemRoot\system32\DRIVERS\vmswitch.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-16 21:53 - 2015-09-16 21:53 - 00014951 _____ C:\Users\v358win\Desktop\FRST.txt
2015-09-16 21:11 - 2015-09-16 21:11 - 00003978 _____ C:\Users\v358win\Desktop\FasadaV1.cpp
2015-09-16 21:11 - 2015-09-16 21:11 - 00000297 _____ C:\Users\v358win\Desktop\Untitled2.cpp
2015-09-16 20:44 - 2015-09-16 21:53 - 00000000 ____D C:\FRST
2015-09-16 20:43 - 2015-09-16 20:43 - 02191360 _____ (Farbar) C:\Users\v358win\Desktop\FRST64.exe
2015-09-16 16:35 - 2015-09-16 16:35 - 00003348 _____ C:\Users\v358win\Desktop\Fasada.cpp
2015-09-16 15:44 - 2015-09-16 15:50 - 00000022 _____ C:\Users\v358win\Desktop\New Text Document.txt
2015-09-16 15:04 - 2015-09-16 16:03 - 00000000 ____D C:\Users\v358win\workspace
2015-09-16 14:55 - 2015-09-16 14:55 - 00000000 ____D C:\Users\v358win\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GCC 5.1.0
2015-09-16 14:54 - 2015-09-16 14:55 - 00000000 ____D C:\MinGW
2015-09-16 12:18 - 2015-09-16 20:24 - 00035300 _____ C:\Windows\WindowsUpdate.log
2015-09-16 00:10 - 2015-09-16 00:26 - 891009133 _____ C:\Users\v358win\Desktop\Hammock - Departure Songs (Full Album).mp4
2015-09-12 22:05 - 2015-09-12 22:05 - 00582272 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-11 13:36 - 2015-09-11 13:36 - 00378880 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-09-11 13:36 - 2015-09-11 13:36 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-09-09 23:51 - 2015-09-13 11:35 - 00002198 _____ C:\Users\v358win\Desktop\primeri za patterne.txt
2015-09-04 12:25 - 2015-09-04 12:26 - 00000000 ____D C:\Users\v358win\Documents\NFS Most Wanted
2015-09-04 12:06 - 2015-09-04 12:06 - 00003182 _____ C:\Windows\System32\Tasks\{BB39BBF1-4283-4A06-99B2-29ACA47051AD}
2015-09-04 12:05 - 2015-09-04 12:05 - 00003032 _____ C:\Windows\System32\Tasks\{93069650-E0D8-4C14-B6BD-E8382E033415}
2015-09-04 00:48 - 2015-09-04 00:48 - 00005676 _____ C:\Users\v358win\Desktop\lista3.cpp
2015-09-01 16:56 - 2015-09-01 16:57 - 00000000 ____D C:\Users\v358win\Desktop\mreze
2015-08-31 22:55 - 2015-08-31 22:55 - 00000762 _____ C:\Users\v358win\Desktop\liste2.cpp
2015-08-25 17:47 - 2015-09-04 19:44 - 00000000 ____D C:\Users\v358win\VirtualBox VMs
2015-08-25 17:42 - 2015-09-04 19:45 - 00000000 ____D C:\Users\v358win\.VirtualBox
2015-08-25 17:41 - 2015-08-25 17:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2015-08-25 17:41 - 2015-08-13 18:24 - 00960808 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2015-08-25 17:41 - 2015-08-13 18:24 - 00138904 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2015-08-23 13:24 - 2007-08-02 17:33 - 00012672 _____ (Razer (Asia-Pacific) Pte Ltd) C:\Windows\system32\Drivers\dadder.sys
2015-08-23 13:24 - 2007-05-07 18:19 - 00085504 _____ (Razer USA Ltd.) C:\Windows\SysWOW64\DeathAdder64.cpl

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-16 21:15 - 2014-12-29 21:03 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-452044520-4055168981-2684586079-1001
2015-09-16 21:00 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\sru
2015-09-16 20:48 - 2015-02-10 15:17 - 00000000 ____D C:\Users\v358win\AppData\Roaming\CodeBlocks
2015-09-16 20:35 - 2014-12-29 20:59 - 00003918 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{5612B485-2F60-425A-970D-56EC9D4E6179}
2015-09-16 20:27 - 2014-12-29 21:02 - 00000916 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-16 20:27 - 2014-12-29 21:02 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-16 20:25 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-16 20:24 - 2014-12-30 18:53 - 00000000 ____D C:\Users\v358win\AppData\Roaming\BitTorrent
2015-09-16 20:24 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-09-16 15:06 - 2014-12-30 18:59 - 00000000 ____D C:\Users\v358win\AppData\Local\Eclipse
2015-09-16 15:04 - 2014-12-29 20:54 - 00000000 ____D C:\Users\v358win
2015-09-16 12:19 - 2014-12-29 20:56 - 00000000 __RDO C:\Users\v358win\SkyDrive
2015-09-14 16:35 - 2014-12-29 21:10 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-09-12 09:20 - 2013-09-30 06:14 - 00913650 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-12 00:58 - 2014-12-31 14:59 - 00000000 ____D C:\Users\v358win\Documents\Bluetooth Folder
2015-09-11 17:59 - 2014-12-30 19:02 - 00000000 ____D C:\Users\v358win\AppData\Roaming\Notepad++
2015-09-11 17:59 - 2014-12-30 19:02 - 00000000 ____D C:\Program Files\Notepad++
2015-09-11 14:49 - 2015-02-07 02:07 - 00000000 ____D C:\Users\v358win\AppData\Local\CrashDumps
2015-09-11 13:36 - 2014-12-29 21:10 - 01048344 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2015-09-11 13:36 - 2014-12-29 21:10 - 00447944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-09-11 13:36 - 2014-12-29 21:10 - 00274808 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-09-11 13:36 - 2014-12-29 21:10 - 00150672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-09-11 13:36 - 2014-12-29 21:10 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-09-11 13:36 - 2014-12-29 21:10 - 00090968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-09-11 13:36 - 2014-12-29 21:10 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-09-11 13:36 - 2014-12-29 21:10 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-09-01 00:11 - 2015-03-14 12:32 - 00000000 ____D C:\Users\v358win\Documents\Visual Studio 2013
2015-08-31 12:22 - 2014-12-29 21:02 - 00003888 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-31 12:22 - 2014-12-29 21:02 - 00003652 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-29 12:28 - 2015-01-15 22:40 - 00000000 ____D C:\Users\v358win\AppData\Roaming\MiniLyrics
2015-08-28 22:25 - 2014-12-31 15:03 - 00000000 ____D C:\Users\v358win\AppData\Roaming\Atheros
2015-08-23 13:24 - 2015-05-10 08:55 - 00000000 ____D C:\Program Files (x86)\Razer
2015-08-23 13:24 - 2014-12-30 17:59 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information

==================== Files in the root of some directories =======

2015-06-12 18:53 - 2015-06-12 18:53 - 0000218 _____ () C:\Users\v358win\AppData\Local\recently-used.xbel
2015-06-16 17:31 - 2015-07-22 15:28 - 0007599 _____ () C:\Users\v358win\AppData\Local\Resmon.ResmonCfg
2014-12-30 18:01 - 2014-12-30 18:01 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\v358win\AppData\Local\Temp\UniC01F.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-09-10 12:32

==================== End of FRST.txt ============================






[Link mogu videti samo ulogovani korisnici]



offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

Pozdrav v358,

Da li si uopste procitao sta ti to avast! Shield prijavljuje kada si pokrenio AIMP? Detekcija je lazna (FP a.k.a Falce Positive) i odnosi se na radni AIMP direktorijum;
C:\program files\aimp3

Sto se tice postavljenih izvestaja, nema tragova aktivne infekcije. Mozes obrisati alat i njegov C:\FRST radni folder.

Sto se tice avast!-a, vrati detekciju i prijavi kao FP putem AV obrazca ili prijavi putem web forme, sekcija Report a Virus.
[Link mogu videti samo ulogovani korisnici]



Ko je trenutno na forumu
 

Ukupno su 1337 korisnika na forumu :: 86 registrovanih, 11 sakrivenih i 1240 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 6018 - dana 19 Dec 2025 13:41

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, acatomic, aleksmajstor, AOE, Avalon015, Betta, Bojan198527, bojan313, bojankrstc, Borski1977, bpop, Bubili, bukefal, Burovnyak, crazydkure, dano, darkojbn, Darth Malak, Deki Duga Devetka, dendrit86, Django777, djonsule, Djota1, Donneraj, DonRumataEstorski, dulleo, Electron, EVIDENTICAR, Feller, HogarStrashni, hyla, ikan, ivan979, Jan, jarovitt, Kajzer Soze, knutveliki, koom0001, kovinacc, Kruger, Lance Guest, LUDI, luka35, M74AB3, mainstream, Malahit, marre, MB120mm, Mercury, Millennium, Milometer, minke, MK10, mkukoleca, moldway, narandzasti, nemkea71, nikolapetkovic, nuki1234, operniki, Oscar2, peradetlić, Perudin_92, Peruta, PlayerOne, Povratak1912, powSrb, Prečanin30, rodoljub, ruso, Sale0501, samsung, Semberija, Sinduk, Sonic, Srki98, srđan, Steeeefan, Stefan M, stefanmpurtic, suton, Tas011, vespa nikola, W123, wolf431, Đurđevdan