Problem na racunaru u vezi igrice

Problem na racunaru u vezi igrice

offline
  • Pridružio: 12 Avg 2013
  • Poruke: 19

Skinuo sam igricu City Car Drivinig (voznja automobila),usao sam u igricu i sve je odlicno bilo dok nisam krenuo da vozim auto,moj racunar je poceo da bude veoma bucan i da "vibrira",odmah sam ga iskljucio,i kasnije ponovo upalio,ali isti problem se ponovo pojavio.. Pomoc ! Sad



DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16476 BrowserJavaVersion: 10.25.2
Run by Nikolic at 14:16:02 on 2013-08-12
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.4060.2518 [GMT 2:00]
.
AV: Norton Internet Security *Disabled/Outdated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Disabled/Outdated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe
C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
C:\Users\Nikolic\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe
C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\Intel\iCLS Client\HeciServer.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\System32\ctfmon.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\ROCCAT\Pyra Mouse\PyraMonitor.exe
C:\Program Files\Rainmeter\Rainmeter.exe
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\loggingserver.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Users\Nikolic\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=C442902B34751858&affID=119776&tsp=4958
uSearch Page = hxxp://search.b1.org/?bsrc=hmior&chid=c162341
mStart Page = hxxp://websearch.pu-results.info/?pid=576&r=2013/03/08&hid=1887254495&lg=EN&cc=RS
uURLSearchHooks: UrlSearchHook Class: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
mWinlogon: Userinit = userinit.exe,
BHO: Torntv 2: {11111111-1111-1111-1111-110311551178} - C:\Program Files (x86)\Torntv 2\Torntv 2-bho.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Babylon toolbar helper: {2EECD738-5844-4a99-B4B6-146BF802613B} -
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: DefaultTab Browser Helper: {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Nikolic\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.4.0.5\AVG Secure Search_toolbar.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: delta Helper Object: {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.22.0\bh\delta.dll
BHO: Avira SearchFree Toolbar plus Web Protection: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO: SoundFrost: {d997c836-ff82-4519-b459-1482ba942a4f} - C:\Program Files (x86)\SoundFrost\SoundFrost.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.4.0.5\AVG Secure Search_toolbar.dll
TB: Avira SearchFree Toolbar plus Web Protection: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB: Delta Toolbar: {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.22.0\deltaTlbr.dll
uRun: [502136] C:\Users\Nikolic\AppData\Local\Temp\502136\svhost.exe
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
uRun: [NTRedirect] C:\Windows\SysWOW64\rundll32.exe "C:\Users\Nikolic\AppData\Roaming\BabSolution\Shared\NTRedirect.dll",Run
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRun: [ROCCAT Pyra Mouse] "C:\Program Files (x86)\ROCCAT\Pyra Mouse\PyraMonitor.EXE"
StartupFolder: C:\Users\Nikolic\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Rainmeter.lnk - C:\Program Files\Rainmeter\Rainmeter.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
LSP: mswsock.dll
TCP: NameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{04345F5B-E748-4B36-83FC-2F6ABFC2A561} : NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
TCP: Interfaces\{C22641C1-FDD3-4CDA-A5BF-32EC2D90D3F2} : DHCPNameServer = 192.168.1.1 0.0.0.0
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.4.0\ViProtocol.dll
AppInit_DLLs= c:\progra~3\browserdefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\browserdefender.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [New Value #1] "ctfmon"="CTFMON.EXE"
x64-Run: [New Value #2] C:\Windows\System32\ctfmon.exe
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Nikolic\AppData\Roaming\Mozilla\Firefox\Profiles\zd7jx12i.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Delta Search
FF - prefs.js: browser.startup.homepage - hxxp://start.search.us.com/v/2/?guid={0DCAB46B-80D1-4C19-9CF2-1AF3D29F13E8}&serpv=5
FF - prefs.js: keyword.URL - hxxp://search.us.com/serp?guid={D976C0E5-7AC2-4B6C-857B-1414408C0D48}&action=default_search&serpv=5&k=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.4.0\npsitesafety.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
FF - plugin: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
FF - plugin: C:\Users\Nikolic\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
FF - plugin: C:\Users\Nikolic\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: C:\Users\Nikolic\AppData\Local\TNT2\2.0.0.1534\npTNT2.dll
FF - plugin: C:\Users\Nikolic\AppData\Local\TNT2\2.0.0.1534\npTNT2Ghost.dll
FF - plugin: C:\Users\Nikolic\AppData\LocalLow\PowerChallenge\nppowerloader.dll
FF - plugin: C:\Users\Nikolic\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Nikolic\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Users\Nikolic\AppData\Roaming\Mozilla\plugins\npo1d.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-06-25 12:36; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=c4427409000000000000902b34751858&q=
FF - user.js: extensions.BabylonToolbar.id - c4427409000000000000902b34751858
FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}
FF - user.js: extensions.BabylonToolbar.instlDay - 15729
FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.7.2
FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.7.2
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.8.7.217:45:40
FF - user.js: extensions.BabylonToolbar.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar.tlbrId - base
FF - user.js: extensions.BabylonToolbar.instlRef - sst
FF - user.js: extensions.BabylonToolbar.dfltLng - en
FF - user.js: extensions.BabylonToolbar_i.excTlbr - false
FF - user.js: extensions.BabylonToolbar.excTlbr - false
FF - user.js: extensions.BabylonToolbar.admin - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=117023
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar.autoRvrt - false
FF - user.js: extensions.BabylonToolbar.rvrt - false
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extentions.y2layers.installId - ca4a8ed9-c6a5-4e03-8729-ec4562ca73b4
FF - user.js: extentions.y2layers.defaultEnableAppsList - twittube,buzzdock,YontooNewOffers
.
FF - user.js: browser.startup.homepage - hxxp://start.search.us.com/v/2/?guid={0DCAB46B-80D1-4C19-9CF2-1AF3D29F13E8}&serpv=5
FF - user.js: browser.startup.page - 1
FF - user.js: browser.newtab.url - file:///C:\Users\Nikolic\AppData\Local\TNT2\Common\pinnedSearch.htm
FF - user.js: keyword.URL - hxxp://search.us.com/serp?guid={D976C0E5-7AC2-4B6C-857B-1414408C0D48}&action=default_search&serpv=5&k=
FF - user.js: browser.search.defaultenginename - Search.us
FF - user.js: browser.keywordURLPromptDeclined - 1
FF - user.js: browser.newtab.url -
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - c4427409000000000000902b34751858
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15915
FF - user.js: extensions.delta.vrsn - 1.8.22.0
FF - user.js: extensions.delta.vrsni - 1.8.22.0
FF - user.js: extensions.delta.vrsnTs - 1.8.22.020:05:30
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - en
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=119776&tsp=4958
FF - user.js: extensions.delta_i.babExt -
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
============= SERVICES / DRIVERS ===============
.
R1 AppleCharger;AppleCharger;C:\Windows\System32\drivers\AppleCharger.sys [2012-12-5 21104]
R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2013-1-28 45856]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-12-11 283200]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2013-1-30 240640]
R2 BrowserDefendert;BrowserDefendert;C:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [2013-7-29 2827728]
R2 BstHdDrv;BlueStacks Hypervisor;C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [2012-5-30 75144]
R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [2012-5-30 385416]
R2 DefaultTabUpdate;DefaultTabUpdate;C:\Users\Nikolic\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe [2013-7-13 107520]
R2 Dokan;Dokan;C:\Windows\System32\drivers\dokan.sys [2011-1-10 120408]
R2 DokanMounter;DokanMounter;C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [2011-1-10 14848]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2013-6-28 2470736]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2011-12-8 607456]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe [2012-12-5 161560]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-6-20 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-6-20 701512]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2012-7-13 769432]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-4-16 39056]
R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-7-12 3289472]
R2 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-6-1 4153184]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2012-9-17 2365792]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-12-5 363800]
R2 vToolbarUpdater15.4.0;vToolbarUpdater15.4.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [2013-7-29 1616048]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2013-1-30 96256]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-6-20 25928]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-12-5 646248]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [2012-8-29 11880]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 DefaultTabSearch;DefaultTabSearch;C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe [2013-2-11 572928]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-6-21 162408]
S3 ALSysIO;ALSysIO;C:\Users\Nikolic\AppData\Local\Temp\ALSysIO64.sys [2013-7-13 17416]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 BstHdAndroidSvc;BlueStacks Android Service;C:\Program Files (x86)\BlueStacks\HD-Service.exe [2012-5-30 397704]
S3 cpudrv64;cpudrv64;C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [2011-6-2 17864]
S3 DrvAgent64;DrvAgent64;C:\Windows\SysWOW64\drivers\DrvAgent64.SYS [2013-4-28 21712]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2013-1-24 1038088]
S3 GVTDrv64;GVTDrv64;C:\Windows\GVTDrv64.sys [2012-12-5 30528]
S3 h647906;DragonRise H647906 AMD64 Driver;C:\Windows\System32\drivers\h647906.sys [2013-6-3 63856]
S3 h648101;DragonRise H648101 AMD64 Driver;C:\Windows\System32\drivers\h648101.sys [2013-6-3 65776]
S3 h648103;DragonRise H648103 AMD64 Driver;C:\Windows\System32\drivers\h648103.sys [2013-6-3 62960]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-12-5 160256]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
.
=============== File Associations ===============
.
FileExt: .ini: Applications\Rainmeter.exe="C:\Program Files\Rainmeter\Rainmeter.exe" "%1" [UserChoice]
.
=============== Created Last 30 ================
.
2013-08-10 21:40:45 -------- d-----w- C:\Users\Nikolic\AppData\Roaming\LolClient
2013-08-10 16:15:25 467984 ----a-w- C:\Windows\SysWow64\d3dx10_39.dll
2013-08-10 16:15:25 1493528 ----a-w- C:\Windows\SysWow64\D3DCompiler_39.dll
2013-08-10 16:15:23 3851784 ----a-w- C:\Windows\SysWow64\D3DX9_39.dll
2013-08-10 16:15:02 -------- d-sh--w- C:\Windows\SysWow64\AI_RecycleBin
2013-08-10 16:14:17 -------- d-----w- C:\Users\Nikolic\AppData\Local\PMB Files
2013-08-10 16:14:15 -------- d-----w- C:\ProgramData\PMB Files
2013-08-10 16:14:11 -------- d-----w- C:\Program Files (x86)\Pando Networks
2013-08-10 16:13:52 -------- d-----w- C:\Users\Nikolic\AppData\Roaming\Riot Games
2013-07-31 19:17:18 -------- d-----w- C:\Program Files (x86)\ROCCAT
2013-07-31 18:45:37 34656 ----a-w- C:\Windows\System32\TURegOpt.exe
2013-07-31 18:45:36 25952 ----a-w- C:\Windows\System32\authuitu.dll
2013-07-31 18:45:36 21344 ----a-w- C:\Windows\SysWow64\authuitu.dll
2013-07-31 18:45:15 -------- d-----w- C:\Program Files (x86)\TuneUp Utilities 2013
2013-07-31 18:35:48 -------- d-----w- C:\ProgramData\Informer Technologies, Inc
2013-07-31 18:35:32 -------- d-----w- C:\Program Files\Software Informer
2013-07-29 23:17:59 -------- d-----w- C:\Program Files (x86)\City Car Driving
2013-07-29 18:05:30 -------- d-----w- C:\Users\Nikolic\AppData\Roaming\BabSolution
2013-07-29 18:05:30 -------- d-----w- C:\Program Files (x86)\Delta
2013-07-29 18:05:29 -------- d-----w- C:\Users\Nikolic\AppData\Roaming\Delta
2013-07-29 18:05:29 -------- d-----w- C:\ProgramData\BrowserDefender
2013-07-29 18:05:06 -------- d-----w- C:\Program Files (x86)\Torntv 2
2013-07-28 21:57:47 -------- d-----w- C:\Users\Nikolic\AppData\Local\RadonLabs
2013-07-26 22:08:07 -------- d-----w- C:\Users\Nikolic\AppData\Local\4A Games
2013-07-26 22:04:25 -------- d-----w- C:\ProgramData\RELOADED
2013-07-26 21:12:21 -------- d-----w- C:\Program Files (x86)\Metro Last Light
2013-07-23 20:23:51 -------- d-s---w- C:\Windows\SysWow64\Microsoft
2013-07-23 20:20:21 -------- d-----w- C:\Users\Nikolic\AppData\Roaming\.minecraft
2013-07-23 11:04:10 165376 ----a-w- C:\Windows\SysWow64\unrar.dll
2013-07-23 11:04:07 -------- d-----w- C:\Program Files (x86)\K-Lite Codec Pack
2013-07-20 22:17:17 -------- d-----w- C:\Users\Nikolic\AppData\Roaming\Rainmeter
2013-07-20 22:17:02 -------- d-----w- C:\Program Files\Rainmeter
2013-07-20 22:16:39 -------- d-----w- C:\ProgramData\Package Cache
2013-07-20 22:12:04 -------- d-----w- C:\Rainmeter
2013-07-16 21:52:36 -------- d-----w- C:\Photoshop
2013-07-16 20:39:48 -------- d-----w- C:\Users\Nikolic\AppData\Roaming\Tomb Raider
2013-07-16 15:37:03 -------- d-----w- C:\temp
2013-07-16 15:35:42 -------- d-----w- C:\Tnlenterprises
2013-07-14 11:35:45 -------- d-----w- C:\Program Files\AVAST Software
2013-07-14 11:34:59 -------- d-----w- C:\ProgramData\AVAST Software
2013-07-14 10:48:47 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
2013-07-13 22:10:24 -------- d-----w- C:\Users\Nikolic\AppData\Local\Avg2013
2013-07-13 21:04:57 -------- d-----w- C:\Program Files (x86)\Crysis 3
2013-07-13 16:10:03 -------- d-----w- C:\Program Files (x86)\DefaultTab
2013-07-13 16:09:50 -------- d-----w- C:\Users\Nikolic\AppData\Roaming\DefaultTab
2013-07-13 16:09:34 -------- d-----w- C:\Program Files (x86)\MyPC Backup
2013-07-13 15:45:26 -------- d-----w- C:\Program Files\Core Temp
.
==================== Find3M ====================
.
2013-07-29 18:24:55 45856 ----a-w- C:\Windows\System32\drivers\avgtpx64.sys
2013-07-13 22:05:12 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-07-13 22:05:12 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-07-10 19:39:56 282296 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2013-07-10 19:39:56 282296 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2013-07-08 23:14:46 282296 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2013-07-08 15:46:35 76888 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2013-07-06 16:53:00 1200937 ----a-w- C:\Windows\unins000.exe
2013-07-03 21:55:51 468480 ----a-w- C:\Windows\System32\deployJava1.dll
2013-06-25 10:44:23 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-06-25 10:44:23 867240 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-06-25 10:44:23 789416 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-06-20 11:15:34 9154068480 ----a-w- C:\Users\Nikolic\AppData\Roaming\tmps.bin
2013-06-16 13:46:51 499712 ----a-w- C:\Windows\SysWow64\msvcp71.dll
2013-06-16 13:46:51 348160 ----a-w- C:\Windows\SysWow64\msvcr71.dll
2013-06-02 14:11:44 2434856 ----a-w- C:\Windows\SysWow64\pbsvc_bc2.exe
2013-04-18 14:56:12 40444 ----a-w- C:\Program Files (x86)\uninstall.exe
2011-10-22 11:06:32 68272 ----a-w- C:\Program Files (x86)\fraps64.dat
2011-10-22 11:06:32 231600 ----a-w- C:\Program Files (x86)\fraps32.dll
2011-10-22 11:06:32 185520 ----a-w- C:\Program Files (x86)\fraps64.dll
2011-10-22 11:06:30 2533040 ----a-w- C:\Program Files (x86)\fraps.exe
2011-10-22 11:04:34 140288 ----a-w- C:\Program Files (x86)\frapslcd.dll
.
============= FINISH: 14:17:00,59 ===============



mycity.rs/must-login.png



[edit by magna86: korigovan naslov teme]
naslov tipa "Hitno" zabranjeno je pravilnikom MyCity foruma.

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Pozdrav,
Ovo ni malo ne izgleda naivno kao sto se mozda cini. DDS pokazuje tragove 0access/sirefef rootkita a kako je isti skoro usavrsen i unapredjen, moguce je da nas ovde ceka i posao.






Arrow

U toku resavanja slucaja, zamolio bih te da se pridrzavas sledeceg:
Detaljno citati moja uputstva ( ili uputstva kolega koji ce me zamenjivati) i raditi iskljucivo po njima;
Ne traziti istovremeno pomoc na drugom mestu;
Nemoj koristiti druge programe za uklanjanje malware-a, osim onih za koje budes dobio uputstvo;
U toku intervencije ne koristiti USB memorijske uredjaje, dok to ne budem zatrazio;
Ukoliko ne odgovorim u roku od 48h, osvezi temu novim post-om;
Za vise informacija o pravilima Ambulante MyCity foruma: LINK

-------------------------------------------------------------------------------------


Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
[list=1]deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix;
u prozoru koji se otvori klikni "I Agree".

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.



Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku;
Nemoj kliktati u okviru ComboFix prozora dok radi jer to može usporiti rad alata;
Nemoj ponovo pokretati ComboFix na svoju ruku - javi se u temi bilo kakav problem da imaš tokom prvog pokretanja alata;
Ako nakon restarta dobijaš grešku prilikom startovanja pojedinih programa da su označeni za brisanje (Illegal operation attempted on a registry key that has been marked for deletion), onda ponovo restartuj sistem i to ce rešiti problem.

offline
  • Pridružio: 12 Avg 2013
  • Poruke: 19

Moze li se popopraviti/izleciti? I da li je opasnopo racunar?

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Napisano: 12 Avg 2013 14:48

Nikolic Nebojsa ::Moze li se popopraviti/izleciti? I da li je opasnopo racunar?
Sve sto treba da uradis jeste da procitas moju predhodnu poruku i doslovice pratis notes i uputstva.


Opis problema moze biti i hardverski problem ali idemo redom ...

Dopuna: 13 Avg 2013 21:35

bump!

Jesi li ti jos uvek sa nama? Da li je tebi i dalje potrebna pomoc?

Ko je trenutno na forumu
 

Ukupno su 1507 korisnika na forumu :: 48 registrovanih, 16 sakrivenih i 1443 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: AF-1, Andrija357, Apok, babaroga, Bane san, Ben Roj, Bobrock1, bokisha253, bufanje, comi_pfc, darkangel, Dimitrise93, doktor123, DonRumataEstorski, Dorcolac, Dovla, flash12, frenki1986, gomago, goxin, kikisp, krkalon, Kubovac, kunktator, kuntalo, mercedesamg, Mi lao shu, milenko crazy north, Milometer, opt1, Parker, pein, pera12345, raso7, Raso75, royst33, slonic_tonic, sombrero, Srle993, suton, tmanda323, Trpe Grozni, vathra, vladaa012, voja64, Webb, wolf431, šumar bk2