Rootkit hidden file

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
nelahrabovska
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 21 Lis 2012 20:36

Rootkit hidden file

#1 Příspěvek od nelahrabovska »

Dobrý den, prosím o pomoc. Po testu provedeném Avastem mi Avast našel přes 100 hozeb vysoké závažnosti Rootkit: hidden file.
Nejde s tím nic udělat, píše to - Chyba: přístup byl odepřen.
V počítačích se moc nevyznám, natož v odstraňování virů :-(

Avatar uživatele
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 Lis 2006 13:37
Místo/Bydliště: ČR

Re: Rootkit hidden file

#2 Příspěvek od Roli »

Zdravím, dej mi sem prosím log z Rsit nebo Frst.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

nelahrabovska
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 21 Lis 2012 20:36

Re: Rootkit hidden file

#3 Příspěvek od nelahrabovska »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Nela at 2015-01-11 15:06:12
Microsoft Windows 8.1
System drive C: has 879 GB (94%) free of 935 GB
Total RAM: 3976 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:06:41, on 11. 1. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Nela.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com/?pc=ACJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [BacKGround Agent] C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_60468DCD212E1A8C9619611CDBFC4ED2] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AtherosSvc - Windows (R) Win 7 DDK provider - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: CCDMonitorService - Acer Incorporated - C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppIntegrationService - TODO: <Company name> - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Launch Manager Service (LMSvc) - Acer Incorporate - C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 9396 bytes

======Listing Processes======





wininit.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe"
"C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe"
"C:\Program Files\Elantech\ETDService.exe"
dashost.exe {b0ca2c9a-5279-4cd6-a94f393dee11ed0d}
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe"
"C:\Windows\system32\mfevtps.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe"
"C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
ngservice.exe pipeserver
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe" "C:\Users\Nela\AppData\Local\AOP SDK\Acer Infra\acer\SyncAgent" S-1-5-21-3660941846-2406076726-2113872896-1001 468 532 "C:\ProgramData\acer\CCD"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv

C:\Windows\System32\WinLogon.exe -SpecialSession
-hiberboot
atieclxx
taskhostex.exe
"C:\Program Files\Elantech\ETDCtrl.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Elantech\ETDTouch.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Acer\Acer Launch Manager\LMTray.exe"
"C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="1204.0.668919972\114381934" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,17,38 --gpu-vendor-id=0x8086 --gpu-device-id=0x0a16 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3355 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/QUIC/Disabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_12/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="1204.1.1126747763\704712104" /prefetch:673131151
"C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Windows\System32\WWAHost.exe" -ServerName:Windows.Store
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17499_x64__8wekyb3d8bbwe\glcnd.exe" -ServerName:Microsoft.Reader.AppXtszmc7avrx02s7n8gch63tzwg517wd9k.mca
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
taskhost.exe
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GCM/Enabled/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/PP_Ethersuggest_A1_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/Disabled/RememberCertificateErrorDecisions/Default/SHA1ToolbarUIJanuary2017/Warning/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_12/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="1204.38.981643356\256131311" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GCM/Enabled/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/PP_Ethersuggest_A1_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/Disabled/RememberCertificateErrorDecisions/Default/SHA1ToolbarUIJanuary2017/Warning/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_12/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="1204.43.1383893859\327172629" /prefetch:673131151
taskeng.exe {BE489147-6367-4BAA-89CF-BEF8919CE798}
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe16_ Global\UsGthrCtrlFltPipeMssGthrPipe16 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 560 564 572 65536 568

"C:\Users\Nela\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-01-10 705448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-01-10 586968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2013-11-19 771056]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-08-27 13647576]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2013-09-06 2890056]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [2013-09-07 132736]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GoogleChromeAutoLaunch_60468DCD212E1A8C9619611CDBFC4ED2"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2014-12-06 856904]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2014-12-12 7394584]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"BacKGround Agent"=C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [2014-12-19 62208]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-01-10 5227112]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [2013-09-07 132736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2013-11-13 624640]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefire]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfevtp]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLinkedConnections"=1
"DisableTaskMgr"=0
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"mixer4"=wdmaud.drv
"midi4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-01-11 15:06:13 ----D---- C:\Program Files\trend micro
2015-01-11 15:06:12 ----D---- C:\rsit
2015-01-11 13:35:57 ----A---- C:\Windows\system32\drivers\mwac.sys
2015-01-11 13:35:57 ----A---- C:\Windows\system32\drivers\mbam.sys
2015-01-11 13:35:56 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-11 13:11:54 ----D---- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-01-11 13:11:54 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2015-01-11 13:08:16 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2015-01-10 22:00:58 ----D---- C:\Windows\SYSWOW64\vbox
2015-01-10 22:00:58 ----D---- C:\Windows\system32\vbox
2015-01-10 21:44:24 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-01-10 20:02:55 ----D---- C:\Windows\system32\MRT
2015-01-10 20:02:50 ----A---- C:\Windows\system32\MRT.exe
2015-01-10 19:40:12 ----D---- C:\Users\Nela\AppData\Roaming\Dropbox
2015-01-10 19:30:08 ----D---- C:\Users\Nela\AppData\Roaming\AVAST Software
2015-01-10 19:28:38 ----A---- C:\Windows\system32\drivers\aswVmm.sys
2015-01-10 19:28:38 ----A---- C:\Windows\system32\drivers\aswStm.sys
2015-01-10 19:28:38 ----A---- C:\Windows\system32\drivers\aswSP.sys
2015-01-10 19:28:38 ----A---- C:\Windows\system32\drivers\aswsnx.sys
2015-01-10 19:28:38 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2015-01-10 19:28:38 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2015-01-10 19:28:38 ----A---- C:\Windows\system32\drivers\aswmonflt.sys
2015-01-10 19:28:38 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2015-01-10 19:28:36 ----A---- C:\Windows\system32\aswBoot.exe
2015-01-10 19:28:31 ----A---- C:\Windows\avastSS.scr
2015-01-10 19:26:55 ----D---- C:\Program Files\AVAST Software
2015-01-10 19:25:53 ----D---- C:\ProgramData\AVAST Software
2015-01-10 14:59:53 ----A---- C:\Windows\system32\winbici.dll
2015-01-10 14:59:24 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2015-01-10 14:59:23 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2015-01-10 14:59:22 ----A---- C:\Windows\system32\SyncEngine.dll
2015-01-10 14:59:18 ----A---- C:\Windows\system32\winmde.dll
2015-01-10 14:59:18 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-01-10 14:59:18 ----A---- C:\Windows\system32\authui.dll
2015-01-10 14:59:17 ----A---- C:\Windows\system32\wmpmde.dll
2015-01-10 14:59:17 ----A---- C:\Windows\system32\ubpm.dll
2015-01-10 14:59:17 ----A---- C:\Windows\system32\SystemEventsBrokerServer.dll
2015-01-10 14:59:17 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-01-10 14:59:17 ----A---- C:\Windows\system32\audiosrv.dll
2015-01-10 14:59:16 ----A---- C:\Windows\SYSWOW64\winmde.dll
2015-01-10 14:59:16 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-01-10 14:59:16 ----A---- C:\Windows\system32\bisrv.dll
2015-01-10 14:59:15 ----A---- C:\Windows\system32\wlansvc.dll
2015-01-10 14:59:15 ----A---- C:\Windows\system32\ploptin.dll
2015-01-10 14:59:15 ----A---- C:\Windows\system32\oleaut32.dll
2015-01-10 14:59:15 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2015-01-10 14:59:14 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2015-01-10 14:59:14 ----A---- C:\Windows\system32\psmsrv.dll
2015-01-10 14:59:14 ----A---- C:\Windows\system32\mfds.dll
2015-01-10 14:59:14 ----A---- C:\Windows\system32\lsasrv.dll
2015-01-10 14:59:13 ----A---- C:\Windows\SYSWOW64\mfds.dll
2015-01-10 14:59:13 ----A---- C:\Windows\system32\Windows.Graphics.dll
2015-01-10 14:59:13 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2015-01-10 14:59:12 ----A---- C:\Windows\SYSWOW64\Windows.Graphics.dll
2015-01-10 14:59:12 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-01-10 14:59:12 ----A---- C:\Windows\system32\rastls.dll
2015-01-10 14:59:11 ----A---- C:\Windows\system32\msieftp.dll
2015-01-10 14:59:11 ----A---- C:\Windows\system32\mispace.dll
2015-01-10 14:59:11 ----A---- C:\Windows\system32\drivers\ipnat.sys
2015-01-10 14:59:11 ----A---- C:\Windows\system32\bi.dll
2015-01-10 14:59:10 ----A---- C:\Windows\SYSWOW64\rastls.dll
2015-01-10 14:59:10 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2015-01-10 14:59:10 ----A---- C:\Windows\SYSWOW64\mispace.dll
2015-01-10 14:59:10 ----A---- C:\Windows\system32\drivers\BtaMPM.sys
2015-01-10 14:59:09 ----A---- C:\Windows\system32\deviceregistration.dll
2015-01-10 14:56:13 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2015-01-10 14:56:10 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2015-01-10 14:56:04 ----A---- C:\Windows\system32\schedsvc.dll
2015-01-10 14:56:04 ----A---- C:\Windows\system32\mfsvr.dll
2015-01-10 14:56:04 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2015-01-10 14:56:03 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2015-01-10 14:56:03 ----A---- C:\Windows\system32\SettingSyncHost.exe
2015-01-10 14:56:03 ----A---- C:\Windows\system32\SettingSyncCore.dll
2015-01-10 14:56:03 ----A---- C:\Windows\system32\MFMediaEngine.dll
2015-01-10 14:56:02 ----A---- C:\Windows\SYSWOW64\SettingSyncHost.exe
2015-01-10 14:56:02 ----A---- C:\Windows\SYSWOW64\SettingSyncCore.dll
2015-01-10 14:56:02 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2015-01-10 14:56:02 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2015-01-10 14:56:02 ----A---- C:\Windows\system32\ReAgent.dll
2015-01-10 14:56:02 ----A---- C:\Windows\system32\pnrpsvc.dll
2015-01-10 14:56:02 ----A---- C:\Windows\system32\MsSpellCheckingFacility.dll
2015-01-10 14:56:02 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2015-01-10 14:56:01 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2015-01-10 14:56:01 ----A---- C:\Windows\SYSWOW64\WSClient.dll
2015-01-10 14:56:01 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2015-01-10 14:56:01 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-01-10 14:56:01 ----A---- C:\Windows\system32\WSClient.dll
2015-01-10 14:56:01 ----A---- C:\Windows\system32\reseteng.dll
2015-01-10 14:56:01 ----A---- C:\Windows\system32\hal.dll
2015-01-10 14:56:00 ----A---- C:\Windows\SYSWOW64\MsSpellCheckingFacility.dll
2015-01-10 14:56:00 ----A---- C:\Windows\system32\sti.dll
2015-01-10 14:56:00 ----A---- C:\Windows\system32\ntdll.dll
2015-01-10 14:56:00 ----A---- C:\Windows\system32\easinvoker.exe
2015-01-10 14:56:00 ----A---- C:\Windows\system32\drivers\rdbss.sys
2015-01-10 14:55:59 ----A---- C:\Windows\SYSWOW64\sti.dll
2015-01-10 14:55:59 ----A---- C:\Windows\SYSWOW64\OEMLicense.dll
2015-01-10 14:55:59 ----A---- C:\Windows\SYSWOW64\easwrt.dll
2015-01-10 14:55:59 ----A---- C:\Windows\system32\OEMLicense.dll
2015-01-10 14:55:59 ----A---- C:\Windows\system32\easwrt.dll
2015-01-10 14:55:59 ----A---- C:\Windows\system32\drivers\USBXHCI.SYS
2015-01-10 14:55:00 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2015-01-10 14:55:00 ----A---- C:\Windows\system32\d2d1.dll
2015-01-10 14:54:59 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2015-01-10 14:54:59 ----A---- C:\Windows\system32\d3d10warp.dll
2015-01-10 14:54:58 ----A---- C:\Windows\system32\imagehlp.dll
2015-01-10 14:54:57 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2015-01-10 14:54:54 ----A---- C:\Windows\system32\mshtml.dll
2015-01-10 14:54:53 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-01-10 14:54:46 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-01-10 14:54:46 ----A---- C:\Windows\system32\mshtmled.dll
2015-01-10 14:54:08 ----A---- C:\Windows\system32\wuaueng.dll
2015-01-10 14:54:07 ----A---- C:\Windows\SYSWOW64\explorer.exe
2015-01-10 14:54:07 ----A---- C:\Windows\explorer.exe
2015-01-10 14:54:06 ----A---- C:\Windows\system32\workfolderssvc.dll
2015-01-10 14:54:06 ----A---- C:\Windows\system32\mfasfsrcsnk.dll
2015-01-10 14:54:05 ----A---- C:\Windows\SYSWOW64\mfasfsrcsnk.dll
2015-01-10 14:54:04 ----A---- C:\Windows\system32\d3d9.dll
2015-01-10 14:54:02 ----A---- C:\Windows\system32\Windows.Web.Http.dll
2015-01-10 14:54:02 ----A---- C:\Windows\system32\TSWorkspace.dll
2015-01-10 14:54:01 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2015-01-10 14:54:01 ----A---- C:\Windows\system32\iuilp.dll
2015-01-10 14:54:01 ----A---- C:\Windows\system32\dnsapi.dll
2015-01-10 14:54:00 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2015-01-10 14:54:00 ----A---- C:\Windows\system32\Windows.Media.dll
2015-01-10 14:54:00 ----A---- C:\Windows\system32\UIAutomationCore.dll
2015-01-10 14:53:59 ----A---- C:\Windows\SYSWOW64\user32.dll
2015-01-10 14:53:59 ----A---- C:\Windows\system32\WWAHost.exe
2015-01-10 14:53:59 ----A---- C:\Windows\system32\WorkfoldersControl.dll
2015-01-10 14:53:59 ----A---- C:\Windows\system32\d3d10level9.dll
2015-01-10 14:53:58 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2015-01-10 14:53:58 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2015-01-10 14:53:58 ----A---- C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2015-01-10 14:53:58 ----A---- C:\Windows\system32\eapphost.dll
2015-01-10 14:53:57 ----A---- C:\Windows\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2015-01-10 14:53:57 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2015-01-10 14:53:57 ----A---- C:\Windows\system32\kd_02_8086.dll
2015-01-10 14:53:57 ----A---- C:\Windows\system32\drivers\acpi.sys
2015-01-10 14:53:57 ----A---- C:\Windows\system32\AudioSes.dll
2015-01-10 14:53:56 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2015-01-10 14:53:56 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2015-01-10 14:53:56 ----A---- C:\Windows\system32\tsmf.dll
2015-01-10 14:53:56 ----A---- C:\Windows\system32\eapp3hst.dll
2015-01-10 14:53:56 ----A---- C:\Windows\system32\drivers\portcls.sys
2015-01-10 14:53:56 ----A---- C:\Windows\system32\comdlg32.dll
2015-01-10 14:53:55 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2015-01-10 14:53:55 ----A---- C:\Windows\SYSWOW64\tsmf.dll
2015-01-10 14:53:55 ----A---- C:\Windows\system32\wintrust.dll
2015-01-10 14:53:55 ----A---- C:\Windows\system32\apphelp.dll
2015-01-10 14:53:54 ----A---- C:\Windows\SYSWOW64\ncryptsslp.dll
2015-01-10 14:53:54 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2015-01-10 14:53:54 ----A---- C:\Windows\system32\profsvc.dll
2015-01-10 14:53:54 ----A---- C:\Windows\system32\pcsvDevice.dll
2015-01-10 14:53:54 ----A---- C:\Windows\system32\ncryptsslp.dll
2015-01-10 14:53:54 ----A---- C:\Windows\system32\drivers\srv.sys
2015-01-10 14:53:53 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-01-10 14:53:53 ----A---- C:\Windows\SYSWOW64\Windows.Web.Http.dll
2015-01-10 14:53:53 ----A---- C:\Windows\SYSWOW64\eapphost.dll
2015-01-10 14:53:53 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-01-10 14:53:53 ----A---- C:\Windows\system32\samsrv.dll
2015-01-10 14:53:53 ----A---- C:\Windows\system32\msched.dll
2015-01-10 14:53:53 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2015-01-10 14:53:53 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2015-01-10 14:53:52 ----A---- C:\Windows\system32\wldp.dll
2015-01-10 14:53:52 ----A---- C:\Windows\system32\ipnathlp.dll
2015-01-10 14:53:52 ----A---- C:\Windows\system32\iphlpsvc.dll
2015-01-10 14:53:52 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2015-01-10 14:53:52 ----A---- C:\Windows\system32\drivers\bthport.sys
2015-01-10 14:53:51 ----A---- C:\Windows\system32\wuauclt.exe
2015-01-10 14:53:51 ----A---- C:\Windows\system32\TSWbPrxy.exe
2015-01-10 14:53:51 ----A---- C:\Windows\system32\drivers\stornvme.sys
2015-01-10 14:53:51 ----A---- C:\Windows\system32\dafWfdProvider.dll
2015-01-10 14:53:51 ----A---- C:\Windows\system32\dafBth.dll
2015-01-10 14:53:50 ----A---- C:\Windows\SYSWOW64\shsetup.dll
2015-01-10 14:53:50 ----A---- C:\Windows\system32\WUSettingsProvider.dll
2015-01-10 14:53:50 ----A---- C:\Windows\system32\shsetup.dll
2015-01-10 14:53:50 ----A---- C:\Windows\system32\eappcfg.dll
2015-01-10 14:53:50 ----A---- C:\Windows\system32\dnsrslvr.dll
2015-01-10 14:53:49 ----A---- C:\Windows\SYSWOW64\eappgnui.dll
2015-01-10 14:53:49 ----A---- C:\Windows\SYSWOW64\eappcfg.dll
2015-01-10 14:53:49 ----A---- C:\Windows\SYSWOW64\eapp3hst.dll
2015-01-10 14:53:49 ----A---- C:\Windows\system32\WiFiDisplay.dll
2015-01-10 14:53:49 ----A---- C:\Windows\system32\eappgnui.dll
2015-01-10 14:53:47 ----A---- C:\Windows\SYSWOW64\ftp.exe
2015-01-10 14:53:47 ----A---- C:\Windows\system32\wucltux.dll
2015-01-10 14:53:47 ----A---- C:\Windows\system32\WorkFoldersShell.dll
2015-01-10 14:53:46 ----A---- C:\Windows\system32\rdpclip.exe
2015-01-10 14:53:46 ----A---- C:\Windows\system32\ftp.exe
2015-01-10 14:53:45 ----A---- C:\Windows\SYSWOW64\miutils.dll
2015-01-10 14:53:45 ----A---- C:\Windows\system32\miutils.dll
2015-01-10 14:51:42 ----A---- C:\Windows\system32\sppsvc.exe
2015-01-10 14:51:42 ----A---- C:\Windows\system32\drivers\tcpip.sys
2015-01-10 14:51:41 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2015-01-10 14:51:41 ----A---- C:\Windows\system32\mfcore.dll
2015-01-10 14:51:41 ----A---- C:\Windows\system32\combase.dll
2015-01-10 14:51:40 ----A---- C:\Windows\SYSWOW64\combase.dll
2015-01-10 14:51:40 ----A---- C:\Windows\system32\mstscax.dll
2015-01-10 14:51:40 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2015-01-10 14:51:39 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-01-10 14:51:39 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll
2015-01-10 14:51:39 ----A---- C:\Windows\system32\dbghelp.dll
2015-01-10 14:51:39 ----A---- C:\Windows\system32\dbgeng.dll
2015-01-10 14:51:38 ----A---- C:\Windows\SYSWOW64\Faultrep.dll
2015-01-10 14:51:38 ----A---- C:\Windows\SYSWOW64\dbghelp.dll
2015-01-10 14:51:38 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2015-01-10 14:51:38 ----A---- C:\Windows\system32\WerFault.exe
2015-01-10 14:51:38 ----A---- C:\Windows\system32\swprv.dll
2015-01-10 14:51:38 ----A---- C:\Windows\system32\mfps.dll
2015-01-10 14:51:38 ----A---- C:\Windows\system32\Faultrep.dll
2015-01-10 14:51:37 ----A---- C:\Windows\SYSWOW64\WerFault.exe
2015-01-10 14:51:37 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-01-10 14:51:37 ----A---- C:\Windows\SYSWOW64\rdpencom.dll
2015-01-10 14:51:37 ----A---- C:\Windows\SYSWOW64\DWWIN.EXE
2015-01-10 14:51:37 ----A---- C:\Windows\system32\tsgqec.dll
2015-01-10 14:51:37 ----A---- C:\Windows\system32\rdvidcrl.dll
2015-01-10 14:51:37 ----A---- C:\Windows\system32\rdpencom.dll
2015-01-10 14:51:37 ----A---- C:\Windows\system32\DWWIN.EXE
2015-01-10 14:51:37 ----A---- C:\Windows\system32\drivers\volsnap.sys
2015-01-10 14:51:36 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2015-01-10 14:51:36 ----A---- C:\Windows\system32\sppcomapi.dll
2015-01-10 14:51:26 ----A---- C:\Windows\system32\twinui.appcore.dll
2015-01-10 14:51:26 ----A---- C:\Windows\system32\actxprxy.dll
2015-01-10 14:51:25 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2015-01-10 14:51:25 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2015-01-10 14:50:55 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-01-10 14:50:55 ----A---- C:\Windows\system32\msxml3.dll
2015-01-10 14:50:26 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2015-01-10 14:50:26 ----A---- C:\Windows\system32\msdrm.dll
2015-01-10 14:50:05 ----A---- C:\Windows\system32\IKEEXT.DLL
2015-01-10 14:50:05 ----A---- C:\Windows\system32\drivers\wfplwfs.sys
2015-01-10 14:50:05 ----A---- C:\Windows\system32\BFE.DLL
2015-01-10 14:50:03 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-01-10 14:50:03 ----A---- C:\Windows\system32\mfplat.dll
2015-01-10 14:49:56 ----A---- C:\Windows\SYSWOW64\AppxAllUserStore.dll
2015-01-10 14:49:56 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2015-01-10 14:49:56 ----A---- C:\Windows\system32\AppxAllUserStore.dll
2015-01-10 14:49:50 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-01-10 14:49:50 ----A---- C:\Windows\system32\dwmcore.dll
2015-01-10 14:49:49 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-01-10 14:49:49 ----A---- C:\Windows\system32\SettingsHandlers.dll
2015-01-10 14:49:48 ----A---- C:\Windows\system32\dcomp.dll
2015-01-10 14:49:47 ----A---- C:\Windows\system32\wlidcli.dll
2015-01-10 14:49:47 ----A---- C:\Windows\system32\SkyDrive.exe
2015-01-10 14:49:47 ----A---- C:\Windows\system32\msftedit.dll
2015-01-10 14:49:46 ----A---- C:\Windows\system32\WMPDMC.exe
2015-01-10 14:49:45 ----A---- C:\Windows\SYSWOW64\dcomp.dll
2015-01-10 14:49:45 ----A---- C:\Windows\system32\winresume.exe
2015-01-10 14:49:44 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2015-01-10 14:49:44 ----A---- C:\Windows\system32\wpncore.dll
2015-01-10 14:49:44 ----A---- C:\Windows\system32\drivers\spaceport.sys
2015-01-10 14:49:44 ----A---- C:\Windows\system32\AppXDeploymentClient.dll
2015-01-10 14:49:43 ----A---- C:\Windows\SYSWOW64\WMPDMC.exe
2015-01-10 14:49:43 ----A---- C:\Windows\SYSWOW64\AppXDeploymentClient.dll
2015-01-10 14:49:43 ----A---- C:\Windows\system32\drivers\intelpep.sys
2015-01-10 14:49:42 ----A---- C:\Windows\system32\drivers\SerCx2.sys
2015-01-10 14:49:42 ----A---- C:\Windows\system32\drivers\pdc.sys
2015-01-10 14:49:42 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2015-01-10 14:49:41 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2015-01-10 14:49:41 ----A---- C:\Windows\SYSWOW64\Display.dll
2015-01-10 14:49:41 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2015-01-10 14:49:41 ----A---- C:\Windows\SYSWOW64\CredentialMigrationHandler.dll
2015-01-10 14:49:41 ----A---- C:\Windows\system32\dxgi.dll
2015-01-10 14:49:41 ----A---- C:\Windows\system32\Display.dll
2015-01-10 14:49:41 ----A---- C:\Windows\system32\d3d11.dll
2015-01-10 14:49:41 ----A---- C:\Windows\system32\CredentialMigrationHandler.dll
2015-01-10 14:49:40 ----A---- C:\Windows\SYSWOW64\wlidcli.dll
2015-01-10 14:47:48 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-01-10 14:47:48 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-01-10 14:47:48 ----A---- C:\Windows\system32\KernelBase.dll
2015-01-10 14:47:48 ----A---- C:\Windows\system32\kernel32.dll
2015-01-10 14:47:45 ----A---- C:\Windows\system32\WMPhoto.dll
2015-01-10 14:47:44 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-01-10 14:47:42 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-01-10 14:47:42 ----A---- C:\Windows\system32\gdi32.dll
2015-01-10 14:47:40 ----A---- C:\Windows\system32\winload.exe
2015-01-10 14:47:38 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-01-10 14:47:37 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-01-10 14:47:37 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-01-10 14:47:37 ----A---- C:\Windows\system32\iertutil.dll
2015-01-10 14:47:37 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-01-10 14:47:36 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-01-10 14:47:36 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-01-10 14:47:36 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-01-10 14:47:33 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-01-10 14:47:33 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-01-10 14:47:33 ----A---- C:\Windows\system32\urlmon.dll
2015-01-10 14:47:33 ----A---- C:\Windows\system32\iernonce.dll
2015-01-10 14:47:32 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-01-10 14:47:32 ----A---- C:\Windows\system32\msfeeds.dll
2015-01-10 14:47:32 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-01-10 14:47:31 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-01-10 14:47:31 ----A---- C:\Windows\system32\iesetup.dll
2015-01-10 14:47:29 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-01-10 14:47:29 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-01-10 14:47:29 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-01-10 14:47:29 ----A---- C:\Windows\system32\ie4uinit.exe
2015-01-10 14:47:28 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-01-10 14:47:28 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-01-10 14:47:27 ----A---- C:\Windows\system32\ieUnatt.exe
2015-01-10 14:47:27 ----A---- C:\Windows\system32\ieframe.dll
2015-01-10 14:47:26 ----A---- C:\Windows\system32\jscript9diag.dll
2015-01-10 14:47:26 ----A---- C:\Windows\system32\jscript9.dll
2015-01-10 14:47:26 ----A---- C:\Windows\system32\ieapfltr.dll
2015-01-10 14:47:25 ----A---- C:\Windows\system32\wininet.dll
2015-01-10 14:47:25 ----A---- C:\Windows\system32\msrating.dll
2015-01-10 14:47:25 ----A---- C:\Windows\system32\jsproxy.dll
2015-01-10 14:46:26 ----A---- C:\Windows\SYSWOW64\WSShared.dll
2015-01-10 14:46:26 ----A---- C:\Windows\system32\WSShared.dll
2015-01-10 14:46:26 ----A---- C:\Windows\system32\WSService.dll
2015-01-10 14:46:25 ----A---- C:\Windows\system32\WSCollect.exe
2015-01-10 14:46:24 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-01-10 14:46:24 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-01-10 14:45:51 ----A---- C:\Windows\system32\drivers\WdFilter.sys
2015-01-10 14:45:49 ----A---- C:\Windows\system32\drivers\WdBoot.sys
2015-01-10 14:45:47 ----A---- C:\Windows\system32\drivers\WdNisDrv.sys
2015-01-10 14:44:49 ----A---- C:\Windows\system32\shell32.dll
2015-01-10 14:44:47 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-01-10 14:44:45 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-01-10 14:44:45 ----A---- C:\Windows\SYSWOW64\qedit.dll
2015-01-10 14:44:45 ----A---- C:\Windows\SYSWOW64\pcaui.exe
2015-01-10 14:44:45 ----A---- C:\Windows\system32\win32k.sys
2015-01-10 14:44:45 ----A---- C:\Windows\system32\vbscript.dll
2015-01-10 14:44:45 ----A---- C:\Windows\system32\qedit.dll
2015-01-10 14:44:45 ----A---- C:\Windows\system32\pcaui.exe
2015-01-10 14:44:41 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2015-01-10 14:44:41 ----A---- C:\Windows\system32\scrrun.dll
2015-01-10 14:44:41 ----A---- C:\Windows\system32\drivers\ntfs.sys
2015-01-10 14:44:40 ----A---- C:\Windows\system32\drivers\clfs.sys
2015-01-10 14:44:38 ----A---- C:\Windows\system32\Windows.UI.Search.dll
2015-01-10 14:44:38 ----A---- C:\Windows\system32\twinui.dll
2015-01-10 14:44:37 ----A---- C:\Windows\SYSWOW64\twinui.dll
2015-01-10 14:44:36 ----A---- C:\Windows\SYSWOW64\Windows.UI.Search.dll
2015-01-10 14:44:36 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2015-01-10 14:44:36 ----A---- C:\Windows\SYSWOW64\propsys.dll
2015-01-10 14:44:36 ----A---- C:\Windows\SYSWOW64\MrmCoreR.dll
2015-01-10 14:44:36 ----A---- C:\Windows\system32\SearchFolder.dll
2015-01-10 14:44:36 ----A---- C:\Windows\system32\propsys.dll
2015-01-10 14:44:36 ----A---- C:\Windows\system32\MrmCoreR.dll
2015-01-10 14:43:05 ----A---- C:\Windows\system32\crypt32.dll
2015-01-10 14:43:04 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-01-10 14:41:32 ----A---- C:\Windows\system32\uDWM.dll
2015-01-10 14:41:31 ----A---- C:\Windows\SYSWOW64\mdmregistration.dll
2015-01-10 14:41:31 ----A---- C:\Windows\system32\mdmregistration.dll
2015-01-10 14:41:31 ----A---- C:\Windows\system32\MDMAgent.exe
2015-01-10 14:41:27 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2015-01-10 14:41:27 ----A---- C:\Windows\system32\poqexec.exe
2015-01-09 22:16:59 ----D---- C:\AdwCleaner
2015-01-09 21:18:53 ----D---- C:\ProgramData\Malwarebytes
2015-01-09 20:39:45 ----D---- C:\Users\Nela\AppData\Roaming\GetRightToGo
2015-01-09 20:38:51 ----D---- C:\Windows\system32\log
2015-01-09 20:08:08 ----D---- C:\Program Files (x86)\38e863ea-1142-4268-8a20-020aed50ce15
2015-01-09 20:06:22 ----D---- C:\Users\Nela\AppData\Roaming\Opera Software
2015-01-09 20:04:46 ----D---- C:\Program Files (x86)\Opera
2015-01-09 20:02:02 ----D---- C:\Users\Nela\AppData\Roaming\ImperiaOnline
2015-01-09 19:09:02 ----D---- C:\Users\Nela\AppData\Roaming\ATI
2015-01-09 19:09:02 ----D---- C:\ProgramData\ATI
2015-01-09 19:07:38 ----D---- C:\Program Files (x86)\Adobe
2015-01-09 19:07:18 ----D---- C:\ProgramData\Adobe
2015-01-08 21:59:55 ----D---- C:\Program Files (x86)\Microsoft Works
2015-01-08 21:59:12 ----D---- C:\Program Files (x86)\Microsoft Visual Studio
2015-01-08 21:57:44 ----D---- C:\Windows\PCHEALTH
2015-01-08 21:53:49 ----D---- C:\Program Files\Microsoft Office
2015-01-08 21:53:29 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2015-01-08 21:51:19 ----D---- C:\ProgramData\Microsoft Help
2015-01-08 21:50:59 ----RHD---- C:\MSOCache
2015-01-08 18:05:58 ----D---- C:\KMPlayer
2015-01-08 16:47:26 ----D---- C:\Users\Nela\AppData\Roaming\WinRAR
2015-01-08 16:40:01 ----D---- C:\Program Files\WinRAR
2015-01-08 16:23:43 ----D---- C:\Users\Nela\AppData\Roaming\WinRARPasswordCracker.com
2015-01-08 16:19:12 ----D---- C:\Program Files (x86)\uTorrent
2015-01-08 15:52:09 ----D---- C:\Program Files\CCleaner
2015-01-08 15:47:00 ----D---- C:\Program Files (x86)\WinRAR
2015-01-08 15:10:36 ----D---- C:\Users\Nela\AppData\Roaming\uTorrent
2015-01-08 15:02:14 ----D---- C:\MOJE PROGRAMY
2015-01-08 15:01:11 ----D---- C:\Program Files (x86)\Mp3tag
2015-01-08 13:00:26 ----D---- C:\Program Files (x86)\Google
2015-01-08 12:58:26 ----D---- C:\Users\Nela\AppData\Roaming\Macromedia
2015-01-08 12:41:46 ----D---- C:\Users\Nela\AppData\Roaming\Atheros
2015-01-08 12:41:07 ----D---- C:\ProgramData\OEM_YAHOO
2015-01-08 12:40:14 ----D---- C:\Users\Nela\AppData\Roaming\Adobe
2015-01-08 12:37:47 ----SD---- C:\Users\Nela\AppData\Roaming\Microsoft

======List of files/folders modified in the last 1 month======

2015-01-11 15:06:13 ----RD---- C:\Program Files
2015-01-11 15:06:06 ----D---- C:\Windows\Prefetch
2015-01-11 15:00:00 ----D---- C:\Windows\system32\sru
2015-01-11 14:24:05 ----D---- C:\Windows\Microsoft.NET
2015-01-11 14:22:58 ----RSD---- C:\Windows\assembly
2015-01-11 14:14:36 ----D---- C:\Windows\Logs
2015-01-11 13:36:12 ----D---- C:\Windows\Temp
2015-01-11 13:35:57 ----D---- C:\Windows\system32\drivers
2015-01-11 13:35:56 ----RD---- C:\Program Files (x86)
2015-01-11 13:34:46 ----HD---- C:\Program Files\WindowsApps
2015-01-11 13:34:44 ----D---- C:\Windows\AppReadiness
2015-01-11 13:11:54 ----HD---- C:\ProgramData
2015-01-11 11:55:48 ----D---- C:\Windows\system32\config
2015-01-11 11:53:37 ----D---- C:\Windows\CbsTemp
2015-01-11 11:53:17 ----D---- C:\Windows\system32\catroot2
2015-01-11 11:53:04 ----D---- C:\Windows\WinSxS
2015-01-10 23:47:10 ----RD---- C:\Windows\System32
2015-01-10 23:47:10 ----D---- C:\Windows\Inf
2015-01-10 23:47:10 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-01-10 22:32:46 ----SHD---- C:\System Volume Information
2015-01-10 22:00:58 ----D---- C:\Windows\SysWOW64
2015-01-10 20:57:52 ----D---- C:\Windows\SYSWOW64\sk-SK
2015-01-10 20:57:52 ----D---- C:\Windows\SYSWOW64\en-US
2015-01-10 20:57:52 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-01-10 20:57:51 ----D---- C:\Windows\system32\sk-SK
2015-01-10 20:57:51 ----D---- C:\Windows\system32\en-US
2015-01-10 20:57:51 ----D---- C:\Windows\system32\cs-CZ
2015-01-10 20:57:45 ----D---- C:\Windows\system32\Boot
2015-01-10 20:57:44 ----D---- C:\Windows\MediaViewer
2015-01-10 20:57:44 ----D---- C:\Windows\FileManager
2015-01-10 20:57:44 ----D---- C:\Windows\Camera
2015-01-10 20:57:42 ----D---- C:\Windows\SYSWOW64\Dism
2015-01-10 20:57:42 ----D---- C:\Windows\system32\Dism
2015-01-10 20:57:41 ----D---- C:\Windows\apppatch
2015-01-10 20:57:39 ----D---- C:\Program Files\Internet Explorer
2015-01-10 20:57:39 ----D---- C:\Program Files (x86)\Internet Explorer
2015-01-10 20:57:26 ----D---- C:\Program Files\Windows Defender
2015-01-10 20:57:26 ----D---- C:\Program Files (x86)\Windows Defender
2015-01-10 20:57:24 ----RD---- C:\Windows\ToastData
2015-01-10 20:57:24 ----D---- C:\Windows\WinStore
2015-01-10 20:57:24 ----D---- C:\Windows\system32\migration
2015-01-10 20:57:10 ----D---- C:\Windows\system32\migwiz
2015-01-10 20:57:10 ----D---- C:\Windows\PolicyDefinitions
2015-01-10 20:57:09 ----D---- C:\Windows
2015-01-10 20:57:00 ----D---- C:\Windows\system32\DriverStore
2015-01-10 20:07:03 ----D---- C:\Windows\system32\Tasks
2015-01-10 19:43:02 ----D---- C:\Program Files\Common Files\microsoft shared
2015-01-10 19:42:51 ----D---- C:\Windows\system32\SecureBootUpdates
2015-01-10 19:42:23 ----D---- C:\Windows\system32\wbem
2015-01-10 19:24:37 ----D---- C:\Windows\system32\wdi
2015-01-10 19:23:27 ----D---- C:\ProgramData\McAfee
2015-01-10 19:23:27 ----D---- C:\Program Files (x86)\McAfee
2015-01-10 19:23:25 ----D---- C:\Program Files\Common Files\mcafee
2015-01-10 17:54:10 ----HD---- C:\OEM
2015-01-10 11:13:37 ----D---- C:\Windows\SoftwareDistribution
2015-01-09 22:04:20 ----SHD---- C:\Windows\Installer
2015-01-09 21:59:06 ----D---- C:\Program Files (x86)\NortonInstaller
2015-01-09 21:59:02 ----D---- C:\Windows\Globalization
2015-01-09 21:57:30 ----D---- C:\Windows\Tasks
2015-01-09 21:19:34 ----A---- C:\Windows\win.ini
2015-01-09 20:27:07 ----D---- C:\ProgramData\Norton
2015-01-09 20:12:56 ----D---- C:\Program Files (x86)\Common Files
2015-01-09 18:18:36 ----D---- C:\Program Files (x86)\Acer
2015-01-09 15:20:27 ----D---- C:\ProgramData\OEM
2015-01-09 15:05:47 ----D---- C:\Windows\Panther
2015-01-09 15:05:47 ----D---- C:\Windows\debug
2015-01-09 03:07:21 ----D---- C:\Windows\rescache
2015-01-08 23:01:47 ----D---- C:\Windows\system32\catroot
2015-01-08 22:59:35 ----HD---- C:\Windows\ELAMBKUP
2015-01-08 21:59:45 ----D---- C:\Program Files (x86)\MSBuild
2015-01-08 21:59:34 ----D---- C:\Program Files (x86)\Microsoft Office
2015-01-08 21:59:02 ----D---- C:\Windows\ShellNew
2015-01-08 21:58:01 ----RSD---- C:\Windows\Fonts
2015-01-08 21:57:44 ----SD---- C:\ProgramData\Microsoft
2015-01-08 21:57:44 ----D---- C:\Program Files (x86)\Microsoft.NET
2015-01-08 19:22:08 ----D---- C:\Windows\system32\drivers\UMDF
2015-01-08 15:53:39 ----D---- C:\Windows\system32\restore
2015-01-08 12:42:48 ----D---- C:\Windows\system32\LogFiles
2015-01-08 12:41:23 ----SHD---- C:\$Recycle.Bin
2015-01-08 12:40:30 ----RD---- C:\Windows\ImmersiveControlPanel
2015-01-08 12:37:46 ----RD---- C:\Users

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amdkmpfd;@oem13.inf,%AMDKMPFD_svcdesc%;AMD PCI Root Bus Lower Filter; C:\Windows\System32\drivers\amdkmpfd.sys [2013-05-21 36096]
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-01-10 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-01-10 267632]
R0 mfehidk;McAfee Inc. mfehidk; C:\Windows\system32\drivers\mfehidk.sys [2014-06-20 786296]
R0 mfewfpk;McAfee Inc. mfewfpk; C:\Windows\system32\drivers\mfewfpk.sys [2014-06-20 348552]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-01-10 93568]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-01-10 1050432]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-01-10 436624]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2013-08-22 71680]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-01-10 29208]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-01-10 87912]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-01-10 116728]
R2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2015-01-10 271752]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-10-02 12762624]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-10-02 619008]
R3 athr;@oem18.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athwbx.sys [2013-08-16 3859968]
R3 bScsiSDa;bScsiSDa; C:\Windows\System32\drivers\bScsiSDa.sys [2013-07-19 82128]
R3 BTATH_BUS;@oem19.inf,%BTATH_BUS.SVCDESC%;Qualcomm Atheros Bluetooth Bus; C:\Windows\System32\drivers\btath_bus.sys [2013-09-07 34384]
R3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [2013-09-07 594120]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2013-10-05 81920]
R3 ETD;@oem17.inf,%PS2.DeviceDesc%;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2013-09-06 370504]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2013-11-13 4208640]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2013-08-27 3613528]
R3 iwdbus;@oem8.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2013-10-29 27032]
R3 k57nd60a;@oem15.inf,%SvcDispName%;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2013-07-26 458960]
R3 LMDriver;@oem4.inf,%LMDriver.SVCDESC%;Launch Manager Wireless Driver; C:\Windows\System32\drivers\LMDriver.sys [2013-07-17 21360]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-11-21 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2015-01-11 129752]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-11-21 64216]
R3 MEIx64;@oem9.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2013-09-04 99288]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\Windows\system32\drivers\mfeavfk.sys [2014-06-20 313544]
R3 mfefirek;McAfee Inc. mfefirek; C:\Windows\system32\drivers\mfefirek.sys [2014-06-20 523792]
R3 RadioShim;@oem4.inf,%RadioShim.SVCDESC%;Shim for HID-KMDF Interface layer; C:\Windows\System32\drivers\RadioShim.sys [2013-07-17 14680]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-08-22 212224]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2013-08-22 36864]
S0 mfeelamk;McAfee Inc. mfeelamk; C:\Windows\system32\drivers\mfeelamk.sys [2014-06-20 70600]
S3 AthBTPort;@oem22.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys [2013-09-07 89800]
S3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl63a.sys [2013-07-01 8536752]
S3 BTATH_A2DP;@oem21.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys [2013-09-07 338120]
S3 btath_avdt;@oem21.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\Windows\system32\drivers\btath_avdt.sys [2013-09-07 116424]
S3 BTATH_HCRP;@oem24.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\Windows\System32\drivers\btath_hcrp.sys [2013-09-07 179432]
S3 BTATH_LWFLT;@oem26.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys [2013-09-07 77464]
S3 BTATH_RCP;@oem28.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\Windows\System32\drivers\btath_rcp.sys [2013-09-07 137928]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\Windows\System32\drivers\BthEnum.sys [2013-08-22 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\Windows\system32\DRIVERS\BthLEEnum.sys [2013-08-22 224768]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2013-08-22 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2013-10-05 1200640]
S3 ccSet_NARA;NARA Settings Manager; C:\Windows\system32\drivers\NARAx64\0405000.009\ccSetx64.sys [2013-07-30 150104]
S3 cfwids;McAfee Inc. cfwids; C:\Windows\system32\drivers\cfwids.sys [2014-06-20 72128]
S3 intaud_WaveExtensible;@oem7.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2013-10-29 39320]
S3 IntcDAud;@oem5.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2013-11-13 449496]
S3 mfeapfk;McAfee Inc. mfeapfk; C:\Windows\system32\drivers\mfeapfk.sys [2014-06-20 181704]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\System32\drivers\rfcomm.sys [2013-09-11 167424]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-03 81088]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-10-02 239616]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [2013-09-07 312448]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-01-10 50344]
R2 CCDMonitorService;CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2014-12-19 2713856]
R2 ETDService;Elan Service; C:\Program Files\Elantech\ETDService.exe [2013-09-06 101192]
R2 GamesAppIntegrationService;GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [2013-07-16 235008]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-05-12 733696]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-09-04 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-09-04 390616]
R2 LMSvc;Launch Manager Service; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [2013-08-03 457768]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-11-21 969016]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-11-21 1871160]
R2 mfefire;McAfee Firewall Core Service; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [2014-06-20 219752]
R2 mfevtp;McAfee Validation Trust Protection Service; C:\Windows\system32\mfevtps.exe [2014-06-20 189912]
R3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2015-01-10 4012248]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2013-11-19 279024]
S3 ePowerSvc;ePower Service; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2013-07-06 663592]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-22 43696]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-08 107912]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-08 107912]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-05-12 822232]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2012-07-14 769432]
S3 NOBU;Norton Online Backup; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2013-08-02 4278112]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Avatar uživatele
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 Lis 2006 13:37
Místo/Bydliště: ČR

Re: Rootkit hidden file

#4 Příspěvek od Roli »

V jaké složce našel Avast tu hrozbu ?

Máš tam Mbam, našel něco ?


Smaž nepotřebné soubory

pomocí CCleaneru

návod :

Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)

čištění registru je třeba několikrát zopakovat !

Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém


Stáhni a ulož na plochu AdwCleaner,

ukonči všechny programy včetně prohlížeče a dvojklikem spusť,

objeví se okno kde vlevo nahoře klikni na Scan.

Po té proběhne sken a po jeho skončení klikni na Report a to co na Tebe vypadne mi sem zkopíruj.


Spusť skener Cure It podle TOHOTO návodu

po skončení skenu chci sem výsledky.

(Upozornění je úchylně pomalý a je zapotřebí ho sledovat občas se na něco ptá)
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

nelahrabovska
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 21 Lis 2012 20:36

Re: Rootkit hidden file

#5 Příspěvek od nelahrabovska »

Většína je v C:/Windowns/WinSxS/.../ pak se to liší.

Malwarebytes nic nenašel.

nelahrabovska
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 21 Lis 2012 20:36

Re: Rootkit hidden file

#6 Příspěvek od nelahrabovska »

# AdwCleaner v4.107 - Report created 11/01/2015 at 15:59:27
# Updated 07/01/2015 by Xplode
# Database : 2015-01-03.1 [Live]
# Operating System : Windows 8.1 (64 bits)
# Username : Nela - NELCA
# Running from : C:\Users\Nela\Desktop\adwcleaner_4.107.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16518


-\\ Google Chrome v39.0.2171.95

[C:\Users\Nela\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://websearch.ask.com/redirect?client=cr&src=kw&tb=ORJ&o=&locale=&apn_uid=DBDF6851-11F8-4B60-A568-7EB57AE2B150&apn_ptnrs=U3&apn_sauid=9E412F60-B138-4693-BB1B-EB7F3F0CBFCE&apn_dtid=OSJ000YYIT&q={searchTerms}
[C:\Users\Nela\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://websearch.ask.com/redirect?client=cr&src=kw&tb=ORJ&o=&locale=&apn_uid=DBDF6851-11F8-4B60-A568-7EB57AE2B150&apn_ptnrs=U3&apn_sauid=9E412F60-B138-4693-BB1B-EB7F3F0CBFCE&apn_dtid=OSJ000YYIT&q={searchTerms}
[C:\Users\Nela\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}

-\\ Opera v0.0.0.0


*************************

AdwCleaner[R0].txt - [3695 octets] - [09/01/2015 22:17:05]
AdwCleaner[R1].txt - [859 octets] - [11/01/2015 12:43:28]
AdwCleaner[R2].txt - [1484 octets] - [11/01/2015 15:59:27]
AdwCleaner[S0].txt - [3749 octets] - [09/01/2015 22:18:36]

########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [1604 octets] ##########

Avatar uživatele
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 Lis 2006 13:37
Místo/Bydliště: ČR

Re: Rootkit hidden file

#7 Příspěvek od Roli »

Znovu spusť AdwCleaner ale tentokrát klikni na Clean,

proběhne restart PC kdy dojde ke smazání nepořádku.


Pak si počkám ne ten Cure It.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

nelahrabovska
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 21 Lis 2012 20:36

Re: Rootkit hidden file

#8 Příspěvek od nelahrabovska »

Mě nějak nejde ten CureIt. Po tom Express prohledávání mi nejde se dostat k tomu kompletnímu skenu :-(

A nebo mi to napíše : Platnost Vaší registrace vypršela.

Avatar uživatele
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 Lis 2006 13:37
Místo/Bydliště: ČR

Re: Rootkit hidden file

#9 Příspěvek od Roli »

Tak jej odinstaluj, stáhni ODTUD poslední verzi a zkus to znovu.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

nelahrabovska
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 21 Lis 2012 20:36

Re: Rootkit hidden file

#10 Příspěvek od nelahrabovska »

V tom lugu je toho nějak moc a najednou se mi to tu nechce vložit.

Avatar uživatele
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 Lis 2006 13:37
Místo/Bydliště: ČR

Re: Rootkit hidden file

#11 Příspěvek od Roli »

Nahraj ho třeba TADY a sem mi dej odkaz na stažení a nebo jen konec s výsledky.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

nelahrabovska
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 21 Lis 2012 20:36

Re: Rootkit hidden file

#12 Příspěvek od nelahrabovska »


Avatar uživatele
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 Lis 2006 13:37
Místo/Bydliště: ČR

Re: Rootkit hidden file

#13 Příspěvek od Roli »

Bezva, dokážeš udělat printscreen toho co Avast našel ?
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

nelahrabovska
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 21 Lis 2012 20:36

Re: Rootkit hidden file

#14 Příspěvek od nelahrabovska »

Už ho mám, ale jaksik jsem nepobrala jak ho tu dát.

nelahrabovska
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 21 Lis 2012 20:36

Re: Rootkit hidden file

#15 Příspěvek od nelahrabovska »

Tak už :D
Přílohy
Snímek obrazovky (5).png
Snímek obrazovky (5).png (92.83 KiB) Zobrazeno 4120 x

Zamčeno