Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

LNK/Agent.AK

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Hanzell
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 24 črc 2014 11:31

LNK/Agent.AK

#1 Příspěvek od Hanzell »

Přeji dobrý den,
Na pracovním PC mám podezření na LNK/Agent.AK. Při vložení flešky do usb "odstaní" všechny soubory a místo nich zůstanou jen ink zástupci a jako grafik, kdy mi do práce zákazníci nosí vesměs jen flešky to není moc ok :) . Vím že už se tady tahle havěť párkrát řešila, pročetl jsem si pár topiců, ale jako úplný nováček se v tom moc neorietuji :) Prosím tedy o pomoc.

Logfile of random's system information tool 1.10 (written by random/random)
Run by uzivatel at 2014-07-24 12:35:36
Microsoft Windows 8.1 Pro
System drive C: has 55 GB (49%) free of 114 GB
Total RAM: 16328 MB (80% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:35:41, on 24. 7. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17126)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Program Files (x86)\Pidgin\pidgin.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\uzivatel.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [autoactivation] wscript.exe //B "C:\Users\uzivatel\AppData\Local\Temp\autoactivation.vbs"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_FA6F99A34873A093FA88EBF49A43251D] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [autoactivation] wscript.exe //B "C:\Users\uzivatel\AppData\Local\Temp\autoactivation.vbs"
O4 - Startup: autoactivation.vbs
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Protexis Licensing V2 x64 (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10003 bytes

======Listing Processes======





wininit.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe"
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
dashost.exe {4cbeb6e4-673e-431d-b8bea3b673ed9d5c}
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 6578a17c-a3d2-41a5-a396-f7ff36f572e2 1
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-a99dcc79-4d93-486d-b9df-f692d24d92bb -SystemEventPortName:HostProcess-6e17ef6e-65cb-4246-8b7c-77483fb23d07 -IoCancelEventPortName:HostProcess-d5df4746-858b-4f8e-a6db-6f5185008b16 -NonStateChangingEventPortName:HostProcess-d2fae432-b0c0-4e38-805f-5247abf4f80f -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:9ca3d990-bc4c-4a87-aeb5-4a307c6d4565 -DeviceGroupId:WudfDefaultDevicePool
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"

C:\Windows\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
taskhostex.exe
C:\Windows\Explorer.EXE
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Windows\System32\wscript.exe" //B "C:\Users\uzivatel\AppData\Local\Temp\autoactivation.vbs"
"C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\totalcmd\TOTALCMD64.EXE"
"C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe"
"C:\Program Files\Corel\CorelDRAW Graphics Suite X6\Programs64\CorelDRW.exe"
"C:\Program Files (x86)\Pidgin\pidgin.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5200.0.1981394156\289636563" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,16,43 --gpu-vendor-id=0x10de --gpu-device-id=0x0fc6 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.3788 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --channel="5200.2.991013008\9228705" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --channel="5200.3.405971505\570783392" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --channel="5200.4.1024882867\46351670" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --channel="5200.5.1004965780\812706448" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --channel="5200.7.1407522723\172886270" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --channel="5200.8.1429313126\828227392" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --channel="5200.10.875717613\793605658" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --channel="5200.11.1458821578\1047174809" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --channel="5200.12.1259830667\972625355" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --channel="5200.17.212956584\1490939273" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --channel="5200.22.459613384\388552132" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --channel="5200.25.1762957790\1092515829" /prefetch:673131151

"D:\DOWNLOADS\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\qi9h59ry.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.65.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.65.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Acrobat]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-11 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2014-05-08 343424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-11 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2014-05-08 343424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2014-05-08 343424]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-03-31 7569112]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2014-04-11 36352]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-05-30 2352072]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-05-30 1279480]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2014-02-24 5581888]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GoogleChromeAutoLaunch_FA6F99A34873A093FA88EBF49A43251D"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2014-07-15 860488]
"AdobeBridge"= []
"autoactivation"=wscript.exe //B C:\Users\uzivatel\AppData\Local\Temp\autoactivation.vbs []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
""= []
"Adobe Acrobat Speed Launcher"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [2014-05-08 41336]
"Acrobat Assistant 8.0"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2014-05-08 840568]
"autoactivation"=wscript.exe //B C:\Users\uzivatel\AppData\Local\Temp\autoactivation.vbs []
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-07-11 256896]

C:\Users\uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
autoactivation.vbs

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=l3codeca.acm
"vidc.yuy2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"vidc.yvyu"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"vidc.uyvy"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"

======List of files/folders created in the last 1 month======

2014-07-24 12:35:36 ----D---- C:\rsit
2014-07-24 12:35:36 ----D---- C:\Program Files\trend micro
2014-07-23 14:23:45 ----A---- C:\AUTOEXEC.BAT
2014-07-23 07:11:37 ----A---- C:\Windows\system32\SyncEngine.dll
2014-07-23 07:11:37 ----A---- C:\Windows\system32\SkyDriveTelemetry.dll
2014-07-23 07:11:37 ----A---- C:\Windows\system32\SkyDrive.exe
2014-07-22 14:39:54 ----D---- C:\Users\uzivatel\AppData\Roaming\TP
2014-07-22 13:41:02 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2014-07-22 13:40:33 ----D---- C:\ProgramData\Malwarebytes
2014-07-22 13:40:33 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-22 13:40:33 ----A---- C:\Windows\system32\drivers\mwac.sys
2014-07-22 13:40:33 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2014-07-22 13:40:33 ----A---- C:\Windows\system32\drivers\mbam.sys
2014-07-15 15:31:25 ----D---- C:\ProgramData\vsosdk
2014-07-15 13:41:46 ----D---- C:\Users\uzivatel\AppData\Roaming\MPC-HC
2014-07-15 13:34:29 ----D---- C:\Users\uzivatel\AppData\Roaming\Vso
2014-07-15 13:34:29 ----A---- C:\Users\uzivatel\AppData\Roaming\pcouffin.sys
2014-07-15 13:34:29 ----A---- C:\Users\uzivatel\AppData\Roaming\inst.exe
2014-07-15 13:34:23 ----D---- C:\ProgramData\VSO
2014-07-15 13:34:23 ----D---- C:\Program Files (x86)\VSO
2014-07-11 12:56:23 ----A---- C:\Windows\fnerr.dat
2014-07-09 10:40:54 ----D---- C:\Program Files (x86)\Corel
2014-07-09 10:39:42 ----D---- C:\Program Files\Common Files\Corel
2014-07-09 09:56:01 ----D---- C:\Program Files\Common Files\Protexis
2014-07-09 09:23:14 ----SD---- C:\Windows\system32\CompatTel
2014-07-09 09:22:18 ----A---- C:\Windows\system32\termsrv.dll
2014-07-09 07:35:28 ----A---- C:\Windows\system32\win32k.sys
2014-07-09 07:35:27 ----A---- C:\Windows\SYSWOW64\osk.exe
2014-07-09 07:35:27 ----A---- C:\Windows\system32\osk.exe
2014-07-09 07:35:25 ----A---- C:\Windows\system32\drivers\afd.sys
2014-07-09 07:35:24 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2014-07-09 07:35:24 ----A---- C:\Windows\system32\lsasrv.dll
2014-07-09 07:35:24 ----A---- C:\Windows\system32\drivers\cng.sys
2014-07-09 07:35:24 ----A---- C:\Windows\system32\adtschema.dll
2014-07-09 07:35:23 ----A---- C:\Windows\SYSWOW64\certcli.dll
2014-07-09 07:35:23 ----A---- C:\Windows\system32\certcli.dll
2014-07-09 07:34:45 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-07-09 07:34:45 ----A---- C:\Windows\system32\iedkcs32.dll
2014-07-09 07:34:44 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-07-09 07:34:44 ----A---- C:\Windows\system32\mshtml.dll
2014-07-09 07:34:41 ----A---- C:\Windows\system32\jscript9.dll
2014-07-09 07:34:40 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-07-09 07:34:40 ----A---- C:\Windows\system32\ieframe.dll
2014-07-09 07:34:39 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-07-09 07:34:39 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-07-09 07:34:39 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-07-09 07:34:39 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-07-09 07:34:39 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-07-09 07:34:39 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-07-09 07:34:39 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-07-09 07:34:39 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-07-09 07:34:39 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-07-09 07:34:39 ----A---- C:\Windows\system32\wininet.dll
2014-07-09 07:34:39 ----A---- C:\Windows\system32\urlmon.dll
2014-07-09 07:34:39 ----A---- C:\Windows\system32\mshtmled.dll
2014-07-09 07:34:39 ----A---- C:\Windows\system32\msfeeds.dll
2014-07-09 07:34:39 ----A---- C:\Windows\system32\iertutil.dll
2014-07-09 07:34:39 ----A---- C:\Windows\system32\ieapfltr.dll
2014-07-09 07:34:39 ----A---- C:\Windows\system32\ie4uinit.exe
2014-07-09 07:34:39 ----A---- C:\Windows\system32\dxtrans.dll
2014-07-09 07:34:39 ----A---- C:\Windows\system32\dxtmsft.dll
2014-07-09 07:34:28 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-07-09 07:34:28 ----A---- C:\Windows\system32\qedit.dll
2014-07-09 07:34:28 ----A---- C:\Windows\system32\devinv.dll
2014-07-09 07:34:28 ----A---- C:\Windows\system32\aepdu.dll
2014-07-09 07:34:28 ----A---- C:\Windows\system32\aeinv.dll
2014-07-09 07:34:27 ----A---- C:\Windows\system32\wuaueng.dll
2014-07-09 07:34:26 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-07-09 07:34:26 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-07-09 07:34:26 ----A---- C:\Windows\SYSWOW64\WSShared.dll
2014-07-09 07:34:26 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-09 07:34:26 ----A---- C:\Windows\SYSWOW64\twinui.dll
2014-07-09 07:34:26 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2014-07-09 07:34:26 ----A---- C:\Windows\system32\wudriver.dll
2014-07-09 07:34:26 ----A---- C:\Windows\system32\wuauclt.exe
2014-07-09 07:34:26 ----A---- C:\Windows\system32\wuapi.dll
2014-07-09 07:34:26 ----A---- C:\Windows\system32\WSShared.dll
2014-07-09 07:34:26 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-09 07:34:26 ----A---- C:\Windows\system32\twinui.dll
2014-07-09 07:34:26 ----A---- C:\Windows\system32\twinui.appcore.dll
2014-07-09 07:34:26 ----A---- C:\Windows\system32\twinapi.appcore.dll
2014-07-09 07:34:00 ----A---- C:\Windows\system32\WSReset.exe
2014-07-02 13:21:28 ----D---- C:\ProgramData\CorelDRAW Graphics Suite X6.1
2014-07-02 11:55:46 ----D---- C:\Users\uzivatel\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2014-07-02 11:53:03 ----D---- C:\Users\uzivatel\AppData\Roaming\WinRAR
2014-07-02 09:43:27 ----D---- C:\Program Files\WinRAR
2014-07-02 09:12:59 ----D---- C:\Users\uzivatel\AppData\Roaming\NVIDIA
2014-07-02 09:01:44 ----D---- C:\ProgramData\ALM
2014-07-02 08:57:25 ----D---- C:\Program Files\Adobe
2014-07-02 08:57:11 ----D---- C:\Program Files\Common Files\Adobe
2014-07-02 08:33:00 ----D---- C:\Users\uzivatel\AppData\Roaming\.purple
2014-07-02 08:31:57 ----D---- C:\Program Files (x86)\Pidgin
2014-07-01 08:24:46 ----D---- C:\ProgramData\Bitstream
2014-06-30 15:22:06 ----D---- C:\Users\uzivatel\AppData\Roaming\Corel
2014-06-30 15:22:06 ----D---- C:\ProgramData\Protexis64
2014-06-30 15:13:10 ----D---- C:\Users\uzivatel\AppData\Roaming\ESET
2014-06-30 15:12:40 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2014-06-30 15:12:40 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2014-06-30 15:12:40 ----A---- C:\Windows\SYSWOW64\x264vfw.dll
2014-06-30 15:12:40 ----A---- C:\Windows\SYSWOW64\lagarith.dll
2014-06-30 15:12:40 ----A---- C:\Windows\system32\xvidvfw.dll
2014-06-30 15:12:40 ----A---- C:\Windows\system32\xvidcore.dll
2014-06-30 15:12:40 ----A---- C:\Windows\system32\x264vfw64.dll
2014-06-30 15:12:40 ----A---- C:\Windows\system32\lagarith.dll
2014-06-30 15:12:38 ----A---- C:\Windows\SYSWOW64\unrar.dll
2014-06-30 15:12:38 ----A---- C:\Windows\system32\unrar64.dll
2014-06-30 15:12:36 ----A---- C:\Windows\SYSWOW64\ff_vfw.dll
2014-06-30 15:12:34 ----D---- C:\Program Files (x86)\K-Lite Codec Pack
2014-06-30 15:11:47 ----D---- C:\ProgramData\ESET
2014-06-30 15:11:47 ----D---- C:\Program Files\ESET
2014-06-30 15:02:30 ----D---- C:\Program Files (x86)\Microsoft SDKs
2014-06-30 15:02:29 ----D---- C:\ProgramData\Microsoft Help
2014-06-30 15:02:29 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 9.0
2014-06-30 15:02:12 ----D---- C:\ProgramData\Corel
2014-06-30 15:01:27 ----D---- C:\Program Files\Corel
2014-06-30 14:55:04 ----D---- C:\ProgramData\CorelDRAW Graphics Suite X6
2014-06-30 14:27:30 ----D---- C:\KonicaMinolta
2014-06-28 23:31:34 ----D---- C:\Program Files (x86)\Reference Assemblies
2014-06-28 23:31:34 ----D---- C:\Program Files (x86)\MSBuild
2014-06-28 23:31:33 ----D---- C:\Windows\SYSWOW64\XPSViewer
2014-06-28 23:31:33 ----D---- C:\Program Files\Reference Assemblies
2014-06-28 23:31:33 ----D---- C:\Program Files\MSBuild
2014-06-28 23:30:26 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-06-28 23:30:26 ----A---- C:\Windows\SYSWOW64\PresentationNative_v0300.dll
2014-06-28 23:30:26 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-06-28 23:30:26 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-06-28 23:30:26 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2014-06-28 23:30:26 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-06-28 23:14:40 ----D---- C:\Users\uzivatel\AppData\Roaming\Thunderbird
2014-06-28 23:14:33 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2014-06-28 23:11:13 ----D---- C:\Users\uzivatel\AppData\Roaming\LibreOffice
2014-06-28 23:10:01 ----D---- C:\Program Files (x86)\LibreOffice 4
2014-06-28 23:08:54 ----D---- C:\Users\uzivatel\AppData\Roaming\WinTools
2014-06-28 23:08:49 ----D---- C:\Program Files (x86)\WinTools Software
2014-06-28 23:06:50 ----D---- C:\totalcmd
2014-06-28 23:04:04 ----D---- C:\Users\uzivatel\AppData\Roaming\Mozilla
2014-06-28 23:04:02 ----D---- C:\ProgramData\Mozilla
2014-06-28 23:04:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-28 23:03:58 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-06-28 23:01:43 ----D---- C:\Program Files\CCleaner
2014-06-28 22:57:38 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2014-06-28 22:57:38 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2014-06-28 22:57:38 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2014-06-28 22:57:38 ----A---- C:\Windows\system32\ntdll.dll
2014-06-28 22:57:38 ----A---- C:\Windows\system32\mfcore.dll
2014-06-28 22:57:38 ----A---- C:\Windows\system32\localspl.dll
2014-06-28 22:57:38 ----A---- C:\Windows\system32\d3d9.dll
2014-06-28 22:57:37 ----AC---- C:\Windows\system32\drivers\usbuhci.sys
2014-06-28 22:57:37 ----AC---- C:\Windows\system32\drivers\usbport.sys
2014-06-28 22:57:37 ----AC---- C:\Windows\system32\drivers\usbhub.sys
2014-06-28 22:57:37 ----AC---- C:\Windows\system32\drivers\usbehci.sys
2014-06-28 22:57:37 ----AC---- C:\Windows\system32\drivers\usbd.sys
2014-06-28 22:57:37 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2014-06-28 22:57:37 ----A---- C:\Windows\SYSWOW64\SkyDriveShell.dll
2014-06-28 22:57:37 ----A---- C:\Windows\SYSWOW64\Robocopy.exe
2014-06-28 22:57:37 ----A---- C:\Windows\SYSWOW64\ncobjapi.dll
2014-06-28 22:57:37 ----A---- C:\Windows\SYSWOW64\framedynos.dll
2014-06-28 22:57:37 ----A---- C:\Windows\SYSWOW64\dhcpcore6.dll
2014-06-28 22:57:37 ----A---- C:\Windows\SYSWOW64\dhcpcore.dll
2014-06-28 22:57:37 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-06-28 22:57:37 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2014-06-28 22:57:37 ----A---- C:\Windows\system32\winbici.dll
2014-06-28 22:57:37 ----A---- C:\Windows\system32\WebClnt.dll
2014-06-28 22:57:37 ----A---- C:\Windows\system32\vpnike.dll
2014-06-28 22:57:37 ----A---- C:\Windows\system32\SkyDriveShell.dll
2014-06-28 22:57:37 ----A---- C:\Windows\system32\Robocopy.exe
2014-06-28 22:57:37 ----A---- C:\Windows\system32\ncobjapi.dll
2014-06-28 22:57:37 ----A---- C:\Windows\system32\IKEEXT.DLL
2014-06-28 22:57:37 ----A---- C:\Windows\system32\fveapi.dll
2014-06-28 22:57:37 ----A---- C:\Windows\system32\framedynos.dll
2014-06-28 22:57:37 ----A---- C:\Windows\system32\framedyn.dll
2014-06-28 22:57:37 ----A---- C:\Windows\system32\drivers\vwifimp.sys
2014-06-28 22:57:37 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2014-06-28 22:57:37 ----A---- C:\Windows\system32\drivers\agilevpn.sys
2014-06-28 22:57:37 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2014-06-28 22:57:37 ----A---- C:\Windows\system32\dhcpcsvc.dll
2014-06-28 22:57:37 ----A---- C:\Windows\system32\dhcpcore6.dll
2014-06-28 22:57:37 ----A---- C:\Windows\system32\dhcpcore.dll
2014-06-28 22:57:37 ----A---- C:\Windows\system32\BFE.DLL
2014-06-28 22:57:37 ----A---- C:\Windows\system32\bdesvc.dll
2014-06-28 22:57:37 ----A---- C:\Windows\system32\authui.dll
2014-06-28 22:57:37 ----A---- C:\Windows\system32\actxprxy.dll
2014-06-28 22:57:36 ----A---- C:\Windows\SYSWOW64\framedyn.dll
2014-06-28 22:57:36 ----A---- C:\Windows\SYSWOW64\dhcpcsvc6.dll
2014-06-28 22:57:36 ----A---- C:\Windows\SYSWOW64\dhcpcsvc.dll
2014-06-28 22:57:36 ----A---- C:\Windows\SYSWOW64\d3d8thk.dll
2014-06-28 22:57:36 ----A---- C:\Windows\system32\srms.dat
2014-06-28 22:57:36 ----A---- C:\Windows\system32\reseteng.dll
2014-06-28 22:57:36 ----A---- C:\Windows\system32\fvewiz.dll
2014-06-28 22:57:36 ----A---- C:\Windows\system32\fvecpl.dll
2014-06-28 22:57:36 ----A---- C:\Windows\system32\drivers\vwififlt.sys
2014-06-28 22:57:36 ----A---- C:\Windows\system32\BulkOperationHost.exe
2014-06-28 22:57:36 ----A---- C:\Windows\system32\BdeHdCfgLib.dll
2014-06-28 22:57:36 ----A---- C:\Windows\system32\BdeHdCfg.exe
2014-06-28 22:57:26 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2014-06-28 22:53:57 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2014-06-28 22:53:57 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2014-06-28 22:53:57 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2014-06-28 22:53:57 ----A---- C:\Windows\system32\D3DX9_43.dll
2014-06-28 22:53:57 ----A---- C:\Windows\system32\d3dx11_43.dll
2014-06-28 22:53:57 ----A---- C:\Windows\system32\d3dx10_43.dll
2014-06-28 22:53:46 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2014-06-28 22:53:46 ----A---- C:\Windows\system32\nvspcap64.dll
2014-06-28 22:53:21 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2014-06-28 22:52:24 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-06-28 22:52:24 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-06-28 22:52:24 ----A---- C:\Windows\system32\jsproxy.dll
2014-06-28 22:52:24 ----A---- C:\Windows\system32\jscript9diag.dll
2014-06-28 22:52:14 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2014-06-28 22:52:14 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2014-06-28 22:52:14 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2014-06-28 22:52:14 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2014-06-28 22:52:14 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2014-06-28 22:52:14 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2014-06-28 22:52:14 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2014-06-28 22:52:14 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2014-06-28 22:52:14 ----A---- C:\Windows\system32\nvopencl.dll
2014-06-28 22:52:14 ----A---- C:\Windows\system32\nvoglv64.dll
2014-06-28 22:52:14 ----A---- C:\Windows\system32\nvoglshim64.dll
2014-06-28 22:52:14 ----A---- C:\Windows\system32\nvinitx.dll
2014-06-28 22:52:14 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2014-06-28 22:52:14 ----A---- C:\Windows\system32\NvIFR64.dll
2014-06-28 22:52:14 ----A---- C:\Windows\system32\nvaudcap64v.dll
2014-06-28 22:52:14 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2014-06-28 22:52:14 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2014-06-28 22:52:13 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2014-06-28 22:52:13 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2014-06-28 22:52:13 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2014-06-28 22:52:13 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2014-06-28 22:52:13 ----A---- C:\Windows\SYSWOW64\nvcuvenc.dll
2014-06-28 22:52:13 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2014-06-28 22:52:13 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2014-06-28 22:52:13 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2014-06-28 22:52:13 ----A---- C:\Windows\system32\NvFBC64.dll
2014-06-28 22:52:13 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2014-06-28 22:52:13 ----A---- C:\Windows\system32\nvdispgenco6433788.dll
2014-06-28 22:52:13 ----A---- C:\Windows\system32\nvdispco6433788.dll
2014-06-28 22:52:13 ----A---- C:\Windows\system32\nvd3dumx.dll
2014-06-28 22:52:13 ----A---- C:\Windows\system32\nvcuvid.dll
2014-06-28 22:52:13 ----A---- C:\Windows\system32\nvcuvenc.dll
2014-06-28 22:52:13 ----A---- C:\Windows\system32\nvcuda.dll
2014-06-28 22:52:13 ----A---- C:\Windows\system32\nvcompiler.dll
2014-06-28 22:51:42 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-06-28 22:51:42 ----A---- C:\Windows\system32\msxml3.dll
2014-06-28 22:51:41 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-06-28 22:51:41 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-06-28 22:51:40 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-06-28 22:51:40 ----A---- C:\Windows\system32\rdpcorets.dll
2014-06-28 22:51:40 ----A---- C:\Windows\system32\gdi32.dll
2014-06-28 22:51:40 ----A---- C:\Windows\system32\drivers\ks.sys
2014-06-28 22:51:39 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2014-06-28 22:51:39 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2014-06-28 22:51:39 ----A---- C:\Windows\system32\FntCache.dll
2014-06-28 22:51:39 ----A---- C:\Windows\system32\DWrite.dll
2014-06-28 22:51:39 ----A---- C:\Windows\system32\drvinst.exe
2014-06-28 22:51:39 ----A---- C:\Windows\system32\drvcfg.exe
2014-06-28 22:51:13 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2014-06-28 22:51:13 ----A---- C:\Windows\system32\WpcWebSync.dll
2014-06-28 22:51:13 ----A---- C:\Windows\system32\WpcMon.exe
2014-06-28 22:51:13 ----A---- C:\Windows\system32\wpccpl.dll
2014-06-28 22:51:13 ----A---- C:\Windows\system32\Wpc.dll
2014-06-28 22:51:13 ----A---- C:\Windows\system32\drivers\wpcfltr.sys
2014-06-28 22:45:02 ----D---- C:\Program Files (x86)\Google
2014-06-28 22:44:15 ----D---- C:\Users\uzivatel\AppData\Roaming\Macromedia
2014-06-28 17:45:07 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2014-06-28 17:45:07 ----A---- C:\Windows\system32\nvspbridge64.dll

======List of files/folders modified in the last 1 month======

2014-07-24 12:35:36 ----RD---- C:\Program Files
2014-07-24 12:35:12 ----D---- C:\Windows\Temp
2014-07-24 12:00:00 ----D---- C:\Windows\system32\sru
2014-07-24 11:58:25 ----D---- C:\Windows\Prefetch
2014-07-24 10:40:14 ----D---- C:\Users\uzivatel\AppData\Roaming\GHISLER
2014-07-23 14:18:55 ----RD---- C:\Windows\System32
2014-07-23 14:18:55 ----D---- C:\Windows\Inf
2014-07-23 14:18:55 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-07-23 11:07:41 ----D---- C:\Windows\rescache
2014-07-23 11:07:17 ----SHD---- C:\System Volume Information
2014-07-23 10:50:20 ----D---- C:\Windows\system32\config
2014-07-23 10:47:52 ----HD---- C:\Program Files\WindowsApps
2014-07-23 10:47:52 ----D---- C:\Windows\AppReadiness
2014-07-23 10:47:47 ----D---- C:\Windows\WinSxS
2014-07-23 10:47:47 ----D---- C:\Windows\CbsTemp
2014-07-23 10:47:41 ----D---- C:\Windows\debug
2014-07-23 10:47:40 ----D---- C:\Windows\Microsoft.NET
2014-07-23 09:40:23 ----D---- C:\Windows\SoftwareDistribution
2014-07-23 09:40:23 ----D---- C:\Windows
2014-07-22 13:41:02 ----D---- C:\Windows\system32\drivers
2014-07-22 13:40:33 ----RD---- C:\Program Files (x86)
2014-07-22 13:40:33 ----HD---- C:\ProgramData
2014-07-21 13:59:44 ----D---- C:\Windows\system32\FxsTmp
2014-07-18 13:09:31 ----SHD---- C:\$Recycle.Bin
2014-07-17 13:25:24 ----RSD---- C:\Windows\Fonts
2014-07-17 10:38:46 ----D---- C:\ProgramData\Oracle
2014-07-17 10:38:43 ----SHD---- C:\Windows\Installer
2014-07-17 10:38:42 ----D---- C:\Windows\SysWOW64
2014-07-17 10:38:42 ----D---- C:\Program Files (x86)\Common Files
2014-07-17 10:38:41 ----D---- C:\Program Files (x86)\Java
2014-07-16 07:08:01 ----D---- C:\ProgramData\NVIDIA
2014-07-15 14:26:27 ----D---- C:\Windows\system32\NDF
2014-07-14 11:51:42 ----D---- C:\Users\uzivatel\AppData\Roaming\Adobe
2014-07-11 10:36:02 ----D---- C:\Windows\system32\catroot
2014-07-11 03:02:05 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-07-11 02:56:08 ----A---- C:\Windows\SYSWOW64\javaws.exe
2014-07-11 02:56:01 ----A---- C:\Windows\SYSWOW64\javaw.exe
2014-07-11 02:55:32 ----A---- C:\Windows\SYSWOW64\java.exe
2014-07-09 10:40:47 ----RD---- C:\Windows\assembly
2014-07-09 10:39:42 ----D---- C:\Program Files\Common Files
2014-07-09 09:56:06 ----D---- C:\Program Files\Common Files\microsoft shared
2014-07-09 09:23:15 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-07-09 09:23:15 ----D---- C:\Windows\system32\cs-CZ
2014-07-09 09:23:15 ----D---- C:\Program Files\Windows Journal
2014-07-09 09:23:15 ----D---- C:\Program Files\Internet Explorer
2014-07-09 09:23:15 ----D---- C:\Program Files (x86)\Internet Explorer
2014-07-09 09:23:14 ----RD---- C:\Windows\ToastData
2014-07-09 09:23:14 ----D---- C:\Windows\WinStore
2014-07-09 09:22:57 ----D---- C:\Windows\system32\MRT
2014-07-09 09:22:37 ----A---- C:\Windows\system32\MRT.exe
2014-07-09 07:34:09 ----D---- C:\Windows\system32\catroot2
2014-07-08 08:56:02 ----D---- C:\ProgramData\Adobe
2014-07-03 15:42:44 ----D---- C:\Windows\system32\DriverStore
2014-07-03 07:14:59 ----D---- C:\Windows\system32\wdi
2014-07-02 10:22:02 ----SD---- C:\Users\uzivatel\AppData\Roaming\Microsoft
2014-07-02 09:01:30 ----D---- C:\Program Files (x86)\Adobe
2014-07-01 09:28:06 ----D---- C:\Windows\Logs
2014-06-30 15:02:52 ----SD---- C:\ProgramData\Microsoft
2014-06-30 15:02:30 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-06-28 23:31:33 ----D---- C:\Windows\SYSWOW64\MUI
2014-06-28 23:31:33 ----D---- C:\Windows\system32\MUI
2014-06-28 23:13:40 ----D---- C:\Windows\Panther
2014-06-28 23:13:40 ----D---- C:\Windows\AsusInstAll
2014-06-28 23:01:44 ----D---- C:\Windows\system32\Tasks
2014-06-28 22:58:04 ----D---- C:\Windows\SYSWOW64\wbem
2014-06-28 22:58:04 ----D---- C:\Windows\SYSWOW64\migration
2014-06-28 22:58:04 ----D---- C:\Windows\system32\wbem
2014-06-28 22:58:04 ----D---- C:\Windows\system32\en-US
2014-06-28 22:58:04 ----D---- C:\Windows\MediaViewer
2014-06-28 22:58:04 ----D---- C:\Windows\FileManager
2014-06-28 22:58:04 ----D---- C:\Windows\Camera
2014-06-28 22:55:40 ----D---- C:\Windows\system32\migration
2014-06-28 22:54:25 ----D---- C:\ProgramData\NVIDIA Corporation
2014-06-28 22:53:46 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2014-06-28 22:45:03 ----D---- C:\Windows\Tasks
2014-06-28 17:45:31 ----D---- C:\Windows\system32\drivers\UMDF
2014-06-28 17:45:03 ----D---- C:\Program Files\NVIDIA Corporation
2014-06-26 22:55:30 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys [2013-09-17 239296]
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2013-09-17 62136]
R0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2014-04-11 645480]
R0 Wof;Windows Overlay File System Filter Driver; C:\Windows\system32\drivers\Wof.sys [2014-03-13 157016]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2013-07-04 15232]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2013-09-17 239320]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2013-09-17 168256]
R1 EpfwLWF;@oem24.inf,%EpfwLWF_Desc%;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2013-09-17 44120]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2013-09-17 220232]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-03-31 3907544]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-05-12 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2014-07-24 122584]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-05-12 64216]
R3 MEIx64;@oem11.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2014-03-20 118272]
R3 NVHDA;@oem15.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2014-03-20 197408]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2014-05-20 12688328]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-05-30 20256]
R3 nvvad_WaveExtensible;@oem18.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-03-31 40392]
R3 RTL8168;@oem9.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2013-12-18 839896]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-05-08 65432]
R2 asComSvc;ASUS Com Service; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [2013-07-04 936728]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2014-02-24 1343408]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2014-04-11 16232]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2014-03-20 154584]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2014-03-20 398296]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-05-12 860472]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-05-12 1809720]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-05-30 1631008]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-05-30 21055432]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-05-20 927520]
R2 PSI_SVC_2_x64;Protexis Licensing V2 x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-11-30 336824]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-05-20 413128]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-28 116648]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-28 116648]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2014-01-31 887232]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-06-06 119408]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119541
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: LNK/Agent.AK

#2 Příspěvek od Rudy »

Zdravím!
Spusťte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předm nic nemažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Hanzell
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 24 črc 2014 11:31

Re: LNK/Agent.AK

#3 Příspěvek od Hanzell »

Zdravím. Omlouvám se že to tak trvalo, ale konečně jsem se po víkendu dostal k pracovnímu PC.
Postuji log MBAM

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 28. 7. 2014
Čas skenování: 7:29:58
Protokol:
Správce: Ano

Verze: 2.00.2.1012
Databáze malwaru: v2014.07.28.01
Databáze rootkitů: v2014.07.17.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Self-protection: Vypnuto

OS: Windows 8.1
CPU: x64
Souborový systém: NTFS
Uživatel: uzivatel

Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 570891
Uplynulý čas: 36 min, 28 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristics: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(No malicious items detected)

Moduly: 0
(No malicious items detected)

Klíče registru: 0
(No malicious items detected)

Hodnoty registru: 0
(No malicious items detected)

Data registru: 0
(No malicious items detected)

Složky: 0
(No malicious items detected)

Soubory: 3
PUP.RiskwareTool.CK, C:\Users\uzivatel\Desktop\ADOBE\Návod na aktivaci\amtlib.dll\32-bit\amtlib.dll, , [746da400bcbf6fc7fa05f11e2cd620e0],
PUP.RiskwareTool.CK, C:\Users\uzivatel\Desktop\ADOBE\Návod na aktivaci\amtlib.dll\64-bit\amtlib.dll, , [d011c2e2aecdef4722de38d8c83aaf51],
Trojan.FakeMS, D:\!!!FIRMY\ZZZ_OSTATNI\MS_Office_2007\EXCEL.EXE, , [6a773173e5963600a821e9a00bf6f808],

Fyzické sektory: 0
(No malicious items detected)


(end)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119541
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: LNK/Agent.AK

#4 Příspěvek od Rudy »

Vše, co MBAM nalezl smažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Hanzell
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 24 črc 2014 11:31

Re: LNK/Agent.AK

#5 Příspěvek od Hanzell »

Omlouvám se, že píši vždy obden ale jelikož jde o pracovní PC, tak nejsem tolik flexibilní :) Soubory smazány, ovšem i když už Eset nic nehlásí, problému mě to nezbavilo. Vypadalo to nadějně, ovšem po vložení flešky do USB se soubory ve složce sice zobrazí, ale během několika vteřin zmizí a už je nezobrazím. V "Tomto počítači" se fleška jeví jako zaplněná, po otevření je ovšem prázdná. Zkoušel jsem několik různých USB disků, několikrát je formátovat na jiném PC, zaplnit daty a opět vložit do infikovaného počítače, ale výsledek je vždy stejný. (Pokud to nevadí zkusím ještě jednou kompletní kontrolu NODem i MBAM)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119541
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: LNK/Agent.AK

#6 Příspěvek od Rudy »

Dejte log ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Hanzell
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 24 črc 2014 11:31

Re: LNK/Agent.AK

#7 Příspěvek od Hanzell »

Bohužel se mi ComboFix nedaří rozjet. Mám v kanceláři nové PC s W8.1 a na fórech jsem se dočetl že osm jedničky zatím nejsou podporovány... Lze použít nějakou alternativu?

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: LNK/Agent.AK

#8 Příspěvek od vyosek »

Zdravim :)

:arrow: Maly dotaz, proc resite sve pracovni na nasem forum a nedate to tomu, kdo je za jeho spravu\udrzbu placen??

:arrow: A to na pracovnim\firemni PC pouzivate nelaglni SW, to jste hoooodne odvazni :?:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Hanzell
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 24 črc 2014 11:31

Re: LNK/Agent.AK

#9 Příspěvek od Hanzell »

Také zdravím, jde o malou firmu kde je každý sám sobě ajťákem, takže co si nevyřeším sám, to nemám :) Jsem jen vojákem v poli, takže s legálností SW také nic nezmůžu... Pokud je to ovšem problém a řeší se tu jen osobní stroje, klidně mi to tu zamkněte/smažte a nějak se s tím už pokusím poprat... :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: LNK/Agent.AK

#10 Příspěvek od vyosek »

Na pracovni\firemni stroje mame nasi vzdalenou pomoc www.neslape.cz kde jsou pripadne i diky obchodnim podminkam chranena data v PC - coz na fopru zarucit nemuzem...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Hanzell
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 24 črc 2014 11:31

Re: LNK/Agent.AK

#11 Příspěvek od Hanzell »

Ok mrknu na to, díky za link a info :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: LNK/Agent.AK

#12 Příspěvek od vyosek »

Neni zac :)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět