zde je log:
Fix result of Farbar Recovery Scan Tool (x64) Version:05-07-2015
Ran by AGA at 2015-07-06 21:33:10 Run:1
Running from C:\Users\AGA\Desktop
Loaded Profiles: AGA (Available Profiles: AGA)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-600620042-11250831-617673667-1001\...\MountPoints2: {af7482cd-69bc-11e4-8262-d8cb8a13fa26} - "H:\.autorun\autorun.exe"
HKU\S-1-5-21-600620042-11250831-617673667-1001\...\MountPoints2: {af748391-69bc-11e4-8262-d8cb8a13fa26} - "I:\Autorun.exe"
HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-21-600620042-11250831-617673667-1001\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-600620042-11250831-617673667-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
http://www.google.com/search?q={sear
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin HKU\S-1-5-21-600620042-11250831-617673667-1001: @acestream.net/acestreamplugin,version=3.0.3 -> C:\Users\AGA\AppData\Roaming\ACEStream\player\npace_plugin.dll [2014-12-07] (Innovative Digital Technologies)
CHR HKLM\...\Chrome\Extension: [fcimjkehglmijlhnpbmjbpoiamjiegod] -
http://clients2.google.com/service/update2/crxCHR HKU\S-1-5-21-600620042-11250831-617673667-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcimjkehglmijlhnpbmjbpoiamjiegod] -
http://clients2.google.com/service/update2/crxCHR HKU\S-1-5-21-600620042-11250831-617673667-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] -
https://clients2.google.com/service/update2/crxCHR HKLM-x32\...\Chrome\Extension: [fcimjkehglmijlhnpbmjbpoiamjiegod] -
http://clients2.google.com/service/update2/crxCHR Extension: (StoreBirds) - C:\Users\AGA\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcimjkehglmijlhnpbmjbpoiamjiegod [2015-07-06]
S2 Service KMSELDI; C:\Programy\KMSpico\Service_KMS.exe [977088 2014-03-02] () [File not signed]
C:\Programy\KMSpico
C:\ProgramData\RogueKiller
C:\Users\AGA\Desktop\mbam-setup-2.1.8.1057.exe
C:\Users\AGA\Desktop\[CzT]Windows_7_Loader_Version_2_2_1.torrent
C:\Users\AGA\Downloads\B935.tmp
C:\Users\AGA\Downloads\7F4F.tmp
C:\Users\AGA\Downloads\DC21.tmp
C:\Users\AGA\Downloads\5631.tmp
C:\ProgramData\CfGH0250.ini
C:\ProgramData\CfGH0280.ini
C:\ProgramData\cfSB0270.ini
C:\ProgramData\cfSB0271.ini
C:\ProgramData\cfSB0300.ini
C:\ProgramData\cfSB0471.ini
C:\ProgramData\cfSB0490.ini
C:\ProgramData\cfSB0560.ini
C:\ProgramData\cfSB0910.ini
C:\ProgramData\cfSB0950.ini
C:\ProgramData\cfSB1090.ini
C:\ProgramData\cfSB1095.ini
C:\ProgramData\cfSB1095A.ini
C:\ProgramData\cfSB1100.ini
C:\ProgramData\CfSB1170.ini
C:\ProgramData\cfSB1240.ini
C:\ProgramData\cfSB1240A.ini
C:\ProgramData\cfSB1290.ini
C:\ProgramData\cfSB1290A.ini
C:\ProgramData\cfSB1300.ini
C:\ProgramData\cfSB1300A.ini
C:\ProgramData\CfSB1360.ini
C:\ProgramData\CfSB1380.ini
C:\ProgramData\CfSB1390.ini
C:\ProgramData\CfSB1530.ini
C:\ProgramData\CfSB1532.ini
C:\ProgramData\cfSB1560.ini
C:\Users\AGA\AppData\Roaming\inst.exe
Task: {04840686-DCF0-4818-A2B6-983AD2A04793} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-600620042-11250831-617673667-1001UA => C:\Users\AGA\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-18] (Dropbox, Inc.)
Task: {5C526C94-0B4C-467D-8F1D-A4CE040C5633} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {83E0DA29-8343-4877-87B1-C0C83FAD373C} - System32\Tasks\AutoPico Daily Restart => C:\Programy\KMSpico\AutoPico.exe [2014-03-02] ()
Task: {91727166-CD64-42EE-806F-DAC3B60E70DA} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-06-12] (Adobe Systems Incorporated)
Task: {B4D69BB4-1FF7-4E7A-A3E1-C9AFE2714EF2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-11] (Google Inc.)
Task: {F671D9E4-1C67-4EE2-87BC-80FBB440B31D} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-600620042-11250831-617673667-1001Core => C:\Users\AGA\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-18] (Dropbox, Inc.)
Task: {FB93D908-BA26-42CB-AEC0-4BA85B9AF91A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-11] (Google Inc.)
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-600620042-11250831-617673667-1001Core.job => C:\Users\AGA\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-600620042-11250831-617673667-1001UA.job => C:\Users\AGA\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\ProgramData\TEMP:054203E4
FirewallRules: [{702BC9D4-44D0-4DBA-A6B0-BD0A82286C17}] => (Allow) C:\Programy\KMSpico\KMSELDI.exe
FirewallRules: [{1CCA3636-7E5A-4B56-AD0E-AA9A3914B188}] => (Allow) C:\Programy\KMSpico\KMSELDI.exe
FirewallRules: [{40ABAF44-F817-4AAB-81F2-FB255ACF4527}] => (Allow) C:\Programy\KMSpico\AutoPico.exe
FirewallRules: [{16B0BD0E-6928-4486-876B-AB84F37A59F4}] => (Allow) C:\Programy\KMSpico\AutoPico.exe
FirewallRules: [{77EBB05D-0E90-49A5-A944-6741C125AA16}] => (Allow) C:\Programy\KMSpico\Service_KMS.exe
FirewallRules: [{E7C00860-F55D-4B21-A5A3-0CF5FC21C673}] => (Allow) C:\Programy\KMSpico\Service_KMS.exe
FirewallRules: [TCP Query User{406A035F-AC2B-46FA-8B7A-1AF207F29CB3}C:\program files (x86)\sopcast\sopcast.exe] => (Allow) C:\program files (x86)\sopcast\sopcast.exe
FirewallRules: [UDP Query User{3A4A1488-963C-4E70-9AC1-8CE4F8B935C3}C:\program files (x86)\sopcast\sopcast.exe] => (Allow) C:\program files (x86)\sopcast\sopcast.exe
FirewallRules: [{265FF7B2-FE65-4DE6-A128-49A72671FE98}] => (Allow) C:\Programy\KMSpico\Service_KMS.exe
FirewallRules: [{1DB47D29-3968-4C9C-A1A5-CC63977305A3}] => (Allow) C:\Programy\KMSpico\Service_KMS.exe
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
"HKU\S-1-5-21-600620042-11250831-617673667-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{af7482cd-69bc-11e4-8262-d8cb8a13fa26}" => key removed successfully
HKCR\CLSID\{af7482cd-69bc-11e4-8262-d8cb8a13fa26} => key not found.
"HKU\S-1-5-21-600620042-11250831-617673667-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{af748391-69bc-11e4-8262-d8cb8a13fa26}" => key removed successfully
HKCR\CLSID\{af748391-69bc-11e4-8262-d8cb8a13fa26} => key not found.
HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE => value removed successfully
HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE => value removed successfully
HKU\S-1-5-21-600620042-11250831-617673667-1001\Control Panel\Desktop\\SCRNSAVE.EXE => value removed successfully
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-600620042-11250831-617673667-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => key removed successfully
HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => key not found.
"HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3" => key removed successfully
C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll => moved successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9" => key removed successfully
C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll not found.
"HKU\S-1-5-21-600620042-11250831-617673667-1001\Software\MozillaPlugins\@acestream.net/acestreamplugin,version=3.0.3" => key removed successfully
C:\Users\AGA\AppData\Roaming\ACEStream\player\npace_plugin.dll => moved successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\fcimjkehglmijlhnpbmjbpoiamjiegod" => key removed successfully
"HKU\S-1-5-21-600620042-11250831-617673667-1001\SOFTWARE\Google\Chrome\Extensions\fcimjkehglmijlhnpbmjbpoiamjiegod" => key removed successfully
"HKU\S-1-5-21-600620042-11250831-617673667-1001\SOFTWARE\Google\Chrome\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fcimjkehglmijlhnpbmjbpoiamjiegod" => key removed successfully
C:\Users\AGA\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcimjkehglmijlhnpbmjbpoiamjiegod => moved successfully.
Service KMSELDI => Service removed successfully
C:\Programy\KMSpico => moved successfully.
C:\ProgramData\RogueKiller => moved successfully.
C:\Users\AGA\Desktop\mbam-setup-2.1.8.1057.exe => moved successfully.
C:\Users\AGA\Desktop\[CzT]Windows_7_Loader_Version_2_2_1.torrent => moved successfully.
C:\Users\AGA\Downloads\B935.tmp => moved successfully.
C:\Users\AGA\Downloads\7F4F.tmp => moved successfully.
C:\Users\AGA\Downloads\DC21.tmp => moved successfully.
C:\Users\AGA\Downloads\5631.tmp => moved successfully.
C:\ProgramData\CfGH0250.ini => moved successfully.
C:\ProgramData\CfGH0280.ini => moved successfully.
C:\ProgramData\cfSB0270.ini => moved successfully.
C:\ProgramData\cfSB0271.ini => moved successfully.
C:\ProgramData\cfSB0300.ini => moved successfully.
C:\ProgramData\cfSB0471.ini => moved successfully.
C:\ProgramData\cfSB0490.ini => moved successfully.
C:\ProgramData\cfSB0560.ini => moved successfully.
C:\ProgramData\cfSB0910.ini => moved successfully.
C:\ProgramData\cfSB0950.ini => moved successfully.
C:\ProgramData\cfSB1090.ini => moved successfully.
C:\ProgramData\cfSB1095.ini => moved successfully.
C:\ProgramData\cfSB1095A.ini => moved successfully.
C:\ProgramData\cfSB1100.ini => moved successfully.
C:\ProgramData\CfSB1170.ini => moved successfully.
C:\ProgramData\cfSB1240.ini => moved successfully.
C:\ProgramData\cfSB1240A.ini => moved successfully.
C:\ProgramData\cfSB1290.ini => moved successfully.
C:\ProgramData\cfSB1290A.ini => moved successfully.
C:\ProgramData\cfSB1300.ini => moved successfully.
C:\ProgramData\cfSB1300A.ini => moved successfully.
C:\ProgramData\CfSB1360.ini => moved successfully.
C:\ProgramData\CfSB1380.ini => moved successfully.
C:\ProgramData\CfSB1390.ini => moved successfully.
C:\ProgramData\CfSB1530.ini => moved successfully.
C:\ProgramData\CfSB1532.ini => moved successfully.
C:\ProgramData\cfSB1560.ini => moved successfully.
C:\Users\AGA\AppData\Roaming\inst.exe => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{04840686-DCF0-4818-A2B6-983AD2A04793}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{04840686-DCF0-4818-A2B6-983AD2A04793}" => key removed successfully
C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-600620042-11250831-617673667-1001UA => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DropboxUpdateTaskUserS-1-5-21-600620042-11250831-617673667-1001UA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5C526C94-0B4C-467D-8F1D-A4CE040C5633}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5C526C94-0B4C-467D-8F1D-A4CE040C5633}" => key removed successfully
C:\Windows\System32\Tasks\Apple\AppleSoftwareUpdate => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Apple\AppleSoftwareUpdate" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{83E0DA29-8343-4877-87B1-C0C83FAD373C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83E0DA29-8343-4877-87B1-C0C83FAD373C}" => key removed successfully
C:\Windows\System32\Tasks\AutoPico Daily Restart => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoPico Daily Restart" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{91727166-CD64-42EE-806F-DAC3B60E70DA}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{91727166-CD64-42EE-806F-DAC3B60E70DA}" => key removed successfully
C:\Windows\System32\Tasks\Adobe Acrobat Update Task => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Acrobat Update Task" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B4D69BB4-1FF7-4E7A-A3E1-C9AFE2714EF2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4D69BB4-1FF7-4E7A-A3E1-C9AFE2714EF2}" => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F671D9E4-1C67-4EE2-87BC-80FBB440B31D}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F671D9E4-1C67-4EE2-87BC-80FBB440B31D}" => key removed successfully
C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-600620042-11250831-617673667-1001Core => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DropboxUpdateTaskUserS-1-5-21-600620042-11250831-617673667-1001Core" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FB93D908-BA26-42CB-AEC0-4BA85B9AF91A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FB93D908-BA26-42CB-AEC0-4BA85B9AF91A}" => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => key removed successfully
C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-600620042-11250831-617673667-1001Core.job => moved successfully.
C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-600620042-11250831-617673667-1001UA.job => moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully.
C:\ProgramData\TEMP => ":054203E4" ADS removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{702BC9D4-44D0-4DBA-A6B0-BD0A82286C17} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1CCA3636-7E5A-4B56-AD0E-AA9A3914B188} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{40ABAF44-F817-4AAB-81F2-FB255ACF4527} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{16B0BD0E-6928-4486-876B-AB84F37A59F4} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{77EBB05D-0E90-49A5-A944-6741C125AA16} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E7C00860-F55D-4B21-A5A3-0CF5FC21C673} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{406A035F-AC2B-46FA-8B7A-1AF207F29CB3}C:\program files (x86)\sopcast\sopcast.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{3A4A1488-963C-4E70-9AC1-8CE4F8B935C3}C:\program files (x86)\sopcast\sopcast.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{265FF7B2-FE65-4DE6-A128-49A72671FE98} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1DB47D29-3968-4C9C-A1A5-CC63977305A3} => value removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully.
Hosts restored successfully.
EmptyTemp: => 459.6 MB temporary data Removed.
The system needed a reboot..
==== End of Fixlog 21:33:13 ====
=================================================================================
zde jsou linky toho antivir testování:
https://www.virustotal.com/cs/file/f5a4591f86dbe7924707c7a691cd2b7dca365359c81dc2dfc14713ed295525c9/analysis/1436211403/https://www.virustotal.com/cs/file/66616d553e18313756249e739b95dd856d5cf83f66565cbc61636030398109d1/analysis/1436211535/https://www.virustotal.com/cs/file/6166b82ce51d60eee2f50985ef707da75e262e0d2038e4b98fc499ab29dbb346/analysis/1436211634/https://www.virustotal.com/cs/file/1af47113778d411bf3cf82acf428676908121b1f3252133a5f98e188ed1e9c6c/analysis/1436211695/https://www.virustotal.com/cs/file/e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855/analysis/1436211773/ten poslední nejde udelat, protoze ten soubor neexistuje v tom Tempu.. je tam dosti podobný, ale liší se poslední "předpíponou" před .dll
dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.
tmpykxx6x.dll
EDIT: otevrel jsem YT v IE, ale opet stejna nabídka jako v chromu: