Nakonec se mi podařil i log
ComboFix 14-12-08.01 - Mozi 09.12.2014 22:21:30.2.2 - x64 MINIMAL
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4095.3485 [GMT 1:00]
Spuštěný z: c:\dokumenty moje\aplikace\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-- Předchozí spuštění --
.
c:\windows\SysWow64\ole32.dll . . . je infikován!!
.
--------
.
c:\windows\SysWow64\ole32.dll . . . je infikován!!
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_WiseBootAssistant
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-11-09 do 2014-12-09 )))))))))))))))))))))))))))))))
.
.
2014-12-09 21:37 . 2014-12-09 21:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-12-09 19:33 . 2014-11-17 01:08 11632448 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{90410574-D174-4213-ACDC-880CE34BAC8B}\mpengine.dll
2014-12-09 16:26 . 2014-12-09 16:26 -------- d-----w- c:\users\Mozi\AppData\Local\ElevatedDiagnostics
2014-12-08 05:47 . 2014-12-08 05:47 -------- d-sh--w- c:\users\Mozi\AppData\Local\EmieUserList
2014-12-08 05:47 . 2014-12-08 05:47 -------- d-sh--w- c:\users\Mozi\AppData\Local\EmieSiteList
2014-12-04 15:18 . 2014-12-04 15:18 -------- d-----w- c:\program files\CCleaner
2014-12-04 14:48 . 2014-12-04 14:51 -------- d-----w- c:\windows\system32\vbox
2014-12-04 14:48 . 2014-12-04 14:51 -------- d-----w- c:\windows\SysWow64\vbox
2014-12-04 14:33 . 2014-12-04 14:30 364512 ----a-w- c:\windows\system32\aswBoot.exe
2014-12-04 14:30 . 2014-12-04 14:30 43152 ----a-w- c:\windows\avastSS.scr
2014-12-04 12:48 . 2014-12-04 12:48 -------- d-----w- c:\users\Mozi\AppData\Local\Skype
2014-12-04 12:48 . 2014-12-09 06:06 -------- d-----w- c:\users\Mozi\AppData\Roaming\Skype
2014-12-04 12:48 . 2014-12-04 12:48 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-12-04 12:48 . 2014-12-04 12:48 -------- d-----r- c:\program files (x86)\Skype
2014-12-04 12:48 . 2014-12-04 12:48 -------- d-----w- c:\programdata\Skype
2014-12-03 13:18 . 2014-12-03 13:18 -------- d-----w- C:\found.001
2014-12-01 17:45 . 2014-12-01 17:45 -------- d-----w- c:\users\Mozi\AppData\Local\Diagnostics
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-12-09 21:15 . 2014-10-11 00:38 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-12-04 14:37 . 2014-10-08 13:45 1050432 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-12-04 14:30 . 2014-10-08 13:45 116728 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-12-04 14:30 . 2014-10-08 13:45 267632 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-12-04 14:30 . 2014-10-08 13:45 436624 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-12-04 14:30 . 2014-10-08 13:45 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-12-04 14:30 . 2014-10-08 13:45 83280 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-12-04 14:30 . 2014-10-08 13:44 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-12-04 14:30 . 2014-10-08 13:44 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-12-03 13:48 . 2014-10-08 13:27 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-12-03 13:48 . 2014-10-08 13:27 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-11-24 13:04 . 2014-10-08 13:16 275080 ------w- c:\windows\system32\MpSigStub.exe
2014-11-21 05:14 . 2014-10-11 00:38 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-11-21 05:14 . 2014-10-11 00:38 93400 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-11-21 05:14 . 2014-10-11 00:38 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-11-04 06:25 . 2014-11-04 06:25 706084 ----a-w- c:\program files (x86)\unins000.exe
2014-10-31 22:26 . 2014-10-08 13:17 103374192 ----a-w- c:\windows\system32\MRT.exe
2014-10-17 19:51 . 2014-10-17 19:51 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2014-10-09 16:40 . 2014-10-09 16:40 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-10-09 16:40 . 2014-10-09 16:40 942592 ----a-w- c:\windows\system32\jsIntl.dll
2014-10-09 16:40 . 2014-10-09 16:40 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-10-09 16:40 . 2014-10-09 16:40 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2014-10-09 16:40 . 2014-10-09 16:40 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2014-10-09 16:40 . 2014-10-09 16:40 85504 ----a-w- c:\windows\system32\mshtmled.dll
2014-10-09 16:40 . 2014-10-09 16:40 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-10-09 16:40 . 2014-10-09 16:40 81408 ----a-w- c:\windows\system32\icardie.dll
2014-10-09 16:40 . 2014-10-09 16:40 775168 ----a-w- c:\windows\system32\ieapfltr.dll
2014-10-09 16:40 . 2014-10-09 16:40 774144 ----a-w- c:\windows\system32\jscript.dll
2014-10-09 16:40 . 2014-10-09 16:40 77312 ----a-w- c:\windows\system32\tdc.ocx
2014-10-09 16:40 . 2014-10-09 16:40 758272 ----a-w- c:\windows\system32\jscript9diag.dll
2014-10-09 16:40 . 2014-10-09 16:40 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2014-10-09 16:40 . 2014-10-09 16:40 727040 ----a-w- c:\windows\system32\msfeeds.dll
2014-10-09 16:40 . 2014-10-09 16:40 72704 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2014-10-09 16:40 . 2014-10-09 16:40 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2014-10-09 16:40 . 2014-10-09 16:40 707072 ----a-w- c:\windows\system32\ie4uinit.exe
2014-10-09 16:40 . 2014-10-09 16:40 66048 ----a-w- c:\windows\system32\iesetup.dll
2014-10-09 16:40 . 2014-10-09 16:40 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2014-10-09 16:40 . 2014-10-09 16:40 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2014-10-09 16:40 . 2014-10-09 16:40 62464 ----a-w- c:\windows\system32\pngfilt.dll
2014-10-09 16:40 . 2014-10-09 16:40 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2014-10-09 16:40 . 2014-10-09 16:40 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2014-10-09 16:40 . 2014-10-09 16:40 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2014-10-09 16:40 . 2014-10-09 16:40 60416 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2014-10-09 16:40 . 2014-10-09 16:40 597504 ----a-w- c:\windows\SysWow64\jscript9diag.dll
2014-10-09 16:40 . 2014-10-09 16:40 596480 ----a-w- c:\windows\system32\ieui.dll
2014-10-09 16:40 . 2014-10-09 16:40 5833728 ----a-w- c:\windows\system32\jscript9.dll
2014-10-09 16:40 . 2014-10-09 16:40 547328 ----a-w- c:\windows\system32\vbscript.dll
2014-10-09 16:40 . 2014-10-09 16:40 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2014-10-09 16:40 . 2014-10-09 16:40 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2014-10-09 16:40 . 2014-10-09 16:40 51200 ----a-w- c:\windows\system32\jsproxy.dll
2014-10-09 16:40 . 2014-10-09 16:40 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2014-10-09 16:40 . 2014-10-09 16:40 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-10-09 16:40 . 2014-10-09 16:40 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll
2014-10-09 16:40 . 2014-10-09 16:40 48128 ----a-w- c:\windows\system32\imgutil.dll
2014-10-09 16:40 . 2014-10-09 16:40 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-10-09 16:40 . 2014-10-09 16:40 446464 ----a-w- c:\windows\system32\dxtmsft.dll
2014-10-09 16:40 . 2014-10-09 16:40 4232704 ----a-w- c:\windows\SysWow64\jscript9.dll
2014-10-09 16:40 . 2014-10-09 16:40 413696 ----a-w- c:\windows\system32\html.iec
2014-10-09 16:40 . 2014-10-09 16:40 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2014-10-09 16:40 . 2014-10-09 16:40 374968 ----a-w- c:\windows\system32\iedkcs32.dll
2014-10-09 16:40 . 2014-10-09 16:40 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2014-10-09 16:40 . 2014-10-09 16:40 33792 ----a-w- c:\windows\system32\iernonce.dll
2014-10-09 16:40 . 2014-10-09 16:40 337408 ----a-w- c:\windows\SysWow64\html.iec
2014-10-09 16:40 . 2014-10-09 16:40 30208 ----a-w- c:\windows\system32\licmgr10.dll
2014-10-09 16:40 . 2014-10-09 16:40 289280 ----a-w- c:\windows\system32\dxtrans.dll
2014-10-09 16:40 . 2014-10-09 16:40 2793984 ----a-w- c:\windows\system32\iertutil.dll
2014-10-09 16:40 . 2014-10-09 16:40 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-10-09 16:40 . 2014-10-09 16:40 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-10-09 16:40 . 2014-10-09 16:40 247808 ----a-w- c:\windows\system32\msls31.dll
2014-10-09 16:40 . 2014-10-09 16:40 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2014-10-09 16:40 . 2014-10-09 16:40 243200 ----a-w- c:\windows\system32\webcheck.dll
2014-10-09 16:40 . 2014-10-09 16:40 23591424 ----a-w- c:\windows\system32\mshtml.dll
2014-10-09 16:40 . 2014-10-09 16:40 235520 ----a-w- c:\windows\system32\url.dll
2014-10-09 16:40 . 2014-10-09 16:40 235008 ----a-w- c:\windows\system32\elshyph.dll
2014-10-09 16:40 . 2014-10-09 16:40 2310656 ----a-w- c:\windows\system32\wininet.dll
2014-10-09 16:40 . 2014-10-09 16:40 2104832 ----a-w- c:\windows\system32\inetcpl.cpl
2014-10-09 16:40 . 2014-10-09 16:40 2014208 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2014-10-09 16:40 . 2014-10-09 16:40 195584 ----a-w- c:\windows\system32\msrating.dll
2014-10-09 16:40 . 2014-10-09 16:40 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2014-10-09 16:40 . 2014-10-09 16:40 1812992 ----a-w- c:\windows\SysWow64\wininet.dll
2014-10-09 16:40 . 2014-10-09 16:40 167424 ----a-w- c:\windows\system32\iexpress.exe
2014-10-09 16:40 . 2014-10-09 16:40 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2014-10-09 16:40 . 2014-10-09 16:40 147968 ----a-w- c:\windows\system32\occache.dll
2014-10-09 16:40 . 2014-10-09 16:40 1447424 ----a-w- c:\windows\system32\urlmon.dll
2014-10-09 16:40 . 2014-10-09 16:40 143872 ----a-w- c:\windows\system32\wextract.exe
2014-10-09 16:40 . 2014-10-09 16:40 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2014-10-09 16:40 . 2014-10-09 16:40 139264 ----a-w- c:\windows\system32\ieUnatt.exe
2014-10-09 16:40 . 2014-10-09 16:40 13824 ----a-w- c:\windows\system32\mshta.exe
2014-10-09 16:40 . 2014-10-09 16:40 13588480 ----a-w- c:\windows\system32\ieframe.dll
2014-10-09 16:40 . 2014-10-09 16:40 135680 ----a-w- c:\windows\system32\iepeers.dll
2014-10-09 16:40 . 2014-10-09 16:40 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2014-10-09 16:40 . 2014-10-09 16:40 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2014-10-09 16:40 . 2014-10-09 16:40 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-10-09 16:40 . 2014-10-09 16:40 1249280 ----a-w- c:\windows\system32\mshtmlmedia.dll
2014-10-09 16:40 . 2014-10-09 16:40 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2014-10-09 16:40 . 2014-10-09 16:40 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2014-10-09 16:40 . 2014-10-09 16:40 111616 ----a-w- c:\windows\system32\ieetwcollector.exe
2014-10-09 16:40 . 2014-10-09 16:40 1068032 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2014-10-09 16:40 . 2014-10-09 16:40 105984 ----a-w- c:\windows\system32\iesysprep.dll
2014-10-09 16:40 . 2014-10-09 16:40 101376 ----a-w- c:\windows\system32\inseng.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912]
"cz.seznam.software.autoupdate"="c:\users\Mozi\AppData\Roaming\Seznam.cz\szninstall.exe" [2013-05-16 1062472]
"cz.seznam.software.szndesktop"="c:\users\Mozi\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2013-04-12 92664]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2014-11-21 7063832]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-12-04 5226600]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-08-21 959176]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-10-09 2762240]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 AvastVBoxSvc;AvastVBox COM Service;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [x]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2014-12-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-08 13:48]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-12-04 14:30 860984 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-08-19 1796056]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://
www.seznam.cz/?clid=13415
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 213.46.172.37 213.46.172.36
FF - ProfilePath - c:\users\Mozi\AppData\Roaming\Mozilla\Firefox\Profiles\aig3pr23.default-1418154316883\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
.
**************************************************************************
.
Celkový čas: 2014-12-09 23:05:47 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-12-09 22:05
.
Před spuštěním: Volných bajtů: 443 569 893 376
Po spuštění: Volných bajtů: 443 709 501 440
.
- - End Of File - - 5DFFBCEED6AAD390AD5F85C31583944A
A36C5E4F47E84449FF07ED3517B43A31