Kontrola a chyba (mdi064.dll)
Napsal: 27 led 2014 09:48
Zdravim,
po dlhsom case bez problemov sa na vas musim obratit s prosbou o pomoc. Tentoraz ide o kamosov ntb, kde mu vyhadzuje pri spusteni Eset tuto hlasku:
"27.1.2014 9:31:41 Kontrola při startu soubor Operační paměť » C:\DOCUME~1\JURAJB~1\LOCALS~1\Temp\mdi064.dll varianta infiltrace Win32/CoinMiner.KA trojský kůň chyba při mazání JURAJ\Juraj Banas"
Vdaka za rady. Prikladam Log z FRST: (u RSIT po stlaceni continue vyhodilo chybu)
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-01-2014
Ran by Juraj Banas (administrator) on JURAJ on 27-01-2014 09:39:34
Running from C:\Documents and Settings\Juraj Banas\Desktop
Microsoft Windows XP Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
ATTENTION: If processes are not listed WMI should be repaired.
==================== Processes (Whitelisted) ===================
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDCPL] - C:\WINDOWS\RTHDCPL.EXE [16248320 2006-06-28] (Realtek Semiconductor Corp.)
HKLM\...\Run: [SkyTel] - C:\WINDOWS\SkyTel.EXE [2879488 2006-05-16] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] - C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AzMixerSel] - C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [53248 2005-12-21] (Realtek Semiconductor Corp.)
HKLM\...\Run: [LogitechCommunicationsManager] - C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe [304664 2006-10-31] (Acer Inc.)
HKLM\...\Run: [AcerOrbicamRibbon] - C:\Program Files\Acer\OrbiCam10\OrbiCam.exe [754712 2006-11-28] ()
HKLM\...\Run: [LVCOMSX] - C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe [244512 2006-11-28] (Logitech Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [761946 2006-03-03] (Synaptics, Inc.)
HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [13594624 2009-01-30] (NVIDIA Corporation)
HKLM\...\Run: [nwiz] - nwiz.exe /install
HKLM\...\Run: [NvMediaCenter] - C:\WINDOWS\system32\NvMcTray.dll [86016 2009-01-30] (NVIDIA Corporation)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [MSStp] - C:\WINDOWS\system32\msstp.vbe [1418 2014-01-13] ()
HKLM\...\Run: [mncvkfyfSrv] - C:\WINDOWS\inf\mncvkfyf.vbe [1338 2014-01-13] ()
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [2021400 2009-02-06] (ESET)
HKCU\...\Run: [tsiVideo] - C:\DOCUME~1\JURAJB~1\LOCALS~1\Temp\\mdi064.dll [3997696 2014-01-22] () <===== ATTENTION
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mail.ru/cnt/9134
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
SearchScopes: HKCU - DefaultScope {E88E0043-C9D4-4e33-8555-FEE4F5B63060} URL = http://go.mail.ru/search?q={searchTerms ... =1&fr=ietb
SearchScopes: HKCU - {E88E0043-C9D4-4e33-8555-FEE4F5B63060} URL = http://go.mail.ru/search?q={searchTerms ... =1&fr=ietb
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 172.16.40.1
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Juraj Banas\Application Data\Mozilla\Firefox\Profiles\297eyo2j.default
FF Homepage: hxxp://www.zoznam.sk/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.5.1 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\zoznam-sk.xml
FF Extension: Спутник @Mail.Ru - C:\Documents and Settings\Juraj Banas\Application Data\Mozilla\Firefox\Profiles\297eyo2j.default\Extensions\{37964A3C-4EE8-47b1-8321-34DE2C39BA4D} [2013-12-18]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: Eset Plugin - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-01-22]
========================== Services (Whitelisted) =================
S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [20680 2009-02-06] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [727720 2009-02-06] (ESET)
R2 JavaQuickStarterService; C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe [161664 2012-05-04] (Oracle Corporation)
S2 LVSrvLauncher; C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe [101152 2006-11-28] (Logitech Inc.)
S2 NOD32FiXTemDono; C:\WINDOWS\system32\regedt32.exe [3584 2006-02-28] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [328061 2006-01-17] (Broadcom Corporation.)
S3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [30459 2006-01-17] (Broadcom Corporation.)
R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [850474 2006-01-17] (Broadcom Corporation.)
R2 BTSERIAL; C:\WINDOWS\system32\drivers\btserial.sys [23271 2006-01-17] (Broadcom Corporation.)
S3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [148900 2006-01-17] (Broadcom Corporation.)
S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [65688 2006-01-17] (Broadcom Corporation.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R2 eamon; C:\WINDOWS\System32\DRIVERS\eamon.sys [113448 2009-02-06] (ESET)
R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [106208 2009-02-06] (ESET)
R3 EMSCR; C:\WINDOWS\System32\DRIVERS\EMS7SK.sys [61056 2006-06-16] (ENE Technology Inc.)
R2 epfw; C:\WINDOWS\System32\DRIVERS\epfw.sys [130952 2009-02-06] (ESET)
R3 Epfwndis; C:\WINDOWS\System32\DRIVERS\Epfwndis.sys [33096 2009-02-06] (ESET)
R1 epfwtdi; C:\WINDOWS\System32\DRIVERS\epfwtdi.sys [56280 2009-02-06] (ESET)
R3 ESDCR; C:\WINDOWS\System32\DRIVERS\ESD7SK.sys [40064 2006-06-16] (ENE Technology Inc.)
R3 ESMCR; C:\WINDOWS\System32\DRIVERS\ESM7SK.sys [74752 2006-06-16] (ENE Technology Inc.)
R3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [209664 2006-12-22] (Conexant Systems, Inc.)
R3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [988800 2006-12-22] (Conexant Systems, Inc.)
R3 lv321av; C:\WINDOWS\System32\DRIVERS\lv321av.sys [847392 2006-11-28] (Logitech Inc.)
R3 LVMVDrv; C:\WINDOWS\System32\DRIVERS\LVMVDrv.sys [1962784 2006-11-28] (Logitech Inc.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
R3 SMCIRDA; C:\WINDOWS\System32\DRIVERS\smcirda.sys [46080 2004-06-16] (SMSC)
R3 w39n51; C:\WINDOWS\System32\DRIVERS\w39n51.sys [1429632 2006-04-04] (Intel® Corporation)
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [x]
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-27 09:39 - 2014-01-27 09:39 - 00009445 _____ C:\Documents and Settings\Juraj Banas\Desktop\FRST.txt
2014-01-27 09:39 - 2014-01-27 09:39 - 00000000 ____D C:\FRST
2014-01-27 09:38 - 2014-01-27 09:38 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Juraj Banas\Desktop\FRSTLauncher.exe
2014-01-27 09:38 - 2014-01-27 09:38 - 00029696 _____ C:\Documents and Settings\Juraj Banas\Local Settings\Application Data\MSGBOX.EXE
2014-01-27 09:38 - 2014-01-27 09:38 - 00015327 _____ C:\Documents and Settings\Juraj Banas\Desktop\LM.bat
2014-01-27 09:37 - 2014-01-27 09:37 - 01223168 _____ (Farbar) C:\Documents and Settings\Juraj Banas\Desktop\FRST.exe
2014-01-27 09:34 - 2014-01-27 09:34 - 00002341 _____ C:\WINDOWS\setupapi.log
2014-01-27 09:34 - 2014-01-27 09:34 - 00000000 ____D C:\rsit
2014-01-22 14:05 - 2014-01-22 14:05 - 00000000 ____D C:\Program Files\ESET
2014-01-22 14:05 - 2014-01-22 14:05 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\ESET
2014-01-22 13:55 - 2014-01-13 10:25 - 00001418 ____S C:\WINDOWS\system32\msstp.vbe
2014-01-22 09:02 - 2008-03-03 18:21 - 00000568 ____H C:\WINDOWS\nod32fixtemdono.reg
2014-01-22 08:29 - 2014-01-22 08:29 - 00000000 __HDC C:\WINDOWS\$NtUninstallbasecsp$
2014-01-22 08:28 - 2011-08-16 11:45 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iecompat.dll
2014-01-22 08:28 - 2011-03-11 15:10 - 00225262 ____C C:\WINDOWS\system32\dllcache\msimain.sdb
2014-01-22 08:25 - 2014-01-22 08:25 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2014-01-20 18:43 - 2014-01-20 18:43 - 00000719 _____ C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
2014-01-11 10:20 - 2014-01-11 10:20 - 00069232 _____ C:\Documents and Settings\Juraj Banas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2014-01-07 18:47 - 2014-01-07 18:47 - 00000000 __SHD C:\Documents and Settings\LocalService\IETldCache
2014-01-07 18:45 - 2014-01-11 10:47 - 00000000 ____D C:\Documents and Settings\Juraj Banas\Application Data\Skype
2014-01-07 18:45 - 2014-01-07 18:45 - 00000000 ___RD C:\Program Files\Skype
2014-01-07 18:45 - 2014-01-07 18:45 - 00000000 ____D C:\Program Files\Common Files\Skype
2014-01-07 18:45 - 2014-01-07 18:45 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Skype
2014-01-07 18:44 - 2014-01-07 18:45 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Skype
2014-01-07 18:12 - 2014-01-07 18:12 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
2013-12-31 14:15 - 2013-12-31 14:15 - 00000000 ____D C:\Program Files\Mozilla Firefox
==================== One Month Modified Files and Folders =======
2014-01-27 09:39 - 2014-01-27 09:39 - 00009445 _____ C:\Documents and Settings\Juraj Banas\Desktop\FRST.txt
2014-01-27 09:39 - 2014-01-27 09:39 - 00000000 ____D C:\FRST
2014-01-27 09:39 - 2013-12-05 08:50 - 01799959 _____ C:\WINDOWS\WindowsUpdate.log
2014-01-27 09:38 - 2014-01-27 09:38 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Juraj Banas\Desktop\FRSTLauncher.exe
2014-01-27 09:38 - 2014-01-27 09:38 - 00029696 _____ C:\Documents and Settings\Juraj Banas\Local Settings\Application Data\MSGBOX.EXE
2014-01-27 09:38 - 2014-01-27 09:38 - 00015327 _____ C:\Documents and Settings\Juraj Banas\Desktop\LM.bat
2014-01-27 09:38 - 2013-12-05 11:12 - 00000000 ____D C:\Documents and Settings\Juraj Banas\My Documents\Preberanie
2014-01-27 09:37 - 2014-01-27 09:37 - 01223168 _____ (Farbar) C:\Documents and Settings\Juraj Banas\Desktop\FRST.exe
2014-01-27 09:34 - 2014-01-27 09:34 - 00002341 _____ C:\WINDOWS\setupapi.log
2014-01-27 09:34 - 2014-01-27 09:34 - 00000000 ____D C:\rsit
2014-01-27 09:28 - 2013-12-05 09:37 - 00000051 _____ C:\WINDOWS\wiaservc.log
2014-01-27 09:27 - 2013-12-05 13:19 - 00201679 _____ C:\WINDOWS\system32\nvapps.xml
2014-01-27 09:27 - 2013-12-05 09:37 - 00000159 _____ C:\WINDOWS\wiadebug.log
2014-01-27 09:27 - 2013-12-05 08:55 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2014-01-27 09:26 - 2013-12-09 08:43 - 00065536 _____ C:\WINDOWS\system32\config\Internet.evt
2014-01-27 09:26 - 2013-12-09 07:20 - 00065536 _____ C:\WINDOWS\system32\config\ODiag.evt
2014-01-27 09:26 - 2013-12-05 08:57 - 00000178 ___SH C:\Documents and Settings\Juraj Banas\ntuser.ini
2014-01-27 09:26 - 2013-12-05 08:55 - 00032578 _____ C:\WINDOWS\SchedLgU.Txt
2014-01-27 09:22 - 2013-12-05 08:57 - 00000000 ____D C:\Documents and Settings\Juraj Banas
2014-01-27 08:58 - 2013-12-09 10:44 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-01-27 08:38 - 2013-12-05 08:56 - 00000000 __SHD C:\WINDOWS\CSC
2014-01-27 08:38 - 2006-02-28 13:00 - 00002422 _____ C:\WINDOWS\system32\wpa.dbl
2014-01-22 14:05 - 2014-01-22 14:05 - 00000000 ____D C:\Program Files\ESET
2014-01-22 14:05 - 2014-01-22 14:05 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\ESET
2014-01-22 08:32 - 2013-12-09 20:33 - 00000000 ____D C:\WINDOWS\pss
2014-01-22 08:30 - 2013-12-05 08:51 - 00000000 ___HD C:\WINDOWS\$hf_mig$
2014-01-22 08:29 - 2014-01-22 08:29 - 00000000 __HDC C:\WINDOWS\$NtUninstallbasecsp$
2014-01-22 08:29 - 2013-12-05 11:09 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ESET
2014-01-22 08:29 - 2013-12-05 09:23 - 00000000 ____D C:\WINDOWS\security
2014-01-22 08:25 - 2014-01-22 08:25 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2014-01-20 18:45 - 2013-12-09 12:43 - 00000000 ____D C:\Documents and Settings\Juraj Banas\Application Data\vlc
2014-01-20 18:43 - 2014-01-20 18:43 - 00000719 _____ C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
2014-01-20 18:39 - 2013-12-19 19:14 - 00006144 _____ C:\Documents and Settings\Juraj Banas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-18 11:57 - 2013-12-05 09:23 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2014-01-16 15:40 - 2013-12-18 18:16 - 00000000 ____D C:\WINDOWS\system32\MRT
2014-01-16 15:38 - 2013-12-18 18:15 - 83425928 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-01-15 13:59 - 2013-12-09 12:27 - 00002347 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk
2014-01-13 10:25 - 2014-01-22 13:55 - 00001418 ____S C:\WINDOWS\system32\msstp.vbe
2014-01-11 10:47 - 2014-01-07 18:45 - 00000000 ____D C:\Documents and Settings\Juraj Banas\Application Data\Skype
2014-01-11 10:20 - 2014-01-11 10:20 - 00069232 _____ C:\Documents and Settings\Juraj Banas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2014-01-11 09:52 - 2013-12-05 10:59 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2014-01-07 18:47 - 2014-01-07 18:47 - 00000000 __SHD C:\Documents and Settings\LocalService\IETldCache
2014-01-07 18:47 - 2013-12-05 10:11 - 00003419 _____ C:\WINDOWS\system32\lvcoinst.log
2014-01-07 18:47 - 2013-12-05 08:55 - 00000000 __SHD C:\Documents and Settings\LocalService
2014-01-07 18:45 - 2014-01-07 18:45 - 00000000 ___RD C:\Program Files\Skype
2014-01-07 18:45 - 2014-01-07 18:45 - 00000000 ____D C:\Program Files\Common Files\Skype
2014-01-07 18:45 - 2014-01-07 18:45 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Skype
2014-01-07 18:45 - 2014-01-07 18:44 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Skype
2014-01-07 18:12 - 2014-01-07 18:12 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
2014-01-07 18:12 - 2013-12-09 12:44 - 00000000 ____D C:\Program Files\CCleaner
2013-12-31 14:15 - 2013-12-31 14:15 - 00000000 ____D C:\Program Files\Mozilla Firefox
Files to move or delete:
====================
C:\DOCUME~1\JURAJB~1\LOCALS~1\Temp\\mdi064.dll
Some content of TEMP:
====================
C:\Documents and Settings\deti\Local Settings\Temp\RtkBtMnt.exe
C:\Documents and Settings\Juraj Banas\Local Settings\Temp\fp_pl_pfs_installer.exe
C:\Documents and Settings\Juraj Banas\Local Settings\Temp\GuardMailRu.exe
C:\Documents and Settings\Juraj Banas\Local Settings\Temp\mdi064.dll
C:\Documents and Settings\Juraj Banas\Local Settings\Temp\RtkBtMnt.exe
C:\Documents and Settings\Juraj Banas\Local Settings\Temp\vlc-2.1.2-win32.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================
po dlhsom case bez problemov sa na vas musim obratit s prosbou o pomoc. Tentoraz ide o kamosov ntb, kde mu vyhadzuje pri spusteni Eset tuto hlasku:
"27.1.2014 9:31:41 Kontrola při startu soubor Operační paměť » C:\DOCUME~1\JURAJB~1\LOCALS~1\Temp\mdi064.dll varianta infiltrace Win32/CoinMiner.KA trojský kůň chyba při mazání JURAJ\Juraj Banas"
Vdaka za rady. Prikladam Log z FRST: (u RSIT po stlaceni continue vyhodilo chybu)
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-01-2014
Ran by Juraj Banas (administrator) on JURAJ on 27-01-2014 09:39:34
Running from C:\Documents and Settings\Juraj Banas\Desktop
Microsoft Windows XP Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
ATTENTION: If processes are not listed WMI should be repaired.
==================== Processes (Whitelisted) ===================
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDCPL] - C:\WINDOWS\RTHDCPL.EXE [16248320 2006-06-28] (Realtek Semiconductor Corp.)
HKLM\...\Run: [SkyTel] - C:\WINDOWS\SkyTel.EXE [2879488 2006-05-16] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] - C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AzMixerSel] - C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [53248 2005-12-21] (Realtek Semiconductor Corp.)
HKLM\...\Run: [LogitechCommunicationsManager] - C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe [304664 2006-10-31] (Acer Inc.)
HKLM\...\Run: [AcerOrbicamRibbon] - C:\Program Files\Acer\OrbiCam10\OrbiCam.exe [754712 2006-11-28] ()
HKLM\...\Run: [LVCOMSX] - C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe [244512 2006-11-28] (Logitech Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [761946 2006-03-03] (Synaptics, Inc.)
HKLM\...\Run: [NvCplDaemon] - C:\WINDOWS\system32\NvCpl.dll [13594624 2009-01-30] (NVIDIA Corporation)
HKLM\...\Run: [nwiz] - nwiz.exe /install
HKLM\...\Run: [NvMediaCenter] - C:\WINDOWS\system32\NvMcTray.dll [86016 2009-01-30] (NVIDIA Corporation)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [MSStp] - C:\WINDOWS\system32\msstp.vbe [1418 2014-01-13] ()
HKLM\...\Run: [mncvkfyfSrv] - C:\WINDOWS\inf\mncvkfyf.vbe [1338 2014-01-13] ()
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [2021400 2009-02-06] (ESET)
HKCU\...\Run: [tsiVideo] - C:\DOCUME~1\JURAJB~1\LOCALS~1\Temp\\mdi064.dll [3997696 2014-01-22] () <===== ATTENTION
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mail.ru/cnt/9134
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
SearchScopes: HKCU - DefaultScope {E88E0043-C9D4-4e33-8555-FEE4F5B63060} URL = http://go.mail.ru/search?q={searchTerms ... =1&fr=ietb
SearchScopes: HKCU - {E88E0043-C9D4-4e33-8555-FEE4F5B63060} URL = http://go.mail.ru/search?q={searchTerms ... =1&fr=ietb
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 172.16.40.1
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Juraj Banas\Application Data\Mozilla\Firefox\Profiles\297eyo2j.default
FF Homepage: hxxp://www.zoznam.sk/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.5.1 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\zoznam-sk.xml
FF Extension: Спутник @Mail.Ru - C:\Documents and Settings\Juraj Banas\Application Data\Mozilla\Firefox\Profiles\297eyo2j.default\Extensions\{37964A3C-4EE8-47b1-8321-34DE2C39BA4D} [2013-12-18]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: Eset Plugin - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-01-22]
========================== Services (Whitelisted) =================
S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [20680 2009-02-06] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [727720 2009-02-06] (ESET)
R2 JavaQuickStarterService; C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe [161664 2012-05-04] (Oracle Corporation)
S2 LVSrvLauncher; C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe [101152 2006-11-28] (Logitech Inc.)
S2 NOD32FiXTemDono; C:\WINDOWS\system32\regedt32.exe [3584 2006-02-28] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [328061 2006-01-17] (Broadcom Corporation.)
S3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [30459 2006-01-17] (Broadcom Corporation.)
R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [850474 2006-01-17] (Broadcom Corporation.)
R2 BTSERIAL; C:\WINDOWS\system32\drivers\btserial.sys [23271 2006-01-17] (Broadcom Corporation.)
S3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [148900 2006-01-17] (Broadcom Corporation.)
S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [65688 2006-01-17] (Broadcom Corporation.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R2 eamon; C:\WINDOWS\System32\DRIVERS\eamon.sys [113448 2009-02-06] (ESET)
R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [106208 2009-02-06] (ESET)
R3 EMSCR; C:\WINDOWS\System32\DRIVERS\EMS7SK.sys [61056 2006-06-16] (ENE Technology Inc.)
R2 epfw; C:\WINDOWS\System32\DRIVERS\epfw.sys [130952 2009-02-06] (ESET)
R3 Epfwndis; C:\WINDOWS\System32\DRIVERS\Epfwndis.sys [33096 2009-02-06] (ESET)
R1 epfwtdi; C:\WINDOWS\System32\DRIVERS\epfwtdi.sys [56280 2009-02-06] (ESET)
R3 ESDCR; C:\WINDOWS\System32\DRIVERS\ESD7SK.sys [40064 2006-06-16] (ENE Technology Inc.)
R3 ESMCR; C:\WINDOWS\System32\DRIVERS\ESM7SK.sys [74752 2006-06-16] (ENE Technology Inc.)
R3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [209664 2006-12-22] (Conexant Systems, Inc.)
R3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [988800 2006-12-22] (Conexant Systems, Inc.)
R3 lv321av; C:\WINDOWS\System32\DRIVERS\lv321av.sys [847392 2006-11-28] (Logitech Inc.)
R3 LVMVDrv; C:\WINDOWS\System32\DRIVERS\LVMVDrv.sys [1962784 2006-11-28] (Logitech Inc.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
R3 SMCIRDA; C:\WINDOWS\System32\DRIVERS\smcirda.sys [46080 2004-06-16] (SMSC)
R3 w39n51; C:\WINDOWS\System32\DRIVERS\w39n51.sys [1429632 2006-04-04] (Intel® Corporation)
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [x]
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-27 09:39 - 2014-01-27 09:39 - 00009445 _____ C:\Documents and Settings\Juraj Banas\Desktop\FRST.txt
2014-01-27 09:39 - 2014-01-27 09:39 - 00000000 ____D C:\FRST
2014-01-27 09:38 - 2014-01-27 09:38 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Juraj Banas\Desktop\FRSTLauncher.exe
2014-01-27 09:38 - 2014-01-27 09:38 - 00029696 _____ C:\Documents and Settings\Juraj Banas\Local Settings\Application Data\MSGBOX.EXE
2014-01-27 09:38 - 2014-01-27 09:38 - 00015327 _____ C:\Documents and Settings\Juraj Banas\Desktop\LM.bat
2014-01-27 09:37 - 2014-01-27 09:37 - 01223168 _____ (Farbar) C:\Documents and Settings\Juraj Banas\Desktop\FRST.exe
2014-01-27 09:34 - 2014-01-27 09:34 - 00002341 _____ C:\WINDOWS\setupapi.log
2014-01-27 09:34 - 2014-01-27 09:34 - 00000000 ____D C:\rsit
2014-01-22 14:05 - 2014-01-22 14:05 - 00000000 ____D C:\Program Files\ESET
2014-01-22 14:05 - 2014-01-22 14:05 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\ESET
2014-01-22 13:55 - 2014-01-13 10:25 - 00001418 ____S C:\WINDOWS\system32\msstp.vbe
2014-01-22 09:02 - 2008-03-03 18:21 - 00000568 ____H C:\WINDOWS\nod32fixtemdono.reg
2014-01-22 08:29 - 2014-01-22 08:29 - 00000000 __HDC C:\WINDOWS\$NtUninstallbasecsp$
2014-01-22 08:28 - 2011-08-16 11:45 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iecompat.dll
2014-01-22 08:28 - 2011-03-11 15:10 - 00225262 ____C C:\WINDOWS\system32\dllcache\msimain.sdb
2014-01-22 08:25 - 2014-01-22 08:25 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2014-01-20 18:43 - 2014-01-20 18:43 - 00000719 _____ C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
2014-01-11 10:20 - 2014-01-11 10:20 - 00069232 _____ C:\Documents and Settings\Juraj Banas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2014-01-07 18:47 - 2014-01-07 18:47 - 00000000 __SHD C:\Documents and Settings\LocalService\IETldCache
2014-01-07 18:45 - 2014-01-11 10:47 - 00000000 ____D C:\Documents and Settings\Juraj Banas\Application Data\Skype
2014-01-07 18:45 - 2014-01-07 18:45 - 00000000 ___RD C:\Program Files\Skype
2014-01-07 18:45 - 2014-01-07 18:45 - 00000000 ____D C:\Program Files\Common Files\Skype
2014-01-07 18:45 - 2014-01-07 18:45 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Skype
2014-01-07 18:44 - 2014-01-07 18:45 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Skype
2014-01-07 18:12 - 2014-01-07 18:12 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
2013-12-31 14:15 - 2013-12-31 14:15 - 00000000 ____D C:\Program Files\Mozilla Firefox
==================== One Month Modified Files and Folders =======
2014-01-27 09:39 - 2014-01-27 09:39 - 00009445 _____ C:\Documents and Settings\Juraj Banas\Desktop\FRST.txt
2014-01-27 09:39 - 2014-01-27 09:39 - 00000000 ____D C:\FRST
2014-01-27 09:39 - 2013-12-05 08:50 - 01799959 _____ C:\WINDOWS\WindowsUpdate.log
2014-01-27 09:38 - 2014-01-27 09:38 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Juraj Banas\Desktop\FRSTLauncher.exe
2014-01-27 09:38 - 2014-01-27 09:38 - 00029696 _____ C:\Documents and Settings\Juraj Banas\Local Settings\Application Data\MSGBOX.EXE
2014-01-27 09:38 - 2014-01-27 09:38 - 00015327 _____ C:\Documents and Settings\Juraj Banas\Desktop\LM.bat
2014-01-27 09:38 - 2013-12-05 11:12 - 00000000 ____D C:\Documents and Settings\Juraj Banas\My Documents\Preberanie
2014-01-27 09:37 - 2014-01-27 09:37 - 01223168 _____ (Farbar) C:\Documents and Settings\Juraj Banas\Desktop\FRST.exe
2014-01-27 09:34 - 2014-01-27 09:34 - 00002341 _____ C:\WINDOWS\setupapi.log
2014-01-27 09:34 - 2014-01-27 09:34 - 00000000 ____D C:\rsit
2014-01-27 09:28 - 2013-12-05 09:37 - 00000051 _____ C:\WINDOWS\wiaservc.log
2014-01-27 09:27 - 2013-12-05 13:19 - 00201679 _____ C:\WINDOWS\system32\nvapps.xml
2014-01-27 09:27 - 2013-12-05 09:37 - 00000159 _____ C:\WINDOWS\wiadebug.log
2014-01-27 09:27 - 2013-12-05 08:55 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2014-01-27 09:26 - 2013-12-09 08:43 - 00065536 _____ C:\WINDOWS\system32\config\Internet.evt
2014-01-27 09:26 - 2013-12-09 07:20 - 00065536 _____ C:\WINDOWS\system32\config\ODiag.evt
2014-01-27 09:26 - 2013-12-05 08:57 - 00000178 ___SH C:\Documents and Settings\Juraj Banas\ntuser.ini
2014-01-27 09:26 - 2013-12-05 08:55 - 00032578 _____ C:\WINDOWS\SchedLgU.Txt
2014-01-27 09:22 - 2013-12-05 08:57 - 00000000 ____D C:\Documents and Settings\Juraj Banas
2014-01-27 08:58 - 2013-12-09 10:44 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-01-27 08:38 - 2013-12-05 08:56 - 00000000 __SHD C:\WINDOWS\CSC
2014-01-27 08:38 - 2006-02-28 13:00 - 00002422 _____ C:\WINDOWS\system32\wpa.dbl
2014-01-22 14:05 - 2014-01-22 14:05 - 00000000 ____D C:\Program Files\ESET
2014-01-22 14:05 - 2014-01-22 14:05 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\ESET
2014-01-22 08:32 - 2013-12-09 20:33 - 00000000 ____D C:\WINDOWS\pss
2014-01-22 08:30 - 2013-12-05 08:51 - 00000000 ___HD C:\WINDOWS\$hf_mig$
2014-01-22 08:29 - 2014-01-22 08:29 - 00000000 __HDC C:\WINDOWS\$NtUninstallbasecsp$
2014-01-22 08:29 - 2013-12-05 11:09 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ESET
2014-01-22 08:29 - 2013-12-05 09:23 - 00000000 ____D C:\WINDOWS\security
2014-01-22 08:25 - 2014-01-22 08:25 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2014-01-20 18:45 - 2013-12-09 12:43 - 00000000 ____D C:\Documents and Settings\Juraj Banas\Application Data\vlc
2014-01-20 18:43 - 2014-01-20 18:43 - 00000719 _____ C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
2014-01-20 18:39 - 2013-12-19 19:14 - 00006144 _____ C:\Documents and Settings\Juraj Banas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-18 11:57 - 2013-12-05 09:23 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2014-01-16 15:40 - 2013-12-18 18:16 - 00000000 ____D C:\WINDOWS\system32\MRT
2014-01-16 15:38 - 2013-12-18 18:15 - 83425928 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-01-15 13:59 - 2013-12-09 12:27 - 00002347 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk
2014-01-13 10:25 - 2014-01-22 13:55 - 00001418 ____S C:\WINDOWS\system32\msstp.vbe
2014-01-11 10:47 - 2014-01-07 18:45 - 00000000 ____D C:\Documents and Settings\Juraj Banas\Application Data\Skype
2014-01-11 10:20 - 2014-01-11 10:20 - 00069232 _____ C:\Documents and Settings\Juraj Banas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2014-01-11 09:52 - 2013-12-05 10:59 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2014-01-07 18:47 - 2014-01-07 18:47 - 00000000 __SHD C:\Documents and Settings\LocalService\IETldCache
2014-01-07 18:47 - 2013-12-05 10:11 - 00003419 _____ C:\WINDOWS\system32\lvcoinst.log
2014-01-07 18:47 - 2013-12-05 08:55 - 00000000 __SHD C:\Documents and Settings\LocalService
2014-01-07 18:45 - 2014-01-07 18:45 - 00000000 ___RD C:\Program Files\Skype
2014-01-07 18:45 - 2014-01-07 18:45 - 00000000 ____D C:\Program Files\Common Files\Skype
2014-01-07 18:45 - 2014-01-07 18:45 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Skype
2014-01-07 18:45 - 2014-01-07 18:44 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Skype
2014-01-07 18:12 - 2014-01-07 18:12 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
2014-01-07 18:12 - 2013-12-09 12:44 - 00000000 ____D C:\Program Files\CCleaner
2013-12-31 14:15 - 2013-12-31 14:15 - 00000000 ____D C:\Program Files\Mozilla Firefox
Files to move or delete:
====================
C:\DOCUME~1\JURAJB~1\LOCALS~1\Temp\\mdi064.dll
Some content of TEMP:
====================
C:\Documents and Settings\deti\Local Settings\Temp\RtkBtMnt.exe
C:\Documents and Settings\Juraj Banas\Local Settings\Temp\fp_pl_pfs_installer.exe
C:\Documents and Settings\Juraj Banas\Local Settings\Temp\GuardMailRu.exe
C:\Documents and Settings\Juraj Banas\Local Settings\Temp\mdi064.dll
C:\Documents and Settings\Juraj Banas\Local Settings\Temp\RtkBtMnt.exe
C:\Documents and Settings\Juraj Banas\Local Settings\Temp\vlc-2.1.2-win32.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================