Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-10-2013 Ran by Sylwia at 2013-10-29 17:37:09 Run:1 Running from C:\Users\Sylwia\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: C:\Windows\Tasks\dscpfbto.job => C:\Windows\SysWOW64\chsbrkrs.dll C:\Windows\SysWOW64\chsbrkrs.dll Task: {FFD54655-FDC9-4571-9AF9-A667AFC8AF42} - System32\Tasks\dscpfbto => C:\Windows\SysWOW64\chsbrkrs.dll Task: {7038F98D-FE65-4CC8-B815-1A22F16B377B} - System32\Tasks\BonanzaDealsUpdate => C:\Program Task: {10C583E1-1DA5-43CF-A5BE-392391BA44E5} - System32\Tasks\EPUpdater => C:\Users\Sylwia\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe C:\Users\Sylwia\AppData\Roaming\BABSOL~1 C:\Windows\System32\Tasks\EPUpdater C:\Users\Administrator\AppData\Local\Temp\AskSLib.dll C:\Users\Administrator\AppData\Local\Temp\DAPREMOVE.EXE C:\Users\Administrator\AppData\Local\Temp\NEventMessages.dll C:\Users\Sylwia\AppData\Local\Temp\APNStub.exe C:\Users\Sylwia\AppData\Local\Temp\avgnt.exe C:\Users\Sylwia\AppData\Local\Temp\cabex.dll C:\Users\Sylwia\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe C:\Users\Sylwia\AppData\Local\Temp\gg10.upgr.exe C:\Users\Sylwia\AppData\Local\Temp\gg10_upgr_to_11790_from_11119.exe C:\Users\Sylwia\AppData\Local\Temp\gg10_upgr_to_11999_from_11790.exe C:\Users\Sylwia\AppData\Local\Temp\jre-6u22-windows-i586-iftw-rv.exe C:\Users\Sylwia\AppData\Local\Temp\jre-6u23-windows-i586-iftw-rv.exe C:\Users\Sylwia\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe C:\Users\Sylwia\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe C:\Users\Sylwia\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe C:\Users\Sylwia\AppData\Local\Temp\jre-6u34-windows-i586-iftw.exe C:\Users\Sylwia\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe C:\Users\Sylwia\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe C:\Users\Sylwia\AppData\Local\Temp\jre-6u39-windows-i586-iftw.exe C:\Users\Sylwia\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe C:\Users\Sylwia\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe C:\Users\Sylwia\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Sylwia\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Sylwia\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Sylwia\AppData\Local\Temp\MSNDCCA.exe C:\Users\Sylwia\AppData\Local\Temp\NEventMessages.dll C:\Users\Sylwia\AppData\Local\Temp\Nokia_Ovi_Suite_PCS_Update.exe C:\Users\Sylwia\AppData\Local\Temp\Nokia_PC_Suite_pol.exe C:\Users\Sylwia\AppData\Local\Temp\NOSEventMessages.dll C:\Users\Sylwia\AppData\Local\Temp\nsisdt.dll C:\Users\Sylwia\AppData\Local\Temp\RunWizards.exe C:\Users\Sylwia\AppData\Local\Temp\SkypeSetup.exe C:\Users\Sylwia\AppData\Local\Temp\svd_dap.exe C:\Users\Sylwia\AppData\Local\Temp\tempmessage.bfg C:\ProgramData\Babylon C:\Windows\System32\Tasks\BonanzaDealsUpdate FF SearchPlugin: C:\Users\Sylwia\AppData\Roaming\Mozilla\Firefox\Profiles\zw7qjb5t.default\searchplugins\dokotoolbar.xml FF SearchPlugin: C:\Users\Sylwia\AppData\Roaming\Mozilla\Firefox\Profiles\zw7qjb5t.default\searchplugins\web-search.xml FF Extension: dokotoolbar.com - C:\Users\Sylwia\AppData\Roaming\Mozilla\Firefox\Profiles\zw7qjb5t.default\Extensions\ffxtlbr@dokotoolbar.com FF NewTab: hxxp://www.doko-search.com/?babsrc=NT_ss&mntrId=F2BF003091400604&affID=125836&tsp=5040 Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files (x86)\DAP\DAPIELoader64.dll No File ***************** C:\Windows\Tasks\dscpfbto.job => Moved successfully. Could not move "C:\Windows\SysWOW64\chsbrkrs.dll" => Scheduled to move on reboot. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{FFD54655-FDC9-4571-9AF9-A667AFC8AF42} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FFD54655-FDC9-4571-9AF9-A667AFC8AF42} => Key deleted successfully. C:\Windows\System32\Tasks\dscpfbto => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\dscpfbto => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7038F98D-FE65-4CC8-B815-1A22F16B377B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7038F98D-FE65-4CC8-B815-1A22F16B377B} => Key deleted successfully. C:\Windows\System32\Tasks\BonanzaDealsUpdate not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{10C583E1-1DA5-43CF-A5BE-392391BA44E5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{10C583E1-1DA5-43CF-A5BE-392391BA44E5} => Key deleted successfully. C:\Windows\System32\Tasks\EPUpdater not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater => Key deleted successfully. "C:\Users\Sylwia\AppData\Roaming\BABSOL~1" => File/Directory not found. "C:\Windows\System32\Tasks\EPUpdater" => File/Directory not found. C:\Users\Administrator\AppData\Local\Temp\AskSLib.dll => Moved successfully. C:\Users\Administrator\AppData\Local\Temp\DAPREMOVE.EXE => Moved successfully. C:\Users\Administrator\AppData\Local\Temp\NEventMessages.dll => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\APNStub.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\avgnt.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\cabex.dll => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\gg10.upgr.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\gg10_upgr_to_11790_from_11119.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\gg10_upgr_to_11999_from_11790.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\jre-6u22-windows-i586-iftw-rv.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\jre-6u23-windows-i586-iftw-rv.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\jre-6u34-windows-i586-iftw.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\jre-6u37-windows-i586-iftw.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\jre-6u39-windows-i586-iftw.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\MSNDCCA.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\NEventMessages.dll => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\Nokia_Ovi_Suite_PCS_Update.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\Nokia_PC_Suite_pol.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\NOSEventMessages.dll => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\nsisdt.dll => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\RunWizards.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\SkypeSetup.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\svd_dap.exe => Moved successfully. C:\Users\Sylwia\AppData\Local\Temp\tempmessage.bfg => Moved successfully. "C:\ProgramData\Babylon" => File/Directory not found. "C:\Windows\System32\Tasks\BonanzaDealsUpdate" => File/Directory not found. "C:\Users\Sylwia\AppData\Roaming\Mozilla\Firefox\Profiles\zw7qjb5t.default\searchplugins\dokotoolbar.xml" => not found. "C:\Users\Sylwia\AppData\Roaming\Mozilla\Firefox\Profiles\zw7qjb5t.default\searchplugins\web-search.xml" => not found. C:\Users\Sylwia\AppData\Roaming\Mozilla\Firefox\Profiles\zw7qjb5t.default\Extensions\ffxtlbr@dokotoolbar.com not found. Firefox newtab deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value not found. HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000} => Key deleted successfully. HKCR\CLSID\{FF6C3CF0-4B15-11D1-ABED-709549C10000} => Key deleted successfully. =========== Result of Scheduled Files to move =========== C:\Windows\SysWOW64\chsbrkrs.dll => Moved successfully. ==== End of Fixlog ====