Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 20-02-2014 Ran by Piotr at 2014-02-23 01:48:52 Run:1 Running from C:\Users\Piotr\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Users\Piotr\AppData\Local\winlogon.exe (Torpedo) C:\Users\Piotr\AppData\Local\Torpedo\Torpedo.exe () C:\Users\Piotr\AppData\Local\services.exe () C:\Users\Piotr\AppData\Local\lsass.exe HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe HKU\S-1-5-21-2117095606-2655364468-1544713982-1000\...\Run: [Tok-Cirrhatus] - C:\Users\Piotr\AppData\Local\smss.exe [114176 2011-05-04] () HKU\S-1-5-21-2117095606-2655364468-1544713982-1000\...\MountPoints2: {0d7e2478-93d3-11e3-a6f7-001e33ae7174} - G:\AutoRun.exe HKU\S-1-5-21-2117095606-2655364468-1544713982-1000\...\MountPoints2: {0d7e2485-93d3-11e3-a6f7-001e33ae7174} - G:\AutoRun.exe HKU\S-1-5-21-2117095606-2655364468-1544713982-1000\...\MountPoints2: {0d7e24b4-93d3-11e3-a6f7-001e33ae7174} - G:\AutoRun.exe HKU\S-1-5-21-2117095606-2655364468-1544713982-1000\...\MountPoints2: {903d4d2d-1dcc-11e2-8e84-001e33ae7174} - H:\NokiaPCIA_Autorun.exe Startup: C:\Users\Piotr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif () Startup: C:\Users\Piotr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Torpedo.lnk ShortcutTarget: Torpedo.lnk -> C:\Users\Piotr\AppData\Local\Torpedo\Torpedo.exe (Torpedo) 2014-02-22 22:30 - 2014-02-22 22:30 - 00012393 _____ () C:\Users\Piotr\AppData\Local\Bron.tok.A12.em.bin 2014-02-22 00:00 - 2014-02-22 00:00 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok* 2014-02-22 00:00 - 2014-02-22 00:00 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-22 2014-02-21 00:16 - 2014-02-21 00:16 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-21 2014-02-20 00:00 - 2014-02-20 00:00 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-20 2014-02-19 00:00 - 2014-02-19 00:00 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-19 2014-02-18 00:00 - 2014-02-18 00:00 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-18 2014-02-17 00:00 - 2014-02-17 00:00 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-17 2014-02-16 04:17 - 2014-02-16 04:17 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-16 2014-02-15 13:17 - 2014-02-15 13:17 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-15 2014-02-14 15:39 - 2014-02-14 15:39 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-14 2014-02-13 00:00 - 2014-02-13 00:00 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-13 2014-02-12 01:00 - 2014-02-12 01:00 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-12 2014-02-11 00:00 - 2014-02-11 00:00 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-11 2014-02-10 09:09 - 2014-02-10 09:09 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-10 2014-02-09 00:00 - 2014-02-09 00:00 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-9 2014-02-08 00:00 - 2014-02-08 00:00 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-8 2014-02-07 00:00 - 2014-02-07 00:00 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-7 2014-02-06 00:00 - 2014-02-06 00:00 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-6 2014-02-05 00:00 - 2014-02-05 00:00 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-5 2014-02-04 00:00 - 2014-02-04 00:00 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-4 2014-02-03 05:44 - 2014-02-03 05:44 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-3 2014-02-02 01:10 - 2014-02-02 01:10 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-2 2014-02-01 00:03 - 2014-02-01 00:03 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Bron.tok-12-1 2014-02-01 00:09 - 2014-02-01 00:23 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Loc.Mail.Bron.Tok 2014-02-01 00:09 - 2014-02-01 00:09 - 00000051 _____ () C:\Users\Piotr\AppData\Local\Kosong.Bron.Tok.txt 2014-02-01 00:09 - 2014-02-01 00:09 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Ok-SendMail-Bron-tok 2014-02-22 22:30 - 2014-02-22 22:30 - 00012393 _____ () C:\Users\Piotr\AppData\Local\Bron.tok.A12.em.bin 2014-02-22 22:19 - 2013-12-18 23:48 - 00000000 ____D () C:\Users\Piotr\AppData\Roaming\newnext.me 2014-01-24 12:45 - 2014-01-20 22:58 - 00000000 ____D () C:\Users\Piotr\AppData\Local\Torpedo ***************** [2688] C:\Users\Piotr\AppData\Local\winlogon.exe => Process closed successfully. [3104] C:\Users\Piotr\AppData\Local\Torpedo\Torpedo.exe => Process closed successfully. [2932] C:\Users\Piotr\AppData\Local\services.exe => Process closed successfully. [3028] C:\Users\Piotr\AppData\Local\lsass.exe => Process closed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKU\S-1-5-21-2117095606-2655364468-1544713982-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Tok-Cirrhatus => Value deleted successfully. HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0d7e2478-93d3-11e3-a6f7-001e33ae7174} => Key not found. HKCR\CLSID\{0d7e2478-93d3-11e3-a6f7-001e33ae7174} => Key not found. HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0d7e2485-93d3-11e3-a6f7-001e33ae7174} => Key not found. HKCR\CLSID\{0d7e2485-93d3-11e3-a6f7-001e33ae7174} => Key not found. HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0d7e24b4-93d3-11e3-a6f7-001e33ae7174} => Key not found. HKCR\CLSID\{0d7e24b4-93d3-11e3-a6f7-001e33ae7174} => Key not found. HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{903d4d2d-1dcc-11e2-8e84-001e33ae7174} => Key not found. HKCR\CLSID\{903d4d2d-1dcc-11e2-8e84-001e33ae7174} => Key not found. C:\Users\Piotr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif => Moved successfully. C:\Users\Piotr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Torpedo.lnk => Moved successfully. C:\Users\Piotr\AppData\Local\Torpedo\Torpedo.exe => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok.A12.em.bin => Moved successfully. "C:\Users\Piotr\AppData\Local\Bron.tok*" directory move: Could not move "C:\Users\Piotr\AppData\Local\Bron.tok*" directory. => Scheduled to move on reboot. C:\Users\Piotr\AppData\Local\Bron.tok-12-22 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-21 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-20 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-19 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-18 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-17 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-16 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-15 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-14 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-13 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-12 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-11 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-10 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-9 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-8 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-7 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-6 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-5 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-4 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-3 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-2 => Moved successfully. C:\Users\Piotr\AppData\Local\Bron.tok-12-1 => Moved successfully. C:\Users\Piotr\AppData\Local\Loc.Mail.Bron.Tok => Moved successfully. C:\Users\Piotr\AppData\Local\Kosong.Bron.Tok.txt => Moved successfully. C:\Users\Piotr\AppData\Local\Ok-SendMail-Bron-tok => Moved successfully. "C:\Users\Piotr\AppData\Local\Bron.tok.A12.em.bin" => File/Directory not found. C:\Users\Piotr\AppData\Roaming\newnext.me => Moved successfully. C:\Users\Piotr\AppData\Local\Torpedo => Moved successfully. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-02-23 01:49:55)<= C:\Users\Piotr\AppData\Local\Bron.tok* => Is moved successfully. ==== End of Fixlog ====