Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-08-2013 Ran by SYSTEM at 2012-06-29 16:53:39 Run:1 Running from G:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** HKLM\...\Winlogon: [Shell] [x ] () <=== ATTENTION HKLM-x32\...\Run: [SweetIM] - C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe [115032 2012-05-29] (SweetIM Technologies Ltd.) HKLM-x32\...\Run: [Sweetpacks Communicator] - C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.) HKLM-x32\...\Run: [ApnUpdater] - C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1391272 2012-01-03] (Ask) HKLM-x32\...\Run: [] - [x] AppInit_DLLs: c:\progra~3\browse~1\23787~1.43\{16cdf~1\browse~1.dll [162336 2009-07-21] () AppInit_DLLs-x32: c:\progra~3\browse~1\261519~1.190\{16cdf~1\browse~1.dll [2691536 2013-07-26] () Startup: C:\Users\Artur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk S2 Browser Manager; C:\ProgramData\Browser Manager\2.6.1519.190\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe [2847696 2013-07-26] () S1 vBszKyhV2; C:\Windows\system32\drivers\vBszKyhV2.sys [46528 2013-08-10] () C:\Windows\System32\Drivers\vBszKyhV2.sys C:\Windows\System32\vBszKyhV.bmp C:\Windows\System32\vBszKyhV2.exe C:\Windows\System32\vBszKyhV1.exe C:\Windows\System32\vBszKyhV.dll C:\Windows\SysWOW64\searchplugins C:\Windows\SysWOW64\Extensions C:\Users\Artur\AppData\Roaming\Cyral C:\Users\Artur\AppData\Roaming\Fedeif C:\Users\Artur\AppData\Roaming\Geseov C:\Users\Artur\AppData\Roaming\Gifuo C:\Users\Artur\AppData\Local\Temp C:\Users\Artur\Downloads\solidcam_2012_keygen_downloader_pl_99412.exe C:\Users\Artur\Desktop\Continue installation - Promt Downloader Installation.lnk C:\ProgramData\dsgsdgdsgdsgw.pad testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION! ***************** HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value was restored successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SweetIM => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Sweetpacks Communicator => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully. C:\Users\Artur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk => Moved successfully. Browser Manager => Service deleted successfully. vBszKyhV2 => Service deleted successfully. C:\Windows\System32\Drivers\vBszKyhV2.sys => Moved successfully. C:\Windows\System32\vBszKyhV.bmp => Moved successfully. C:\Windows\System32\vBszKyhV2.exe => Moved successfully. C:\Windows\System32\vBszKyhV1.exe => Moved successfully. C:\Windows\System32\vBszKyhV.dll => Moved successfully. C:\Windows\SysWOW64\searchplugins => Moved successfully. C:\Windows\SysWOW64\Extensions => Moved successfully. C:\Users\Artur\AppData\Roaming\Cyral => Moved successfully. C:\Users\Artur\AppData\Roaming\Fedeif => Moved successfully. C:\Users\Artur\AppData\Roaming\Geseov => Moved successfully. C:\Users\Artur\AppData\Roaming\Gifuo => Moved successfully. C:\Users\Artur\AppData\Local\Temp => Moved successfully. C:\Users\Artur\Downloads\solidcam_2012_keygen_downloader_pl_99412.exe => Moved successfully. C:\Users\Artur\Desktop\Continue installation - Promt Downloader Installation.lnk => Moved successfully. C:\ProgramData\dsgsdgdsgdsgw.pad => Moved successfully. The operation completed successfully. ==== End of Fixlog ====