Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-10-2013 Ran by Smok at 2013-10-30 21:26:51 Run:2 Running from C:\Users\Smok\Desktop\wirus\30.10.2013 Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\...\Run: [] - [x] HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] ATTENTION! ====> ZeroAccess? HKLM-x32\...\Run: [] - [x] SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Toolbar: HKCU - No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File Handler: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - No File ZeroAccess: C:\$Recycle.Bin\S-1-5-21-1177522938-3192551413-1856643698-1000\$8223fa178a103d7c5e0f7d0d7b538a54 ZeroAccess: C:\$Recycle.Bin\S-1-5-18\$8223fa178a103d7c5e0f7d0d7b538a54 C:\Users\Smok\AppData\Local\Temp\ntdll_dump.dll BHO-x32: G Data BankGuard - {BA3295CF-17ED-4F49-9E95-D999A0ADBFDC} - C:\Program Files (x86)\Common Files\G DATA\AVKProxy\BanksafeBHO.dll No File S3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [60320 2013-04-13] (G Data Software AG) 2013-10-01 01:14 - 2012-07-19 21:44 - 00000000 ____D C:\ProgramData\G DATA ***************** HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\Default => Value was restored successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} => Value deleted successfully. HKCR\CLSID\{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} => Key not found. HKCR\PROTOCOLS\Handler\vnd.ms.radio => Key deleted successfully. HKCR\CLSID\{3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} => Key not found. C:\$Recycle.Bin\S-1-5-21-1177522938-3192551413-1856643698-1000\$8223fa178a103d7c5e0f7d0d7b538a54 => Moved successfully. C:\$Recycle.Bin\S-1-5-18\$8223fa178a103d7c5e0f7d0d7b538a54 => Moved successfully. C:\Users\Smok\AppData\Local\Temp\ntdll_dump.dll => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA3295CF-17ED-4F49-9E95-D999A0ADBFDC} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{BA3295CF-17ED-4F49-9E95-D999A0ADBFDC} => Key deleted successfully. GDPkIcpt => Service deleted successfully. C:\ProgramData\G DATA => Moved successfully. ==== End of Fixlog ====