Please download IceSword from here:
http://mail.ustc.edu.cn/~jfpan/downl...Sword122en.zip
Run it. Go to the menu "File".
Check if there are the following files on your PC:
windows\system32\drivers\srosa.sys
windows\system32\drivers\hldrrr.exe
windows\system32\wintems.exe
windows\system32\mdelk.exe
If you find any of them, right click on the file and choose "force delete". Click on "yes" when it asks an confirmation. Then reboot your PC, if you found and deleted any of these files.
Run the AVPTool.
Go to the "Manual Cure" window.
Copy and paste the following script (how to do this: read here http://avptool.virusinfo.info/en/AVP...curescript.htm) Execute it.
Код:
begin
QuarantineFile('NTPrime.sys','');
QuarantineFile('c:\windows\system32\Drivers\NTPrime.SYS','');
QuarantineFile('c:\windows\System32\Drivers\ad1m60o1.SYS','');
QuarantineFile('D:\Programy\Odkurzacz\odk_mcd.exe','');
BC_ImportQuarantineList;
BC_Activate;
RebootWindows(true);
end.
Your computer will reboot.
Upload the quarantined files according to the Appendix 3 of the rules. (upload here: http://virusinfo.info/upload_virus_eng.php?tid=20637 )
Do you know this? :
C:\Program Files\OSD\