If you didnt turn off the system restore, then do it (how - see the rules)
Please download pingpong.pif - it is a renamed version of AVZ http://rapidshare.com/files/116949749/pingpong.pif.html
Then AVZ - File - Custom scripts
Execute the following script (copy it, paste it in the script window of AVZ and execute):
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('NdisFileServices32.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\ionnnn.sys','');
QuarantineFile('C:\WINDOWS\system32\wmdrtc32.dll','');
QuarantineFile('C:\DOCUME~1\Mahmoud\LOCALS~1\Temp\winpidn.exe','');
QuarantineFile('c:\windows\system32\23dc6b.exe','');
DeleteFile('c:\windows\system32\23dc6b.exe');
DeleteFile('C:\DOCUME~1\Mahmoud\LOCALS~1\Temp\winpidn.exe');
DeleteFile('C:\WINDOWS\system32\wmdrtc32.dll');
DeleteFile('C:\WINDOWS\system32\drivers\ionnnn.sys');
BC_ImportALL;
ExecuteSysClean;
BC_DeleteSvc('NdisFileServices32');
BC_Activate;
RebootWindows(true);
end.
Your computer will reboot.
Upload the quarantined files according to the Appendix 3 of the rules. (upload here http://virusinfo.info/upload_virus_eng.php?tid=26397 )
Then you have to do following:
1) On a clean PC download CureIt! ftp://ftp.drweb.com/pub/drweb/cureit/setup.exe
2) Unpack it and write it to a CD or DVD
3) Do a whole PC check in the Safe Mode with CureIt! (on CD or DVD) on the infected PC. Then in the normal mode.
Then make 3 logs according to the rules.