Close/unload all the programs excepted AVZ and Internet Explorer
Switch off:
- Antivirus and and, if you have - Firewall.
- System Restore
Fix with Hijackthis
Код:
O1 - Hosts: 194.165.4.145 eggbank.com
- Execute following script
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\internat.exe','');
QuarantineFile('C:\WINDOWS\system32\pavuppad.exe','');
DeleteFile('C:\WINDOWS\system32\pavuppad.exe');
DeleteFile('C:\WINDOWS\internat.exe');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
After reboot:
- Clean Temp-Maps, Cache of Browsers, Recycler. Use Windows service tool cleanmgr or CCleaner or ClearProg
- Close all the programs and start only Internet Explorer!!!
- Repeat 3 log files.
- Switch Antivirus and, if you have - Firewall, on.
- Go On-Line
- Upload the quarantine (s. appendix 2 and 3 of the Rules) here: http://virusinfo.info/upload_virus_eng.php?tid=46508
- Attach 3 logs to your new post..