Close all programs.
Run AVZ.
Choose from the menu "File" => "Custom scripts", copy/paste code below and run it:
Код:
begin
SetAVZGuardStatus(True);
RegKeyIntParamWrite('HKLM','SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer','NoDriveTypeAutoRun', 221);
QuarantineFile('C:\WINDOWS\system32\olhrwef.exe','');
QuarantineFile('C:\fsaht.cmd','');
QuarantineFile('C:\autorun.inf','');
QuarantineFile('C:\WINDOWS\system32\nmdfgds1.dll','');
DeleteFile('C:\autorun.inf');
DeleteFile('C:\fsaht.cmd');
DeleteFile('D:\autorun.inf');
DeleteFile('D:\fsaht.cmd');
DeleteFile('F:\autorun.inf');
DeleteFile('F:\fsaht.cmd');
DeleteFile('C:\WINDOWS\system32\nmdfgds1.dll');
DeleteFile('C:\WINDOWS\system32\olhrwef.exe');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
The computer will reboot.
Upload quarantine (see Appendix 3 in the rules), by the link Upload quarantined files in top of this thread.
Create new logs and attach to the thread.