Close/unload all the programs excepted AVZ and Internet Explorer
Switch off:
- Antivirus and and, if you have - Firewall.
- System Restore
- Execute following script in Manual Healing
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('e:\windows\system32\scvhost.exe');
QuarantineFile('E:\WINDOWS\system32\scvhost.exe','');
QuarantineFile('E:\WINDOWS\scvhost.exe','');
QuarantineFile('Explorer.exe scvhost.exe','');
QuarantineFile('e:\windows\system32\scvhost.exe','');
DeleteFile('e:\windows\system32\scvhost.exe');
DeleteFile('Explorer.exe scvhost.exe');
DeleteFile('E:\WINDOWS\scvhost.exe');
DeleteFile('E:\WINDOWS\system32\scvhost.exe');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
After reboot:
- Execute following script in Manual Healing
Код:
begin
CreateQurantineArchive('C:\quarantine.zip');
end.
- Upload the C:\quarantine.zip here: http://virusinfo.info/upload_virus_eng.php?tid=74123
- Repeat AVPTool log file.
- Make a log of Hijackthis
- Attach both logs to your new post..