1. Please, disable System Restore and antivirus (if you have).
2. Execute this script in AVPTool:
Код:
begin
SetAVZGuardStatus(True);
QuarantineFile('C:\ba.exe','');
QuarantineFile('C:\WINDOWS\system32\explorer\explorer.exe','');
QuarantineFile('C:\DOCUME~1\Shifo\LOCALS~1\Temp\herss.exe','');
QuarantineFile('C:\DOCUME~1\Shifo\LOCALS~1\Temp\cvasds0.dll','');
DeleteFile('C:\DOCUME~1\Shifo\LOCALS~1\Temp\cvasds0.dll');
DeleteFile('C:\DOCUME~1\Shifo\LOCALS~1\Temp\herss.exe');
RegKeyParamDel('HKEY_USERS','S-1-5-21-1708537768-1417001333-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run','cdoosoft');
DeleteFile('C:\WINDOWS\system32\explorer\explorer.exe');
RegKeyParamDel('HKEY_USERS','S-1-5-21-1708537768-1417001333-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','smss');
DeleteFile('C:\autorun.inf');
DeleteFile('C:\ba.exe');
DeleteFile('D:\autorun.inf');
DeleteFile('D:\ba.exe');
DeleteFile('E:\autorun.inf');
DeleteFile('E:\ba.exe');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
3. After reboot execute this script in AVPTool:
Код:
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
Upload file quarantine.zip, by link http://virusinfo.info/upload_virus.php?tid=75841
4. Make a new log of AVPTool.