Switch off/Disable:
- Antivirus and and, if you have - Firewall.
- Execute following script in Manual disinfection
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ClearQuarantine;
DelBHO('{E7F15AC4-E0A9-43F0-921B-70DFEA621220}');
QuarantineFile('C:\WINDOWS\system32\796525\796525.dll','');
DelBHO('{65768B48-B004-4B26-9BAC-A3BAC39643D1}');
DelBHO('{5E5EFA8F-9F53-418E-B78E-44866667A404}');
QuarantineFile('C:\WINDOWS\system32\199638\199638.dll','');
QuarantineFile('C:\WINDOWS\system32\218538\218538.dll','');
DelBHO('{ABD45510-9B22-41cd-9ACD-8182A2DA7C63}');
DelBHO('{ABD42510-9B22-41cd-9DCD-8182A2D07C63}');
QuarantineFile('C:\WINDOWS\system32\iehelper.dll','');
QuarantineFile('C:\WINDOWS\system32\ntos.exe','');
QuarantineFile('C:\WINDOWS\system32\sdra64.exe','');
QuarantineFile('C:\Documents and Settings\Default User\Application Data\ntos.exe','');
QuarantineFile('C:\Documents and Settings\Administrator\Application Data\sdra64.exe','');
DeleteFile('C:\Documents and Settings\Administrator\Application Data\sdra64.exe');
DeleteFile('C:\Documents and Settings\Default User\Application Data\ntos.exe');
DeleteFile('C:\WINDOWS\system32\sdra64.exe');
DeleteFile('C:\WINDOWS\system32\ntos.exe');
DeleteFile('C:\WINDOWS\system32\iehelper.dll');
DeleteFile('C:\WINDOWS\system32\218538\218538.dll');
DeleteFile('C:\WINDOWS\system32\199638\199638.dll');
DeleteFile('C:\WINDOWS\system32\796525\796525.dll');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
SetAVZPMStatus(True);
RebootWindows(true);
end.
After reboot execute following script in Manual disinfection
Код:
begin
CreateQurantineArchive('C:\quarantine.zip');
end.
and upload the C:\quarantine.zip over the link Upload quarantined files on the top of this page.
- Remove Bonjour if you don't use it.
- Repeat a log file of AVPTool.
- Make a log file with Hijackthis ( Analysis, p.3 for further informations).
- Attach both logs to your new post..