Close/unload all the programs excepted AVZ and Internet Explorer
Switch off:
- Antivirus and and, if you have - Firewall.
- System Restore
- Execute following script in Manual Healing
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\system32\winsp\spoolsv.exe','');
QuarantineFile('C:\Drivers\rundll.exe','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\acontrol.sys','');
QuarantineFile('C:\Drivers\svchost.exe','');
StopService('AutoTransfer');
DeleteService('AutoTransfer');
DeleteService('NTService');
StopService('NTService');
StopService('netstart');
DeleteService('netstart');
StopService('AccessPro');
DeleteService('AccessPro');
QuarantineFile('c:\Windows\Drives\NTService.exe','');
QuarantineFile('c:\recycler\svchost.exe','');
TerminateProcessByName('c:\recycler\svchost.exe');
TerminateProcessByName('c:\windows\system32\macrocomptsd\spoolsv.exe');
QuarantineFile('c:\windows\system32\macrocomptsd\spoolsv.exe','');
DeleteFile('c:\windows\system32\macrocomptsd\spoolsv.exe');
DeleteFile('c:\recycler\svchost.exe');
DeleteFile('c:\Windows\Drives\NTService.exe');
DeleteFile('C:\Drivers\svchost.exe');
DeleteFile('C:\Drivers\rundll.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','SvService');
DeleteFile('C:\WINDOWS\system32\winsp\spoolsv.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Eventlog\Application\FIREWALLPRO','EventMessageFile');
BC_DeleteSvc('NTService');
BC_DeleteSvc('netstart');
BC_DeleteSvc('AutoTransfer');
BC_DeleteSvc('AccessPro');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
After reboot:
- Execute following script in Manual Healing
Код:
begin
CreateQurantineArchive('C:\quarantine.zip');
end.
- Upload the C:\quarantine.zip here: http://virusinfo.info/upload_virus_eng.php?tid=82200
- Repeat a log file.
- Attach a new log to your new post..