Close/unload all the programs excepted AVZ and Internet Explorer
Switch off:
- Antivirus and and, if you have - Firewall.
- System Restore
- Execute following script in Manual Healing
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\documents and settings\user\application data\windowsupdateb1a2.exe');
TerminateProcessByName('c:\documents and settings\user\application data\nvdisp.exe');
TerminateProcessByName('c:\documents and settings\user\application data\dx10bac\d-xdiag10bc.exe');
TerminateProcessByName('c:\documents and settings\user\application data\dx10bac\d-werwerwrw.exe');
RegKeyParamDel('HKEY_USERS','S-1-5-21-823518204-1390067357-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run','windowsclient7');
RegKeyParamDel('HKEY_USERS','S-1-5-21-823518204-1390067357-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run','NVIDIA');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','Windows Firewall');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','Microsoft SecureAssist');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','Windows Firewall');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','Microsoft SecureAssist');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','windowsclient7');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','NVIDIA');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','d-x10bc');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','d-werwe');
QuarantineFile('C:\WINDOWS\system32\system32\svchost.exe','');
QuarantineFile('C:\WINDOWS\system32\install\server.exe','');
QuarantineFile('C:\WINDOWS\install\Svchost.exe','');
QuarantineFile('C:\Documents and Settings\user\Application Data\winlogon.exe','');
QuarantineFile('C:\Documents and Settings\user\Application Data\windowsupdateb1a2.exe','');
QuarantineFile('c:\documents and settings\user\application data\windowsupdateb1a2.exe','');
QuarantineFile('C:\Documents and Settings\user\Application Data\System.Data.SQLite.dll','');
QuarantineFile('C:\Documents and Settings\user\Application Data\nvdisp.exe','');
QuarantineFile('c:\documents and settings\user\application data\nvdisp.exe','');
QuarantineFile('C:\Documents and Settings\user\Application Data\galaxy.exe','');
QuarantineFile('c:\documents and settings\user\application data\dx10bac\d-xdiag10bc.exe','');
QuarantineFile('c:\documents and settings\user\application data\dx10bac\d-werwerwrw.exe','');
DeleteFile('C:\WINDOWS\system32\system32\svchost.exe');
DeleteFile('C:\WINDOWS\system32\install\server.exe');
DeleteFile('C:\WINDOWS\install\Svchost.exe');
DeleteFile('C:\Documents and Settings\user\Application Data\winlogon.exe');
DeleteFile('c:\documents and settings\user\application data\windowsupdateb1a2.exe');
DeleteFile('C:\Documents and Settings\user\Application Data\windowsupdateb1a2.exe');
DeleteFile('C:\Documents and Settings\user\Application Data\System.Data.SQLite.dll');
DeleteFile('c:\documents and settings\user\application data\nvdisp.exe');
DeleteFile('C:\Documents and Settings\user\Application Data\nvdisp.exe');
DeleteFile('C:\Documents and Settings\user\Application Data\galaxy.exe');
DeleteFile('c:\documents and settings\user\application data\dx10bac\d-xdiag10bc.exe');
DeleteFile('c:\documents and settings\user\application data\dx10bac\d-werwerwrw.exe');
DelCLSID('{T46R5W7L-2GVA-PPE7-SV56-43SLLPO7J7X0}');
DelCLSID('{4RS2H7BF-V8M5-H54K-56RL-C35S4Q0TW421}');
DelCLSID('{3O50H026-26A6-3786-KHDY-63V0X001E7Y4}');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
After reboot:
- Execute following script in Manual Healing
Код:
begin
CreateQurantineArchive('C:\quarantine.zip');
end.
- Upload the C:\quarantine.zip here: http://virusinfo.info/upload_virus_eng.php?tid=83132
- Make a new log file.
- Attach a new log to your new post..