Hi
Close/unload all the programs excepted AVZ and Internet Explorer
Switch off:
- Antivirus and and, if you have - Firewall.
- System Restore
- Execute following script in Manual Healing
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ClearQuarantine;
QuarantineFileF('C:\WINDOWS\system32\CTF\', '*.*', false, '', 0, 0);
QuarantineFile('C:\WINDOWS\system32\DRIVERS\lmimirr.sys','');
TerminateProcessByName('c:\windows\system32\ctf\ctfmon.exe');
DeleteFileMask('c:\windows\system32\ctf\','*.*',true);
DeleteDirectory('C:\WINDOWS\system32\CTF\');
RegKeyIntParamWrite( 'HKLM', 'SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum', '{BDEADF00-C265-11D0-BCED-00A0C90AB50F}', 1);
ExecuteWizard('TSW', 2, 2, true);
ExecuteWizard('SCU', 2, 2, true);
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
SetAVZPMStatus(True);
RebootWindows(true);
end.
After reboot:
- Execute following script in Manual Healing
Код:
begin
CreateQurantineArchive('C:\quarantine.zip');
end.
- Upload the C:\quarantine.zip here: http://virusinfo.info/upload_virus_eng.php?tid=86123
- Make a new log file of AVPTool
- Attach a new log to your new post..