Hi, I also can't launch tools like SpyBot or HijackThis. In attach the AVPTool syscheck log. Thank you!
Printable View
Hi, I also can't launch tools like SpyBot or HijackThis. In attach the AVPTool syscheck log. Thank you!
Go Offline
Switch off:
- Antivirus and and, if you have - Firewall, Tea Timer of Spybot Search & Destroy - if active.
- System Restore
- [URL="http://virusinfo.info/showthread.php?t=9207"]Execute following script[/URL]
[CODE]begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
DeleteService('Ytj28');
QuarantineFile('C:\WINDOWS\TEMP\UA33AF.EXE','');
QuarantineFile('C:\WINDOWS\System32\drivers\tcpsr.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Ytj28.sys','');
QuarantineFile('C:\WINDOWS\System32\crypts.dll','');
QuarantineFile('cru629.dat','');
QuarantineFile('C:\WINDOWS\system32\vbsys2.dll','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Beep.SYS','');
DeleteFile('C:\WINDOWS\System32\Drivers\Beep.SYS');
DeleteFile('C:\WINDOWS\system32\vbsys2.dll');
DeleteFile('cru629.dat');
DeleteFile('C:\WINDOWS\System32\crypts.dll');
DeleteFile('C:\WINDOWS\System32\Drivers\Ytj28.sys');
DeleteFile('C:\WINDOWS\System32\drivers\tcpsr.sys');
DeleteFile('c:\windows\temp\ua33af.exe');
BC_ImportDeletedList;
ExecuteSysClean;
BC_DeleteService('Ytj28');
BC_Activate;
executerepair(1);
RebootWindows(true);
end.
[/CODE]
After reboot:
- Clean Temp-Maps, Cache of Browsers, Recycler. Use Windows service tool [URL="http://support.microsoft.com/?scid=kb%3Ben-us%3B315246&x=17&y=6"]cleanmgr[/URL] or [URL="http://www.ccleaner.com/"]CCleaner[/URL] or [URL="http://www.clearprog.de/"]ClearProg[/URL]
- Close all the programs and start only Internet Explorer!!!
- If you cannot start Hijackthis rename the file hijackthis.exe in 135.pif. Repeat 3 log files in accordance with the [URL="http://virusinfo.info/showthread.php?t=9184"]rules[/URL].
- Switch Antivirus and, if you have - Firewall, on.
- Go On-Line
- Upload the quarantine [COLOR="Red"][B]over the red link[/B][/COLOR] on th etop of this page.
- Attach 3 logs to your new post..