please help me to remove the viruses in my pc details are collected and in the attachement
Printable View
please help me to remove the viruses in my pc details are collected and in the attachement
Close/unload all the programs excepted AVZ and Internet Explorer
Switch off:
- Antivirus and and, if you have - Firewall.
- System Restore
- [URL="http://virusinfo.info/showthread.php?t=9207"]Execute following script[/URL]
[CODE]begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\docume~1\mainte~1\locals~1\temp\ytb3.exe');
TerminateProcessByName('c:\docume~1\mainte~1\locals~1\temp\ycomp_~1.exe');
TerminateProcessByName('c:\docume~1\mainte~1\locals~1\temp\winvnpc.exe');
TerminateProcessByName('c:\docume~1\mainte~1\locals~1\temp\nfvqa.exe');
TerminateProcessByName('c:\docume~1\mainte~1\locals~1\temp\glb55.tmp');
TerminateProcessByName('c:\docume~1\mainte~1\locals~1\temp\fvsxed.exe');
StopService('dac970nt');
QuarantineFile('dac970nt.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\iqllln.sys','');
QuarantineFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\ytb3.exe','');
QuarantineFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\YCOMP_~1.EXE','');
QuarantineFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\winvnpc.exe','');
QuarantineFile('c:\docume~1\mainte~1\locals~1\temp\winvnpc.exe','');
QuarantineFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\nfvqa.exe','');
QuarantineFile('c:\docume~1\mainte~1\locals~1\temp\nfvqa.exe','');
QuarantineFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\GLK57.tmp','');
QuarantineFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\GLC56.tmp','');
QuarantineFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\GLB55.tmp','');
QuarantineFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\fvsxed.exe','');
DeleteService('dac970nt');
DeleteFile('C:\WINDOWS\system32\drivers\dac970nt.sys');
DeleteFile('C:\WINDOWS\system32\drivers\iqllln.sys');
DeleteFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\ytb3.exe');
DeleteFile('c:\docume~1\mainte~1\locals~1\temp\ycomp_~1.exe');
DeleteFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\YCOMP_~1.EXE');
DeleteFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\winvnpc.exe');
DeleteFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\nfvqa.exe');
DeleteFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\GLK57.tmp');
DeleteFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\GLC56.tmp');
DeleteFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\GLB55.tmp');
DeleteFile('C:\DOCUME~1\MAINTE~1\LOCALS~1\Temp\fvsxed.exe');
BC_ImportAll;
ExecuteSysClean;
BC_DeleteSvc('dac970nt');
BC_Activate;
RebootWindows(true);
end.
[/CODE]
After reboot:
- Clean Temp-Maps, Cache of Browsers, Recycler. Use Windows service tool [URL="http://support.microsoft.com/?scid=kb%3Ben-us%3B315246&x=17&y=6"]cleanmgr[/URL] or [URL="http://www.ccleaner.com/"]CCleaner[/URL] or [URL="http://www.clearprog.de/"]ClearProg[/URL]
- Close all the programs and start only Internet Explorer!!!
- Repeat 3 log files in accordance with the [URL="http://virusinfo.info/showthread.php?t=9184"]rules[/URL].
- Switch Antivirus and, if you have - Firewall, on.
- Go On-Line
- Upload the quarantine in accordance with Appx. 3 of the rules.
- Attach 3 logs to your new post..