i can't cath it..
Printable View
i can't cath it..
Please disable system restore, disconnect from internet and disable all your antivirus and antispyware.
Execute the following script: (how-to: [url]http://avptool.virusinfo.info/en/AVPTool_helpdesk_curescript.htm[/url] )
[code]begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\vshost.exe','');
QuarantineFile('C:\autorun.inf','');
QuarantineFile('C:\WINDOWS\SOUNDMAN.EXE','');
QuarantineFile('C:\RECYCLER\S-1-5-21-2723744624-6555353043-025733044-8622\winservices.exe','');
QuarantineFile('C:\program files\rnamfler\radprlib.dll','');
QuarantineFile('c:\program files\rnamfler\radprcmp.exe','');
QuarantineFile('c:\program files\rnamfler\naomf.exe','');
QuarantineFile('c:\program files\rnamfler\naofsvc.exe','');
QuarantineFile('c:\documents and settings\graюina\my documents\my pictures\free download manager\fdm.exe','');
QuarantineFile('c:\docume~1\graina~1\locals~1\temp\115.exe','');
QuarantineFile('c:\docume~1\graina~1\locals~1\temp\053.exe','');
DeleteFile('c:\docume~1\graina~1\locals~1\temp\053.exe');
DeleteFile('c:\docume~1\graina~1\locals~1\temp\115.exe');
DeleteFile('C:\RECYCLER\S-1-5-21-2723744624-6555353043-025733044-8622\winservices.exe');
DeleteFile('C:\autorun.inf');
DeleteFile('C:\vshost.exe');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(6);
ExecuteRepair(8);
ExecuteRepair(9);
RebootWindows(true);
end.
[/code]
Your system will reboot.
In kaspersky virus removal tool you will find a folder called "quarantine" or similar.
Zip it with password [B]virus [/B]and send us by [url]http://virusinfo.info/upload_virus_eng.php?tid=38868[/url]
Make an another log and attach it to your next post.
the folder quarantine is empty.. so there is no what to send for you.. anyway thank's I think it hellped.. C:/ disck open good and no more "autoran.inf" "svhost.exe"
my english is poor.. sorry for mistakes.. :unsure:
Ok, make an another log and attach it to your post.