Please, turn off the system restore (how - see the rules).
Then AVZ - File - Custom scripts
Execute the following script (copy it, paste it in the script window of AVZ and execute):
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\Users\Thomas\Documents\Downloads\Fertig\SlySoft\AnyDVD 6.3.0.0\AnyDVD leftover killer 1.3.exe','');
QuarantineFile('rdpclip','');
QuarantineFile('.exe','');
QuarantineFile('C:\Windows\system32\oudslohn.dll','');
QuarantineFile('C:\Windows\system32\gfxkywtb.dll','');
QuarantineFile('C:\Windows\system32\ftfytc.dll','');
QuarantineFile('C:\Users\Thomas\AppData\Local\Temp\khfGaaXn.dll','');
DeleteFile('C:\Users\Thomas\AppData\Local\Temp\khfGaaXn.dll');
DeleteFile('C:\Windows\system32\ftfytc.dll');
DeleteFile('C:\Windows\system32\gfxkywtb.dll');
DeleteFile('C:\Windows\system32\oudslohn.dll');
DelBHO('EDB4D6AA-7416-4365-A0F8-506CF658681C');
DelBHO('aece0790-fbf1-4398-9115-2d3062d3524c');
RegKeyParamDel('HKEY_CURRENT_USER', 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run', 'MSServer');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
Your computer will reboot.
Upload the quarantined files according to the Appendix 3 of the rules. (upload here http://virusinfo.info/upload_virus_eng.php?tid=26755 )
Make and attach new logs.