Welcome!
Сure script for you in box below -
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\Programmi\Crawler\Toolbar\ctbr.dll','');
QuarantineFile('kisopn.dll','');
SetServiceStart('ati5mqxx', 4);
QuarantineFile('c:\windows\system32\sysrest32.exe','');
QuarantineFile('c:\windows\system32\lphcc4uj0ea19.exe','');
DeleteFile('c:\windows\system32\lphcc4uj0ea19.exe');
DeleteFile('c:\windows\system32\sysrest32.exe');
DeleteFile('kisopn.dll');
DelWinlogonNotifyByKeyName('kisopn');
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
BC_ImportDeletedList;
ExecuteSysClean;
BC_DeleteSvc('ati5mqxx');
BC_Activate;
RebootWindows(true);
end.
When script done you system automatically reboot.
After reboot repeat AVPTools log and also do additional HijackThis log from rules, also you need to change screensaver in desktop options.
Please upload quarantine archive (for virus analyst), click "Upload quarantined files" overhead of topic and select quarantine.zip from AVPTolls folder.
Post new AVPTool and HijackThis logs.