Hi!
Please, exactly follow the instructions:
Download special avz in my signature.
Please execute this script in avz( how-to: http://virusinfo.info/showthread.php?t=9207) (Do remember before execution scripts to exit antivirus and disconnect from internet, disable System Restore )
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\system32\KCFG32.CPL','');
QuarantineFile('c:\docume~1\boy200~1\applic~1\intern~1\manager ooze media.exe','');
DelBHO('{02478D38-C3F9-4efb-9B51-7695ECA05670}');
DelBHO('{5C255C8A-E604-49b4-9D64-90988571CECB}');
DelBHO('{31FC1F5B-A825-4335-827F-9A604838884A}');
QuarantineFile('C:\WINDOWS\AdobeR.exe','');
QuarantineFile('C:\Program Files\WordWeb\wweb32.exe','');
QuarantineFile('C:\Documents and Settings\All Users\Application Data\part dead amok eggs\cool chin.exe','');
QuarantineFile('C:\Documents and Settings\All Users\Application Data\Mail For File Wave\Blue Cool.exe','');
QuarantineFile('C:\DOCUME~1\BOY200~1\APPLIC~1\INTERN~1\Drv blue.exe','');
QuarantineFile('C:\WINDOWS\system32\drivers\ws2_32sik.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\nicsk32.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\nchssvad.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\fips32cup.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\amd64si.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\PxHelp20.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys','');
DeleteFile('C:\WINDOWS\system32\drivers\ws2_32sik.sys');
DeleteFile('C:\WINDOWS\system32\drivers\nicsk32.sys');
DeleteFile('C:\WINDOWS\system32\drivers\fips32cup.sys');
DeleteFile('C:\WINDOWS\system32\drivers\amd64si.sys');
DeleteFile('C:\DOCUME~1\BOY200~1\APPLIC~1\INTERN~1\Drv blue.exe');
DeleteFile('C:\Documents and Settings\All Users\Application Data\Mail For File Wave\Blue Cool.exe');
DeleteFile('C:\Documents and Settings\All Users\Application Data\part dead amok eggs\cool chin.exe');
DeleteFile('C:\WINDOWS\AdobeR.exe');
DeleteFile('c:\docume~1\boy200~1\applic~1\intern~1\manager ooze media.exe');
DeleteFile('C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys');
BC_DeleteSvc('amd64si');
BC_DeleteSvc('mferkdk');
BC_DeleteSvc('fips32cup');
BC_DeleteSvc('nicsk32');
BC_DeleteSvc('ws2_32sik');
BC_DeleteSvc('mferkdk');
BC_ImportAll;
ExecuteSysClean;
ExecuteRepair(6);
ExecuteRepair(8);
ExecuteRepair(9);
BC_Activate;
SetAVZPMStatus(true);
RebootWindows(true);
end.
System will reboot.
Please upload quarantine according to Appendix# 3 of rules by red link in your topic.
Please read carefully: http://virusinfo.info/showthread.php?t=9184 and make all 3 logs, as described and do attach them to next post in this topic.(use special avz, don't need update it)