In order to make it more easy for you,
please download special avz in my signature and put it in new folder (for ex. on Desktop)
Do execute this script in avz( how-to: http://virusinfo.info/showthread.php?t=9207) (Do remember, before lunching an avz to exit/unload/disable your f-secure and disconnect from internet )
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
DeleteService('MEMSWEEP2');
QuarantineFile('C:\Program Files\Nero\Nero8\InCD\NBHStr.dll','');
QuarantineFile('C:\Program Files\Common Files\Nero\Shared\NL3\AdvrCntr3.dll','');
QuarantineFile('C:\WINDOWS\system32\drivers\npf.sys','');
QuarantineFile('C:\WINDOWS\system32\8A.tmp','');
QuarantineFile('C:\WINDOWS\system32\Drivers\cercsr6.sys','');
QuarantineFile('C:\WINDOWS\system32\Drivers\fsbts.sys','');
QuarantineFile('C:\WINDOWS\system32\UACiuebtvmo.dll','');
QuarantineFile('c:\windows\system32\acs.exe','');
DeleteFile('C:\WINDOWS\system32\UACiuebtvmo.dll');
DeleteFile('C:\WINDOWS\system32\8A.tmp');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(6);
ExecuteRepair(8);
ExecuteRepair(9);
SetAVZPMStatus(true);
RebootWindows(true);
end.
System will reboot.
Please upload quarantine according to Appendix# 3 of the rules by http://virusinfo.info/upload_virus_eng.php?tid=42690
Please do all 3 logs according to rules: System will reboot.
Please upload quarantine according to Appendix# 3 of the rules: http://virusinfo.info/showthread.php?t=9184