Hello.
First of all you should download AVZ tool using the link in rules of "Help me!" section, unpack it to a separate folder and update its databases.
Run avz and execute the script:
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\autorun.inf','');
QuarantineFile('C:\WINDOWS\system32\WORD.exe','');
QuarantineFile('C:\WINDOWS\system32\ieso0.dll','');
QuarantineFile('C:\WINDOWS\system32\Drivers\mchInjDrv.sys','');
QuarantineFile('C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL','');
DeleteFile('C:\WINDOWS\system32\Drivers\mchInjDrv.sys');
BC_DeleteFile('C:\WINDOWS\system32\Drivers\mchInjDrv.sys');
DeleteFile('C:\WINDOWS\system32\ieso0.dll');
BC_DeleteFile('C:\WINDOWS\system32\ieso0.dll');
DeleteFile('C:\WINDOWS\system32\WORD.exe');
BC_DeleteFile('C:\WINDOWS\system32\WORD.exe');
DeleteFile('C:\autorun.inf');
BC_DeleteFile('C:\autorun.inf');
Deletefile('C:\WINDOWS\Tasks\at1.job');
BC_Deletefile('C:\WINDOWS\Tasks\at1.job');
DelBHO('{CE7C3CF0-4B15-11D1-ABED-709549C10000}');
BC_Activate;
ExecuteSysClean;
executerepair(5);
executerepair(6);
executerepair(8);
executerepair(11);
executerepair(17);
RebootWindows(true);
end.
After reboot, upload quarantine using the link http://virusinfo.info/upload_virus_eng.php?tid=42806 as it's described in the appendix 3 of the rules, make new logs and attach them to a new post here.