It is too hard to understand, that you must send quarantine to us by red link only?
Pay attention, please.
Now, disable system restore, disable antivirus.
Execute this script: (there still some malware and very dangerous settings in internet explorer. As you can see : my guess was correct)
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ClearQuarantine;
TerminateProcessByName('c:\program files\common files\bugoilen\bungo659.exe');
QuarantineFile('c:\program files\common files\bugoilen\bungo659.exe','');
DeleteFile('c:\program files\common files\bugoilen\bungo659.exe');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 1);
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
CreateQurantineArchive('C:\quarantine2.zip');
RebootWindows(true);
end.
Remember to upload a new quarantine2.zip by red link only: http://virusinfo.info/upload_virus_eng.php?tid=53294
Make an another log after that and attach it to next post.