1. Please, disable System Restore and antivirus (if you have).
2. Execute the script in AVPTool:
Код:
begin
SetAVZGuardStatus(True);
RegKeyIntParamWrite('HKLM','SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer','NoDriveTypeAutoRun', 221);
QuarantineFile('C:\WINDOWS\system32\DRIVERS\ssmdrv.sys','');
QuarantineFile('C:\Documents and Settings\LocalService\vbllt.exe','');
DeleteFile('C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\_uninstall_is-J8LPD.bat');
DeleteFile('C:\Documents and Settings\LocalService\vbllt.exe');
BC_ImportAll;
ExecuteSysClean;
ExecuteWizard('TSW', 3, 3, true);
BC_Activate;
CreateQurantineArchive('C:\quarantine.zip');
RebootWindows(true);
end.
After restart upload file C:\quarantine.zip, by link http://virusinfo.info/upload_virus.php?tid=56257
3. Attach a new avptool_syscheck.zip.