1. Please, disable System Restore and antivirus (if you have).
2. Execute this script in AVPTool:
Код:
begin
ClearHostsFile;
SetAVZGuardStatus(True);
RegKeyIntParamWrite('HKLM','SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer','NoDriveTypeAutoRun', 221);
QuarantineFile('C:\WINDOWS\system32\xqcpiangrifdddzz.exe','');
QuarantineFile('C:\WINDOWS\system32\liypmizwlghjnrrvtqgx.exe','');
QuarantineFile('C:\WINDOWS\system32\ayphfcusiegjotuzywnfd.exe','');
QuarantineFile('C:\DOCUME~1\Tetis\LOCALS~1\Temp\yujzvqgcqkklorqtqmb.exe .','');
QuarantineFile('C:\DOCUME~1\Tetis\LOCALS~1\Temp\xqcpiangrifdddzz.exe','');
QuarantineFile('C:\DOCUME~1\Tetis\LOCALS~1\Temp\niwlgapkxqpprtrtpk.exe','');
QuarantineFile('C:\DOCUME~1\Tetis\LOCALS~1\Temp\eylztmaugywvwxuvq.exe','');
DeleteFile('C:\DOCUME~1\Tetis\LOCALS~1\Temp\eylztmaugywvwxuvq.exe');
RegKeyParamDel('HKEY_USERS','S-1-5-21-1409082233-1614895754-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run','eqvbnyequ');
DeleteFile('C:\DOCUME~1\Tetis\LOCALS~1\Temp\niwlgapkxqpprtrtpk.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','skvhzqcueuqnmlg');
DeleteFile('C:\DOCUME~1\Tetis\LOCALS~1\Temp\xqcpiangrifdddzz.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','nychschs');
DeleteFile('C:\DOCUME~1\Tetis\LOCALS~1\Temp\yujzvqgcqkklorqtqmb.exe .');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','pgqbsitktidzxv');
RegKeyParamDel('HKEY_USERS','S-1-5-21-1409082233-1614895754-725345543-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce','xkqxkwdqvg');
DeleteFile('C:\WINDOWS\system32\ayphfcusiegjotuzywnfd.exe');
RegKeyParamDel('HKEY_USERS','S-1-5-21-1409082233-1614895754-725345543-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce','oenxncmckysnk');
DeleteFile('C:\WINDOWS\system32\liypmizwlghjnrrvtqgx.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','eqvbnyequ');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','sgnvjwesykc');
DeleteFile('C:\WINDOWS\system32\xqcpiangrifdddzz.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','xkqxkwdqvg');
RegKeyParamDel('HKEY_USERS','S-1-5-21-1409082233-1614895754-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run','pemvkyhwdqjd');
DeleteFile('C:\autorun.inf');
DeleteFile('D:\autorun.inf');
DeleteFile('E:\autorun.inf');
DeleteFileMask('%tmp% ','*.* ',true );
BC_ImportDeletedList;
ExecuteSysClean;
ExecuteWizard('TSW', 3, 3, true);
ExecuteWizard('SCU', 3, 3, true);
BC_Activate;
SetAVZPMStatus(True);
RebootWindows(true);
end.
3. After reboot execute this script in AVPTool:
Код:
begin
CreateQurantineArchive('C:\quarantine.zip');
end.
Upload file C:\quarantine.zip, by link http://virusinfo.info/upload_virus.php?tid=63486
4. Attach a new log to your new post.