1. Please, disable System Restore and antivirus (if you have).
2. Execute this script in AVPTool:
Код:
begin
SetAVZGuardStatus(True);
DeleteFileMask(GetAVZDirectory+'Quarantine', '*.*', true);
DelBHO('{710EB7A1-45ED-11D0-924A-0020AFC7AC4D}');
QuarantineFile('C:\WINDOWS\system32\gebyv.dll','');
DeleteFile('C:\WINDOWS\system32\gebyv.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv','DLLName');
BC_ImportDeletedList;
ExecuteSysClean;
ExecuteRepair(1);
BC_Activate;
RebootWindows(true);
end.
3. After reboot execute this script in AVPTool:
Код:
begin
CreateQurantineArchive('C:\quarantine.zip');
end.
Upload file C:\quarantine.zip, by link http://virusinfo.info/upload_virus.php?tid=67150
4. Execute commands in Gmer:
Код:
8uxvwmjx.exe -del service H8SRTd.sys
8uxvwmjx.exe -del file "c:\windows\system32\drivers\H8SRTwnnpyrdscn.sys"
8uxvwmjx.exe -del file "c:\windows\system32\H8SRToxkaritmkj.dll"
8uxvwmjx.exe -del file "c:\windows\system32\H8SRTarunsofxon.dat"
8uxvwmjx.exe -del file "c:\windows\system32\H8SRTqolkbtghmj.dll"
8uxvwmjx.exe -del file "c:\windows\system32\H8SRTauulsqbqly.dll"
8uxvwmjx.exe -del file "c:\windows\system32\H8SRTvmrohkqfix.dll"
8uxvwmjx.exe -del reg "HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys"
8uxvwmjx.exe -del reg "HKLM\SYSTEM\ControlSet004\Services\H8SRTd.sys"
8uxvwmjx.exe -reboot
5. Fix in HijackThis:
O20 - Winlogon Notify: gebyv - C:\WINDOWS\system32\gebyv.dll (file missing)
6. Make new logs: avptool_sysinfo, hijackthis + gmer.