Close/unload all the programs excepted AVZ and Internet Explorer
Switch off:
- Antivirus and and, if you have - Firewall.
- System Restore
- Execute following script in Manual Healing
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ClearQuarantine;
QuarantineFile('C:\WINDOWS\system32\wsnpoema.exe','');
QuarantineFile('C:\WINDOWS\system32\Drivers\NDIS.sys','');
QuarantineFile('C:\WINDOWS\system32\Drivers\ejxtwmfy.sys','');
DeleteFile('C:\WINDOWS\system32\Drivers\ejxtwmfy.sys');
DeleteFile('C:\WINDOWS\system32\wsnpoema.exe');
DeleteService('ejxtwmfy);
DeleteService('lfozeixaw);
RegKeyResetSecurity('HKLM','SYSTEM\CurrentControlSet\Services\ejxtwmfy);
RegKeyResetSecurity('HKLM','SYSTEM\CurrentControlSet\Services\lfozeixaw);
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
After reboot:
- Replace file C:\WINDOWS\system32\Drivers\NDIS.sys with a system file from Windows CD or from any similar system. For replacing pls. use either recovery console of Windows or any Live CD or re-mount your hard disk as slave into any other PC. Ask your http://www.google.com.my about details.
Boot your system from hard disk with replaced C:\WINDOWS\system32\Drivers\NDIS.sys
- Execute following script in Manual Healing
Код:
begin
CreateQurantineArchive('C:\quarantine.zip');
end.
- Upload the C:\quarantine.zip here: http://virusinfo.info/upload_virus_eng.php?tid=74496
- Install Service Pack 3 and all subsequent updates.
- Install Internet Explorer 8
- Make a new logfile of AVPTool and attach it to your next post. REM: You don't need to use AVPTool, you could make just the same log form Kaspersky Interface. See here for more details: http://forum.kaspersky.com/index.php...6&#entry678326