Switch off:
- Antivirus and and, if you have - Firewall.
- System Restore
- Execute following script in Manual Healing
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\system32\Drivers\mmc_2K.sys','');
QuarantineFile(':\WINDOWS\system32\srrstr.dll','');
QuarantineFile('D:\Uninstall Tool\utool.exe','');
QuarantineFile('cli.dll','');
QuarantineFile('D:\Advanced SystemCare 3\AutoSweep.exe','');
QuarantineFile('C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll','');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Eventlog\Application\WgaSetup','EventMessageFile');
DeleteService('GbpSv');
DeleteService('rotscxrumqlvey');
RegKeyResetSecurity('HKLM','SYSTEM\CurrentControlSet\Services\GbpSv');
RegKeyResetSecurity('HKLM','SYSTEM\CurrentControlSet\Services\rotscxrumqlvey');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
After reboot:
- Execute following script in Manual Healing
Код:
begin
CreateQurantineArchive('C:\quarantine.zip');
end.
- Upload the C:\quarantine.zip here: http://virusinfo.info/upload_virus_eng.php?tid=79327
- Repeat a log file.
- Attach a new log to your new post..