Close/unload all the programs excepted AVZ and Internet Explorer
Switch off:
- Antivirus and and, if you have - Firewall.
- System Restore
- Execute following script in Manual Healing
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\twunk_16.exe','');
QuarantineFile('C:\WINDOWS\system32\pwdmon.dll','');
QuarantineFile('C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe','');
QuarantineFile('C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe','');
QuarantineFile('C:\WINDOWS\system32\PsaSrv.exe','');
QuarantineFile('C:\Documents and Settings\Khilen Shah\Khilen Shah1\winlogon.exe','');
QuarantineFile('C:\WINDOWS\system32\7sGQbATX.exe','');
DeleteFile('C:\WINDOWS\system32\7sGQbATX.exe');
DeleteFile('C:\Documents and Settings\Khilen Shah\Khilen Shah1\winlogon.exe');
DeleteFile('C:\WINDOWS\twunk_16.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','NVIDIA Media Center Library');
RegKeyParamDel('HKEY_USERS','S-1-5-21-2162815159-2298460070-1374140739-1005\Software\Microsoft\Windows\CurrentVersion\Run','NVIDIA Media Center Library');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
After reboot:
- Execute following script in Manual Healing
Код:
begin
CreateQurantineArchive('C:\quarantine.zip');
end.
- Upload the C:\quarantine.zip here: http://virusinfo.info/upload_virus_eng.php?tid=83856
- Make a new log file.
- Make a log file of Malwarebytes Antimalware: http://www.malwarebytes.org/mbam.php
- Attach a new log to your new post..