Close/unload all the programs
Switch off:
- Antivirus and, if you have - Firewall.
- Execute following script in AVZ
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
TerminateProcessByName('c:\windows\paizhao.exe');
QuarantineFile('C:\WINDOWS\Paizhao.EXE','');
QuarantineFile('C:\Program Files\WebSecurity\services.exe','');
QuarantineFile('C:\WINDOWS\system32\hiwe.exe','');
QuarantineFile('C:\WINDOWS\system32\olhrwef.exe','');
QuarantineFile('C:\WINDOWS\system32\userini.exe','');
QuarantineFile('C:\vvv.exe','');
QuarantineFile('C:\WINDOWS\system32\chrome.exe','');
QuarantineFile('C:\Documents and Settings\Niranjan\csrss.exe','');
DeleteFile('C:\Documents and Settings\Niranjan\csrss.exe');
DeleteFile('C:\WINDOWS\system32\chrome.exe');
DeleteFile('C:\vvv.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Updates');
DeleteFile('C:\WINDOWS\system32\userini.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','userini');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Yahoo Messengger');
BC_ImportAll;
ExecuteSysClean;
ExecuteWizard('TSW',2,2,true);
ExecuteRepair(17);
ExecuteRepair(11);
BC_Activate;
RebootWindows(true);
end.
After reboot:
- Execute following script in AVZ
Код:
begin
CreateQurantineArchive('C:\quarantine.zip');
end.
- Upload the C:\quarantine.zip here: upload_virus_eng.
- Make a new log file and Attach a new log to your new post..
- Make a log with antirootkit GMER