Please wait until asked, before running Combofix.
Run this script, PC will reboot:
Code:
begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
QuarantineFile('c:\windows\system32\nmdfgds1.dll','');
QuarantineFile('c:\windows\system32\olhrwef.exe','');
QuarantineFile('c:\windows\system32\nmdfgds0.dll','');
QuarantineFile('C:\gy.exe','');
QuarantineFile('C:\autorun.inf','');
DeleteFile('C:\autorun.inf');
DeleteFile('C:\gy.exe');
DeleteFile('c:\windows\system32\nmdfgds0.dll');
DeleteFile('c:\windows\system32\olhrwef.exe');
DeleteFile('c:\windows\system32\nmdfgds1.dll');
RegKeyDel('HKCU','Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
Then, run this one:
Code:
begin
CreateQurantineArchive('c:\quarantine.zip');
end.
A file called quarantine.zip should be created in C:\. Then please zip up C:\qoobox\quarantine and upload both it and C:\quarantine.zip to a filehost such as
http://rapidshare.com/ Then, Private Message me the download link to the uploaded file. Click my user name and select Send message. Lastly, uninstall Combofix by:
pause Kaspersky > Start > run > type combofix /u > ok. Or Start > run > type 123 /u > ok. Restart Kaspersky.
Also, if you use Windows System restore, turn it off > reboot and do a full scan with Kaspersky. Then turn system restore back on, if you wish; this to remove malware
from system volume information files.
Scan with SuperAntiSpyware: http://www.superantispyware.com/ and post it's log, but please don't fix anything until the log is reviewed.
Bookmarks