Код:
procedure WhatService(AServiceName : string);
var
dllname, servicekey : string;
begin
servicekey := 'SYSTEM\CurrentControlSet\Services\'+AServiceName;
RegKeyResetSecurity( 'HKLM', servicekey);
RegKeyResetSecurity( 'HKLM', servicekey+'\Parameters');
AddToLog('Description: '+RegKeyStrParamRead( 'HKLM', servicekey, 'Description'));
AddToLog('DisplayName: '+RegKeyStrParamRead( 'HKLM', servicekey, 'DisplayName'));
AddToLog('ImagePath: '+RegKeyStrParamRead( 'HKLM', servicekey, 'ImagePath'));
dllname := RegKeyStrParamRead( 'HKLM', servicekey+'\Parameters', 'ServiceDll');
AddToLog('ServiceDll: '+dllname);
QuarantineFile(dllname,'');
end;
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
WhatService('jvatmaruw');
WhatService('pxwtfs');
QuarantineFile('\\?\globalroot\systemroot\system32\9o0pGxU.exe','');
QuarantineFile('C:\WINDOWS\system32\jjzsjr.exe','');
QuarantineFile('C:\WINDOWS\system32\f424382.exe','');
QuarantineFile('C:\WINDOWS\system32\d7193355.exe','');
QuarantineFile('C:\WINDOWS\system32\cqlepg.exe','');
QuarantineFile('C:\WINDOWS\system32\bqmdfb.exe','');
QuarantineFile('C:\WINDOWS\system32\9053627c.exe','');
QuarantineFile('C:\WINDOWS\system32\3d55357f.exe','');
QuarantineFile('C:\WINDOWS\system32\34e4007d.exe','');
QuarantineFile('C:\WINDOWS\system32\3152a68a.exe','');
QuarantineFile('C:\WINDOWS\services.exe','');
QuarantineFile('C:\WINDOWS\TEMP\sadmf.exe','');
QuarantineFile('C:\Program Files\pchd\PCHDPlayer.exe','');
QuarantineFile('C:\WINDOWS\system32\smhlmlb.dll','');
DeleteFile('C:\WINDOWS\system32\smhlmlb.dll');
DeleteFile('C:\Program Files\pchd\PCHDPlayer.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','PCHDPlayer');
DeleteFile('C:\WINDOWS\services.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','services.exe');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','sysadmf');
DeleteFile('C:\WINDOWS\system32\3152a68a.exe');
DeleteFile('C:\WINDOWS\system32\34e4007d.exe');
DeleteFile('C:\WINDOWS\system32\3d55357f.exe');
DeleteFile('C:\WINDOWS\system32\9053627c.exe');
DeleteFile('C:\WINDOWS\system32\bqmdfb.exe');
DeleteFile('C:\WINDOWS\system32\cqlepg.exe');
DeleteFile('C:\WINDOWS\system32\d7193355.exe');
DeleteFile('C:\WINDOWS\system32\f424382.exe');
DeleteFile('C:\WINDOWS\system32\jjzsjr.exe');
DeleteFile('\\?\globalroot\systemroot\system32\9o0pGxU.exe');
DeleteFileMask('C:\Program Files\pchd', '*.*', true);
DeleteDirectory('C:\Program Files\pchd');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Generic Host for Win32 Services');
RegKeyStrParamWrite('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon','UserInit', GetEnvironmentVariable ('WinDir')+'\System32\userinit.exe,');
RegKeyStrParamWrite('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows','AppInit_DLLs','');
BC_ImportAll;
ExecuteSysClean;
ExecuteWizard('TSW', 2, 2, true);
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
SaveLog(GetAVZDirectory+'monssm.log');
RebootWindows(true);
end.
После перезагрузки: