Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\windows\temp\wpv931277648030.exe');
TerminateProcessByName('c:\windows\temp\wpv921277561113.exe');
TerminateProcessByName('c:\windows\temp\wpv681277560653.exe');
TerminateProcessByName('c:\docume~1\bbda~1.ser\locals~1\temp\9158315.exe');
TerminateProcessByName('c:\docume~1\bbda~1.ser\locals~1\temp\574371.exe');
TerminateProcessByName('c:\docume~1\bbda~1.ser\locals~1\temp\0625919.exe');
QuarantineFile('C:\WINDOWS\Mstray.exe','');
QuarantineFile('C:\Documents and Settings\Администратор.SERVER\Application Data\ibnzs.exe','');
QuarantineFile('H:\check.exe','');
QuarantineFile('H:\autorun.inf','');
QuarantineFile('c:\windows\explorer.exe:userini.exe:$DATA','');
QuarantineFile('C:\WINDOWS\system32\userini.exe','');
QuarantineFile('C:\WINDOWS\system32\sysnkey32.exe','');
QuarantineFile('C:\WINDOWS\HELP\SQQNO.exe','');
QuarantineFile('C:\Documents and Settings\Администратор.SERVER\Application Data\yftza.exe','');
QuarantineFile('C:\Documents and Settings\LocalService\Application Data\Microsoft\wufout.exe','');
QuarantineFile('C:\DOCUME~1\9335~1\LOCALS~1\Temp\eeewmdkcvrgat.sys','');
QuarantineFile('c:\windows\temp\wpv931277648030.exe','');
QuarantineFile('c:\windows\temp\wpv921277561113.exe','');
QuarantineFile('c:\windows\temp\wpv681277560653.exe','');
QuarantineFile('c:\docume~1\bbda~1.ser\locals~1\temp\9158315.exe','');
QuarantineFile('c:\docume~1\bbda~1.ser\locals~1\temp\574371.exe','');
QuarantineFile('c:\docume~1\bbda~1.ser\locals~1\temp\0625919.exe','');
QuarantineFile('C:\System Volume Information\_restore{8E95D149-9FEC-42A3-89DB-C88C4D9CBBDA}\RP994\A0221467.exe:userini.exe:$DATA','');
DeleteFile('C:\System Volume Information\_restore{8E95D149-9FEC-42A3-89DB-C88C4D9CBBDA}\RP994\A0221467.exe:userini.exe:$DATA');
DeleteService('odcvoc');
DeleteFile('c:\docume~1\bbda~1.ser\locals~1\temp\0625919.exe');
DeleteFile('c:\docume~1\bbda~1.ser\locals~1\temp\9158315.exe');
DeleteFile('c:\windows\temp\wpv681277560653.exe');
DeleteFile('c:\windows\temp\wpv921277561113.exe');
DeleteFile('c:\windows\temp\wpv931277648030.exe');
DeleteFile('C:\DOCUME~1\9335~1\LOCALS~1\Temp\eeewmdkcvrgat.sys');
DeleteFile('C:\Documents and Settings\LocalService\Application Data\Microsoft\wufout.exe');
DeleteFile('C:\Documents and Settings\Администратор.SERVER\Application Data\yftza.exe');
DeleteFile('C:\WINDOWS\system32\sysnkey32.exe');
DeleteFile('C:\WINDOWS\system32\userini.exe');
DeleteFile('c:\windows\explorer.exe:userini.exe:$DATA');
DeleteFile('H:\autorun.inf');
DeleteFile('H:\check.exe');
DeleteFile('C:\Documents and Settings\Администратор.SERVER\Application Data\ibnzs.exe');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run-','tycoo');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run-','tycoo');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Dr.Watson');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','userini');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run-','userini');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','userini');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','userini');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run-','userini');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','userini');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon','Taskman');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 1);
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
После выполнения скрипта компьютер перезагрузится! Пришлите карантин по ссылке согласно правил