Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
StopService('Passthru');
StopService('MyWebSearchService');
StopService('cblyefry');
StopService('buoiajryeeyina');
RegKeyParamDel('HKEY_USERS','S-1-5-21-842925246-1844237615-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run','Startup');
RegKeyParamDel('HKEY_USERS','S-1-5-21-842925246-1844237615-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run','or4VRheh1aqLTOEeQEbGuXcOEf');
RegKeyParamDel('HKEY_USERS','S-1-5-21-842925246-1844237615-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run','MyWebSearch Email Plugin');
RegKeyParamDel('HKEY_USERS','S-1-5-21-842925246-1844237615-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run','MSWUpdate');
RegKeyParamDel('HKEY_USERS','S-1-5-21-842925246-1844237615-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Corp');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','jasuru');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','jasuru');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','WinSVC');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','svchost32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','SuIaOfBkW1FndOp');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','MyWebSearch Email Plugin');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','My Web Search Bar Search Scope Monitor');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','MSWUpdate');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Windows Network');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Corp');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','jykuzif');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','jasuru');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Microsoft Corp');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbssreg','DLLName');
QuarantineFile('Explorer.exe C:\Documents and Settings\David1\Application Data\lsass.exe','');
QuarantineFile('C:\WINDOWS\WinSVC.exe','');
QuarantineFile('C:\WINDOWS\system32\wono.exe','');
QuarantineFile('C:\WINDOWS\system32\vydoha.exe','');
QuarantineFile('C:\WINDOWS\system32\rupywer.exe','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\ndisvvan.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\cblyefry.sys','');
QuarantineFile('C:\WINDOWS\system32\Drivers\cblyefry.sys','');
QuarantineFile('C:\WINDOWS\raidhost.exe','');
QuarantineFile('C:\WINDOWS\Egezib.exe','');
QuarantineFile('C:\SYSTEMFILES\x-f-324553-12314-3344-1\ise32.exe','');
QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe','');
QuarantineFile('C:\Documents and Settings\LocalService\Application Data\Microsoft\wono.exe','');
QuarantineFile('C:\Documents and Settings\David1\Application Data\svchosts.exe','');
QuarantineFile('C:\Documents and Settings\David1\Application Data\svchost32.exe','');
QuarantineFile('C:\Documents and Settings\David1\Application Data\Microsoft\svchost.exe','');
QuarantineFile('C:\Documents and Settings\David1\Application Data\lsass.exe','');
QuarantineFile('C:\Documents and Settings\David1\Application Data\IvDUA.exe','');
QuarantineFile('C:\Documents and Settings\David1\Application Data\Driver.exe','');
QuarantineFile('C:\Documents and Settings\David1\Application Data\bywsf.exe','');
QuarantineFile('C:\Documents and Settings\All Users\Documents\Settings\cbss.dll','');
DeleteService('Passthru');
DeleteService('MyWebSearchService');
DeleteService('cblyefry');
DeleteService('buoiajryeeyina');
DeleteFile('Explorer.exe C:\Documents and Settings\David1\Application Data\lsass.exe');
DeleteFile('C:\WINDOWS\WinSVC.exe');
DeleteFile('C:\windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job');
DeleteFile('C:\WINDOWS\system32\wono.exe');
DeleteFile('C:\WINDOWS\system32\vydoha.exe');
DeleteFile('C:\WINDOWS\system32\rupywer.exe');
DeleteFile('C:\WINDOWS\system32\DRIVERS\ndisvvan.sys');
DeleteFile('C:\WINDOWS\system32\Drivers\cblyefry.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\cblyefry.sys');
DeleteFile('C:\WINDOWS\raidhost.exe');
DeleteFile('C:\WINDOWS\Egezib.exe');
DeleteFile('C:\SYSTEMFILES\x-f-324553-12314-3344-1\ise32.exe');
DeleteFile('C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe');
DeleteFile('C:\Documents and Settings\LocalService\Application Data\Microsoft\wono.exe');
DeleteFile('C:\Documents and Settings\David1\Application Data\svchosts.exe');
DeleteFile('C:\Documents and Settings\David1\Application Data\svchost32.exe');
DeleteFile('C:\Documents and Settings\David1\Application Data\Microsoft\svchost.exe');
DeleteFile('C:\Documents and Settings\David1\Application Data\lsass.exe');
DeleteFile('C:\Documents and Settings\David1\Application Data\IvDUA.exe');
DeleteFile('C:\Documents and Settings\David1\Application Data\Driver.exe');
DeleteFile('C:\Documents and Settings\David1\Application Data\bywsf.exe');
DeleteFile('C:\Documents and Settings\All Users\Documents\Settings\cbss.dll');
DelBHO('{00A6FAF6-072E-44cf-8957-5838F569A31D}');
BC_DeleteSvc('Passthru');
BC_DeleteSvc('MyWebSearchService');
BC_DeleteSvc('cblyefry');
BC_DeleteSvc('buoiajryeeyina');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
After reboot: