Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
RegKeyResetSecurity('HKLM', 'SYSTEM\CurrentControlSet\Services\fdsknn');
RegKeyResetSecurity('HKLM', 'SYSTEM\CurrentControlSet\Services\fdsknn\Parameters');
RegKeyResetSecurity('HKLM', 'SYSTEM\CurrentControlSet\Services\wwuvcz');
RegKeyResetSecurity('HKLM', 'SYSTEM\CurrentControlSet\Services\wwuvcz\Parameters');
RegKeyResetSecurity('HKLM', 'SYSTEM\CurrentControlSet\Services\zvsjaufp');
RegKeyResetSecurity('HKLM', 'SYSTEM\CurrentControlSet\Services\zvsjaufp\Parameters');
RegKeyStrParamWrite('HKLM', 'SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon', 'UserInit', GetEnvironmentVariable('SystemRoot')+'\system32\userinit.exe,');
QuarantineFile('C:\WINDOWS\system32\SSVICHOSST.exe','');
QuarantineFile('C:\WINDOWS\system32\woujiqu.exe','');
QuarantineFile('C:\WINDOWS\system32\userini.exe','');
QuarantineFile('C:\WINDOWS\system32\sshnas21.dll','');
QuarantineFile('C:\WINDOWS\system32\servises.exe','');
QuarantineFile('C:\WINDOWS\system32\rmv.exe','');
QuarantineFile('C:\WINDOWS\system32\csrcs.exe','');
QuarantineFile('C:\WINDOWS\Grezua.exe','');
QuarantineFile('C:\Documents and Settings\LocalService\Application Data\Microsoft\woujiqu.exe','');
QuarantineFile('C:\Documents and Settings\LocalService\Application Data\Microsoft\fodannussas.exe','');
QuarantineFile('C:\Documents and Settings\-\Главное меню\Программы\Автозагрузка\siszpe32.exe','');
QuarantineFile('C:\DOCUME~1\-\LOCALS~1\Temp\Gzh.exe','');
QuarantineFile('C:\WINDOWS\system32\drivers\oreans32.sys','');
QuarantineFile('C:\WINDOWS\system32\srvany.exe','');
QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe','');
QuarantineFile('C:\Documents and Settings\LocalService\Application Data\Microsoft\voobo.exe','');
QuarantineFile('C:\Documents and Settings\LocalService\Application Data\Microsoft\welu.exe','');
QuarantineFile('c:\windows\system32\..\svchost.exe','');
QuarantineFile('C:\WINDOWS\system32\Drivers\wwuvcz.sys','');
QuarantineFile('C:\WINDOWS\system32\Drivers\fdsknn.sys','');
DeleteService('MyWebSearchService');
DeleteService('abp470n5');
DeleteService('Reset 5');
DeleteService('kue5ei32aaomuqog');
DeleteService('azlo2uay');
DeleteService('msupdate');
DeleteFile('C:\WINDOWS\system32\Drivers\fdsknn.sys');
DeleteFile('C:\WINDOWS\system32\Drivers\wwuvcz.sys');
DeleteFile('c:\windows\system32\..\svchost.exe');
DeleteFile('C:\Documents and Settings\LocalService\Application Data\Microsoft\welu.exe');
DeleteFile('C:\WINDOWS\system32\SSVICHOSST.exe');
DeleteFile('C:\Documents and Settings\LocalService\Application Data\Microsoft\voobo.exe');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe');
DeleteFile('C:\WINDOWS\system32\srvany.exe');
DeleteFile('C:\WINDOWS\system32\drivers\mnkpvn.sys');
DeleteFile('C:\DOCUME~1\-\LOCALS~1\Temp\Gzh.exe');
DeleteFile('C:\Documents and Settings\-\Главное меню\Программы\Автозагрузка\siszpe32.exe');
DeleteFile('C:\Documents and Settings\LocalService\Application Data\Microsoft\fodannussas.exe');
DeleteFile('C:\Documents and Settings\LocalService\Application Data\Microsoft\woujiqu.exe');
DeleteFile('C:\WINDOWS\Grezua.exe');
DeleteFile('C:\WINDOWS\system32\csrcs.exe');
DeleteFile('C:\WINDOWS\system32\rmv.exe');
DeleteFile('C:\WINDOWS\system32\servises.exe');
DeleteFile('C:\WINDOWS\system32\sshnas21.dll');
DeleteFile('C:\WINDOWS\system32\userini.exe');
DeleteFile('C:\WINDOWS\system32\woujiqu.exe');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','vegise');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','vegise');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','WEK9EMDHI9');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','roukooju');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','roukooju');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','roukooju');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','vahodooqu');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunServices','roukooju');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunServices','vegise');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\SSHNAS\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','csrcs');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','userini');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','userini');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','servises');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','servises');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','YVIBBBHA8C');
DeleteFile('C:\Windows\Tasks\At1.job');
DeleteFile('C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job');
DeleteFile('C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
После выполнения скрипта компьютер перезагрузится! Пришлите карантин по ссылке согласно правил