Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
end;
ClearQuarantine;
TerminateProcessByName('c:\programdata\685d26dc-c30a-434b-bda2-3004e8743669\maintainer.exe');
StopService('{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64');
StopService('{b0aa2e34-2206-4d3d-8f9b-da4d3c817ee7}w64');
StopService('{b082a895-f2bc-40a0-9735-d7592e9e422c}w64');
StopService('{8d2ec2e6-fa06-442e-8979-3f0c417f3c4a}w64');
StopService('{69f4939e-c3db-4f47-938c-0519bbf69309}w64');
StopService('{3254b624-3dc6-470b-b41f-230aff035acc}w64');
StopService('{24e0dbe9-5e04-4423-805e-fc8b4c7506a4}w64');
StopService('{16d667ee-6782-4b21-81df-8ded8ebc3868}Gw64');
StopService('{049bbcc5-fa2f-4f64-ac57-0d003a8907b3}w64');
QuarantineFile('C:\Users\USER\appdata\roaming\x11\a\engine.exe','');
QuarantineFile('C:\Users\USER\AppData\Roaming\YK.exe','');
QuarantineFile('C:\Users\USER\AppData\Roaming\UIUEPY.exe','');
QuarantineFile('C:\iexplore.bat','');
QuarantineFile('C:\Users\USER\AppData\Roaming\cppredistx86.exe','');
QuarantineFile('C:\Users\USER\AppData\Roaming\Microsoft\Windows\IEUpdate\autochk.exe','');
QuarantineFile('C:\Program Files (x86)\Google\chrome.bat','');
QuarantineFile('C:\Windows\system32\drivers\{fee70205-e9b9-40aa-9da7-7766876eede2}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{b0aa2e34-2206-4d3d-8f9b-da4d3c817ee7}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{b082a895-f2bc-40a0-9735-d7592e9e422c}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{8d2ec2e6-fa06-442e-8979-3f0c417f3c4a}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{69f4939e-c3db-4f47-938c-0519bbf69309}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{3254b624-3dc6-470b-b41f-230aff035acc}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{24e0dbe9-5e04-4423-805e-fc8b4c7506a4}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{049bbcc5-fa2f-4f64-ac57-0d003a8907b3}w64.sys','');
QuarantineFile('c:\programdata\685d26dc-c30a-434b-bda2-3004e8743669\maintainer.exe','');
DeleteFile('c:\programdata\685d26dc-c30a-434b-bda2-3004e8743669\maintainer.exe','32');
DeleteFile('C:\Windows\system32\drivers\{049bbcc5-fa2f-4f64-ac57-0d003a8907b3}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{24e0dbe9-5e04-4423-805e-fc8b4c7506a4}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{3254b624-3dc6-470b-b41f-230aff035acc}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{69f4939e-c3db-4f47-938c-0519bbf69309}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{8d2ec2e6-fa06-442e-8979-3f0c417f3c4a}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{b082a895-f2bc-40a0-9735-d7592e9e422c}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{b0aa2e34-2206-4d3d-8f9b-da4d3c817ee7}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{fee70205-e9b9-40aa-9da7-7766876eede2}w64.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\BAPIDRV64.sys','32');
DeleteFile('C:\Windows\system32\drivers\ttnfd.sys','32');
DeleteFile('C:\Program Files (x86)\Google\chrome.bat','32');
DeleteFile('C:\Users\USER\AppData\Roaming\Microsoft\Windows\IEUpdate\autochk.exe','32');
DeleteFile('C:\Users\USER\AppData\Roaming\cppredistx86.exe','32');
DeleteFile('C:\iexplore.bat','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP1.job','64');
DeleteFile('C:\Windows\Tasks\APSnotifierPP2.job','64');
DeleteFile('C:\Windows\Tasks\APSnotifierPP3.job','64');
DeleteFile('C:\Windows\Tasks\FF Watcher {C693C4AC-FF04-4DA5-80E3-B496D609E5D3}.job','64');
DeleteFile('C:\Windows\Tasks\UIUEPY.job','64');
DeleteFile('C:\Windows\Tasks\YK.job','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP1','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP2','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP3','64');
DeleteFile('C:\Windows\system32\Tasks\ASP','64');
DeleteFile('C:\Windows\system32\Tasks\DealPlyUpdate','64');
DeleteFile('C:\Windows\system32\Tasks\FF Watcher {C693C4AC-FF04-4DA5-80E3-B496D609E5D3}','64');
DeleteFile('C:\Windows\system32\Tasks\{D7EBDD6D-69D9-4DB0-B08D-EFC14811EFC4}','64');
DeleteFile('C:\Users\USER\appdata\roaming\x11\a\engine.exe','32');
DeleteFile('C:\Users\USER\appdata\roaming\uiuepy.exe','32');
DeleteFile('C:\Users\USER\appdata\roaming\yk.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer','Run');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Microsoft Visual C++ 2010','command');
DeleteService('ttnfd');
DeleteService('BAPIDRV');
DeleteService('{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64');
DeleteService('{b0aa2e34-2206-4d3d-8f9b-da4d3c817ee7}w64');
DeleteService('{b082a895-f2bc-40a0-9735-d7592e9e422c}w64');
DeleteService('{8d2ec2e6-fa06-442e-8979-3f0c417f3c4a}w64');
DeleteService('{69f4939e-c3db-4f47-938c-0519bbf69309}w64');
DeleteService('{3254b624-3dc6-470b-b41f-230aff035acc}w64');
DeleteService('{24e0dbe9-5e04-4423-805e-fc8b4c7506a4}w64');
DeleteService('{16d667ee-6782-4b21-81df-8ded8ebc3868}Gw64');
DeleteService('{049bbcc5-fa2f-4f64-ac57-0d003a8907b3}w64');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Код:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=a92e6d07055badccea4a151e74da68d8&text={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=a92e6d07055badccea4a151e74da68d8&text={searchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1410965110&from=cor&uid=WDCXWD5000AZRX-00A8LB0_WD-WMC1U203780737807&q={searchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1410965110&from=cor&uid=WDCXWD5000AZRX-00A8LB0_WD-WMC1U203780737807&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://webalta.ru/search
O2 - BHO: (no name) - {D5FEC983-01DB-414a-9456-AF95AC9ED7B5} - (no file)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O2 - BHO: (no name) - {EF7BD87A-8024-11E2-F316-F3E56188709B} - (no file)
O3 - Toolbar: (no name) - {09900DE8-1DCA-443F-9243-26FF581438AF} - (no file)
O3 - Toolbar: (no name) - {91397D20-1446-11D4-8AF4-0040CA1127B6} - (no file)
O4 - Global Startup: o9g3DPcAmFegp-Wh83knEyPzwRKCvibJR-x64F0oThU=.xtbl
Сделайте повторные логи по