Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ClearQuarantine;
QuarantineFile('G:\DOCUME~1\NETWOR~1\APPLIC~1\knwwf\klbwx.map','');
QuarantineFile('G:\WINDOWS\WINMSWRO.EXE','');
QuarantineFile('g:\windows\system32\vpwjd.ref','');
QuarantineFile('G:\Program Files\Common Files\1.exe','');
QuarantineFile('G:\Program Files\Internet Explorer\DD.dll','');
QuarantineFile('G:\WINDOWS\Cursors\beifen.exe','');
QuarantineFile('G:\WINDOWS\klls.exe','');
QuarantineFile('G:\WINDOWS\system\nb9ming32c090423.dll','');
QuarantineFile('G:\WINDOWS\system32\4.exe','');
QuarantineFile('G:\WINDOWS\system32\aIpRQB.exe','');
QuarantineFile('G:\WINDOWS\system32\ApNDF.exe','');
QuarantineFile('G:\WINDOWS\system32\aspx.exe','');
QuarantineFile('G:\WINDOWS\system32\axmfgt.dll','');
QuarantineFile('G:\WINDOWS\system32\caVlk.exe','');
QuarantineFile('G:\WINDOWS\system32\CyEGcPw.exe','');
QuarantineFile('G:\WINDOWS\system32\CyMfdiBpb.exe','');
QuarantineFile('G:\WINDOWS\system32\DAQqdRzSW.exe','');
QuarantineFile('G:\WINDOWS\system32\diPdJZwwt.exe','');
QuarantineFile('G:\WINDOWS\system32\dllcache\mspmsnsv.dll','');
QuarantineFile('G:\WINDOWS\system32\dllcache\ntmssvc.dll','');
QuarantineFile('G:\WINDOWS\system32\dllcache\upnphost.dll','');
QuarantineFile('G:\WINDOWS\system32\dllcache\xmlprov.dll','');
QuarantineFile('G:\WINDOWS\system32\EuVKEoXK.exe','');
QuarantineFile('G:\WINDOWS\system32\FEWOP.exe','');
QuarantineFile('G:\WINDOWS\system32\FglHTFKl.exe','');
QuarantineFile('G:\WINDOWS\system32\gDjxk.exe','');
QuarantineFile('G:\WINDOWS\system32\gfMZNBx.exe','');
QuarantineFile('G:\WINDOWS\system32\HgzhBA.exe','');
QuarantineFile('G:\WINDOWS\system32\hmmQhH.exe','');
QuarantineFile('G:\WINDOWS\system32\hRAxIwzP.exe','');
QuarantineFile('G:\WINDOWS\system32\i\A002.exe','');
QuarantineFile('G:\WINDOWS\system32\i\H001.exe','');
QuarantineFile('G:\WINDOWS\system32\i\I001.exe','');
QuarantineFile('G:\WINDOWS\system32\i\M001.exe','');
QuarantineFile('G:\WINDOWS\system32\iFNnG.exe','');
QuarantineFile('G:\WINDOWS\system32\jncjnhCH.exe','');
QuarantineFile('G:\WINDOWS\system32\KzAAs.exe','');
QuarantineFile('G:\WINDOWS\system32\LujKsgIT.exe','');
QuarantineFile('G:\WINDOWS\system32\MsPMSNSv.dll','');
QuarantineFile('G:\WINDOWS\system32\mstcpweb.dll','');
QuarantineFile('G:\WINDOWS\system32\MZwQddhTS.exe','');
QuarantineFile('G:\WINDOWS\system32\nKwAgi.exe','');
QuarantineFile('G:\WINDOWS\system32\ntmssvc.dll','');
QuarantineFile('G:\WINDOWS\system32\peZSiyJ.exe','');
QuarantineFile('G:\WINDOWS\system32\POHhTSuXt.exe','');
QuarantineFile('G:\WINDOWS\system32\QDzgkhjx.exe','');
QuarantineFile('G:\WINDOWS\system32\qiVvCJKv.exe','');
QuarantineFile('G:\WINDOWS\system32\QQ.exe','');
QuarantineFile('G:\WINDOWS\system32\qWmvi.exe','');
QuarantineFile('G:\WINDOWS\system32\ramPqtcn.exe','');
QuarantineFile('G:\WINDOWS\system32\RKpDHn.exe','');
QuarantineFile('G:\WINDOWS\system32\sPhuwhH.exe','');
QuarantineFile('G:\WINDOWS\system32\SzMJxjnc.exe','');
QuarantineFile('G:\WINDOWS\system32\TXDmvyPy.exe','');
QuarantineFile('G:\WINDOWS\system32\UMGciebb.exe','');
QuarantineFile('G:\WINDOWS\system32\unlRK.exe','');
QuarantineFile('G:\WINDOWS\system32\uVabJS.exe','');
QuarantineFile('G:\WINDOWS\system32\vfGuBaOMn.exe','');
QuarantineFile('G:\WINDOWS\system32\VKQYABp.exe','');
QuarantineFile('G:\WINDOWS\system32\VoNYb.exe','');
QuarantineFile('G:\WINDOWS\system32\vWkwio.exe','');
QuarantineFile('G:\WINDOWS\system32\wbem\fonts.exe','');
QuarantineFile('G:\WINDOWS\system32\wSqeffT.exe','');
QuarantineFile('G:\WINDOWS\system32\wxjzAwlyB.exe','');
QuarantineFile('G:\WINDOWS\system32\xdjDbppq.exe','');
QuarantineFile('G:\WINDOWS\system32\XjTjd.exe','');
QuarantineFile('G:\WINDOWS\system32\xmlprov.dll','');
QuarantineFile('G:\WINDOWS\system32\YlVwFaxNk.exe','');
QuarantineFile('G:\WINDOWS\system32\yRJjzH.exe','');
QuarantineFile('G:\WINDOWS\system32\YspYG.exe','');
QuarantineFile('G:\WINDOWS\system32\ZpmTk.exe','');
QuarantineFile('G:\WINDOWS\Temp\s0.exe','');
QuarantineFile('G:\WINDOWS\Temp\s4.exe','');
BC_ImportALL;
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ClearQuarantine;
DeleteFile('G:\DOCUME~1\NETWOR~1\APPLIC~1\knwwf\klbwx.map');
DeleteFile('G:\WINDOWS\WINMSWRO.EXE');
DeleteFile('g:\windows\system32\vpwjd.ref');
DeleteFile('G:\Program Files\Common Files\1.exe');
DeleteFile('G:\Program Files\Internet Explorer\DD.dll');
DeleteFile('G:\WINDOWS\Cursors\beifen.exe');
DeleteFile('G:\WINDOWS\klls.exe');
DeleteFile('G:\WINDOWS\system\nb9ming32c090423.dll');
DeleteFile('G:\WINDOWS\system32\4.exe');
DeleteFile('G:\WINDOWS\system32\aIpRQB.exe');
DeleteFile('G:\WINDOWS\system32\ApNDF.exe');
DeleteFile('G:\WINDOWS\system32\aspx.exe');
DeleteFile('G:\WINDOWS\system32\axmfgt.dll');
DeleteFile('G:\WINDOWS\system32\caVlk.exe');
DeleteFile('G:\WINDOWS\system32\CyEGcPw.exe');
DeleteFile('G:\WINDOWS\system32\CyMfdiBpb.exe');
DeleteFile('G:\WINDOWS\system32\DAQqdRzSW.exe');
DeleteFile('G:\WINDOWS\system32\diPdJZwwt.exe');
DeleteFile('G:\WINDOWS\system32\dllcache\mspmsnsv.dll');
DeleteFile('G:\WINDOWS\system32\dllcache\ntmssvc.dll');
DeleteFile('G:\WINDOWS\system32\dllcache\upnphost.dll');
DeleteFile('G:\WINDOWS\system32\dllcache\xmlprov.dll');
DeleteFile('G:\WINDOWS\system32\EuVKEoXK.exe');
DeleteFile('G:\WINDOWS\system32\FEWOP.exe');
DeleteFile('G:\WINDOWS\system32\FglHTFKl.exe');
DeleteFile('G:\WINDOWS\system32\gDjxk.exe');
DeleteFile('G:\WINDOWS\system32\gfMZNBx.exe');
DeleteFile('G:\WINDOWS\system32\HgzhBA.exe');
DeleteFile('G:\WINDOWS\system32\hmmQhH.exe');
DeleteFile('G:\WINDOWS\system32\hRAxIwzP.exe');
DeleteFile('G:\WINDOWS\system32\i\A002.exe');
DeleteFile('G:\WINDOWS\system32\i\H001.exe');
DeleteFile('G:\WINDOWS\system32\i\I001.exe');
DeleteFile('G:\WINDOWS\system32\i\M001.exe');
DeleteFile('G:\WINDOWS\system32\iFNnG.exe');
DeleteFile('G:\WINDOWS\system32\jncjnhCH.exe');
DeleteFile('G:\WINDOWS\system32\KzAAs.exe');
DeleteFile('G:\WINDOWS\system32\LujKsgIT.exe');
DeleteFile('G:\WINDOWS\system32\MsPMSNSv.dll');
DeleteFile('G:\WINDOWS\system32\mstcpweb.dll');
DeleteFile('G:\WINDOWS\system32\MZwQddhTS.exe');
DeleteFile('G:\WINDOWS\system32\nKwAgi.exe');
DeleteFile('G:\WINDOWS\system32\ntmssvc.dll');
DeleteFile('G:\WINDOWS\system32\peZSiyJ.exe');
DeleteFile('G:\WINDOWS\system32\POHhTSuXt.exe');
DeleteFile('G:\WINDOWS\system32\QDzgkhjx.exe');
DeleteFile('G:\WINDOWS\system32\qiVvCJKv.exe');
DeleteFile('G:\WINDOWS\system32\QQ.exe');
DeleteFile('G:\WINDOWS\system32\qWmvi.exe');
DeleteFile('G:\WINDOWS\system32\ramPqtcn.exe');
DeleteFile('G:\WINDOWS\system32\RKpDHn.exe');
DeleteFile('G:\WINDOWS\system32\sPhuwhH.exe');
DeleteFile('G:\WINDOWS\system32\SzMJxjnc.exe');
DeleteFile('G:\WINDOWS\system32\TXDmvyPy.exe');
DeleteFile('G:\WINDOWS\system32\UMGciebb.exe');
DeleteFile('G:\WINDOWS\system32\unlRK.exe');
DeleteFile('G:\WINDOWS\system32\uVabJS.exe');
DeleteFile('G:\WINDOWS\system32\vfGuBaOMn.exe');
DeleteFile('G:\WINDOWS\system32\VKQYABp.exe');
DeleteFile('G:\WINDOWS\system32\VoNYb.exe');
DeleteFile('G:\WINDOWS\system32\vWkwio.exe');
DeleteFile('G:\WINDOWS\system32\wbem\fonts.exe');
DeleteFile('G:\WINDOWS\system32\wSqeffT.exe');
DeleteFile('G:\WINDOWS\system32\wxjzAwlyB.exe');
DeleteFile('G:\WINDOWS\system32\xdjDbppq.exe');
DeleteFile('G:\WINDOWS\system32\XjTjd.exe');
DeleteFile('G:\WINDOWS\system32\xmlprov.dll');
DeleteFile('G:\WINDOWS\system32\YlVwFaxNk.exe');
DeleteFile('G:\WINDOWS\system32\yRJjzH.exe');
DeleteFile('G:\WINDOWS\system32\YspYG.exe');
DeleteFile('G:\WINDOWS\system32\ZpmTk.exe');
DeleteFile('G:\WINDOWS\Temp\s0.exe');
DeleteFile('G:\WINDOWS\Temp\s4.exe');
DeleteFileMask('G:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0J23MNOP', '*.*',true);
DeleteFileMask('G:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\4RQQD7IK', '*.*',true);
DeleteFileMask('G:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\AQLD87QC', '*.*',true);
DeleteFileMask('G:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\CS566MVK', '*.*',true);
DeleteFileMask('G:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\R7AL29WT', '*.*',true);
DeleteFileMask('G:\Documents and Settings\Пользователь\Local Settings\Temp', '*.*',true);
BC_ImportALL;
BC_Activate;
ExecuteRepair(9);
RebootWindows(true);
end.
После перезагрузки повторите все 3 лога по правилам.