Код:
begin
SearchRootkit(true,true);
SetAVZGuardStatus(true);
QuarantineFile('F:\slncpubqvi.bat','');
QuarantineFile('F:\autorun.inf','');
QuarantineFile('E:\slncpubqvi.bat','');
QuarantineFile('E:\autorun.inf','');
QuarantineFile('D:\slncpubqvi.bat','');
QuarantineFile('D:\autorun.inf','');
QuarantineFile('C:\slncpubqvi.bat','');
QuarantineFile('C:\autorun.inf','');
TerminateProcessByName('c:\temp\vjgqy.exe');
QuarantineFile('c:\temp\vjgqy.exe','');
QuarantineFile('C:\WINDOWS\system32\zzieykyugaefxlbal.exe','');
QuarantineFile('C:\WINDOWS\system32\tvgeaoecqmsvpfxylny.exe','');
QuarantineFile('C:\WINDOWS\system32\ijtqlynkxsxzshyykl.exe','');
QuarantineFile('C:\WINDOWS\system32\gjvurgxwliptofyaordc.exe','');
QuarantineFile('C:\Temp\tvgeaoecqmsvpfxylny.exe','');
QuarantineFile('C:\Temp\srzunylgrknnerge.exe .','');
QuarantineFile('C:\Temp\ijtqlynkxsxzshyykl.exe','');
TerminateProcessByName('c:\windows\system32\srzunylgrknnerge.exe');
QuarantineFile('c:\windows\system32\srzunylgrknnerge.exe','');
DeleteFile('c:\windows\system32\srzunylgrknnerge.exe');
DeleteFile('c:\temp\vjgqy.exe');
DeleteFile('C:\Temp\ijtqlynkxsxzshyykl.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','kfjapwfwdsrn');
DeleteFile('C:\Temp\srzunylgrknnerge.exe .');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','zzieykyugaefxlbal');
DeleteFile('C:\Temp\tvgeaoecqmsvpfxylny.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ijtqlynkxsxzshyykl');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','nhkaoucsymk');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','jfkcsakckaaxl');
DeleteFile('C:\WINDOWS\system32\gjvurgxwliptofyaordc.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','nlsmeoauewyxnzn');
DeleteFile('C:\WINDOWS\system32\ijtqlynkxsxzshyykl.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','jfkcsakckaaxl');
DeleteFile('C:\WINDOWS\system32\tvgeaoecqmsvpfxylny.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','srzunylgrknnerge');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','khngxgrktkljyj');
DeleteFile('C:\WINDOWS\system32\zzieykyugaefxlbal.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','kfjapwfwdsrn');
QuarantineFile('C:\Program Files\Ask.com\UpdateTask.exe','');
QuarantineFile('C:\Program Files\Ask.com\GenericAskToolbar.dll','');
DeleteFile('C:\Program Files\Ask.com\GenericAskToolbar.dll');
DeleteFile('C:\Program Files\Ask.com\UpdateTask.exe');
DeleteFile('C:\autorun.inf');
DeleteFile('C:\slncpubqvi.bat');
DeleteFile('D:\autorun.inf');
DeleteFile('D:\slncpubqvi.bat');
DeleteFile('E:\autorun.inf');
DeleteFile('E:\slncpubqvi.bat');
DeleteFile('F:\autorun.inf');
DeleteFile('F:\slncpubqvi.bat');
DeleteFileMask('c:\temp', '*.*', true);
DeleteFileMask('C:\Program Files\Ask.com', '*.*', true);
DeleteDirectory('C:\Program Files\Ask.com');
DeleteFile('C:\Windows\Tasks\Scheduled Update for Ask Toolbar.job');
DelCLSID('D4027C7F-154A-4066-A1AD-4243D8127440');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
Закачайте карантин по красной ссылке вверху. Повторите логи