Код:
begin
SetAVZPMStatus(True);
SetAVZGuardStatus(True);
SearchRootkit(true, true);
QuarantineFile('c:\documents and settings\евгений\local settings\temp\C1FEA54C-D36ACB02-4572B5FA-32BDA646\QyUupdzuieu.exe','');
QuarantineFile('C:\DOCUME~1\F8AE~1\LOCALS~1\Temp\NOSEventMessages.dll','');
QuarantineFile('C:\Documents and Settings\Евгений\Local Settings\Temp\NEventMessages.dll','');
SetServiceStart('Znf', 4);
DeleteService('Znf');
StopService('Znf');
StopService('ZAM_Guard');
DeleteService('ZAM_Guard');
SetServiceStart('ZAM_Guard', 4);
SetServiceStart('ZAM', 4);
DeleteService('ZAM');
StopService('ZAM');
QuarantineFile('C:\WINDOWS\system32\drivers\Znf.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\zamguard32.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\zam32.sys','');
DeleteFile('C:\WINDOWS\System32\drivers\zam32.sys','32');
BC_DeleteFile('C:\WINDOWS\System32\drivers\zam32.sys');
DeleteFile('C:\WINDOWS\System32\drivers\zamguard32.sys','32');
BC_DeleteFile('C:\WINDOWS\System32\drivers\zamguard32.sys');
DeleteFile('C:\WINDOWS\system32\drivers\Znf.sys','32');
BC_DeleteFile('C:\WINDOWS\system32\drivers\Znf.sys');
BC_DeleteSvc('ZAM');
BC_DeleteSvc('ZAM_Guard');
BC_DeleteSvc('Znf');
DeleteFile('C:\Documents and Settings\Евгений\Local Settings\Temp\NEventMessages.dll','32');
DeleteFile('C:\DOCUME~1\F8AE~1\LOCALS~1\Temp\NOSEventMessages.dll','32');
BC_DeleteFile('C:\DOCUME~1\F8AE~1\LOCALS~1\Temp\NOSEventMessages.dll');
BC_DeleteFile('c:\documents and settings\евгений\local settings\temp\C1FEA54C-D36ACB02-4572B5FA-32BDA646\QyUupdzuieu.exe');
DeleteFile('c:\documents and settings\евгений\local settings\temp\C1FEA54C-D36ACB02-4572B5FA-32BDA646\QyUupdzuieu.exe','32');
BC_ImportDeletedList;
BC_ImportAll;
ExecuteSysClean;
ExecuteWizard('TSW',2,3,true);
BC_Activate;
RebootWindows(true);
end.
Если зилле руки ноги оторву этими действиями, то переставьте ее
чето мне не нравятся те файлы
Bookmarks