Moderator: Moderators
begin
QuarantineFile('brastk.exe','');
QuarantineFile('C:\WINDOWS\svcho.exe','');
QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe','');
QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL','');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe');
DeleteFile('C:\WINDOWS\svcho.exe');
BC_DeleteFile('brastk.exe');
RebootWindows(true);
end.begin
SetAVZPMStatus(True);
RebootWindows(true);
end.begin
SearchRootkit(true, true);
QuarantineFile('C:\WINDOWS\system32\brastk.exe','');
QuarantineFile('C:\WINDOWS\svcho.exe','');
QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe','');
QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL','');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe');
DeleteFile('C:\WINDOWS\svcho.exe');
DeleteFile('C:\WINDOWS\system32\brastk.exe')
DelAutorunByFileName('brastk.exe');
DelAutorunByFileName('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL');
DelAutorunByFileName('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe');
DelAutorunByFileName('C:\WINDOWS\svcho.exe');
BC_ImportDeletedList;
BC_LogFile(GetAVZDirectory + 'boot_clr.log');
BC_Activate;
ExecuteSysClean;
SaveLog(GetAVZDirectory + 'avz_log.txt');
RebootWindows(true);
end.begin
SearchRootkit(true, true);
QuarantineFile('C:\WINDOWS\system32\brastk.exe','');
QuarantineFile('C:\WINDOWS\svcho.exe','');
QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe','');
QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL','');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL');
DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe');
DeleteFile('C:\WINDOWS\svcho.exe');
DeleteFile('C:\WINDOWS\system32\brastk.exe');
DelAutorunByFileName('brastk.exe');
DelAutorunByFileName('C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL');
DelAutorunByFileName('C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe');
DelAutorunByFileName('C:\WINDOWS\svcho.exe');
BC_ImportDeletedList;
BC_LogFile(GetAVZDirectory + 'boot_clr.log');
BC_Activate;
ExecuteSysClean;
SaveLog(GetAVZDirectory + 'avz_log.txt');
RebootWindows(true);
end.File::
c:\windows\system32\TDSSfpho.dll
c:\program files\Common Files\diqixop.db
c:\program files\Common Files\bobawe.sys
c:\program files\Common Files\ysirolafe.exe
c:\program files\Common Files\fusaje.inf
c:\program files\Common Files\vekeky.scr
c:\program files\Common Files\yzemoqop.bin
c:\program files\Common Files\vajis.sys
Users browsing this forum: No registered users and 1 guest