Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
RegKeyStrParamWrite('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon','UserInit', GetEnvironmentVariable ('WinDir')+'\System32\userinit.exe,');
QuarantineFile('services32.exe','');
QuarantineFile('C:\Windows\services32.exe','');
QuarantineFile('C:\Windows\Temp\6529852.exe','');
QuarantineFile('C:\Windows\Temp\46032024.exe','');
QuarantineFile('C:\Windows\Temp\3001334.exe','');
QuarantineFile('C:\Windows\Temp\173994.exe','');
QuarantineFile('C:\Windows\Temp\1630740.exe','');
QuarantineFile('C:\Windows\Temp\1378908.exe','');
DeleteService('DnsServer_11');
DeleteService('srvsysdriver32');
DeleteService('srviecheck');
DeleteService('ddservice');
QuarantineFile('C:\Windows\systemup.exe','');
QuarantineFile('C:\Windows\sysdriver32.exe','');
QuarantineFile('C:\Windows\l1rezerv.exe','');
QuarantineFile('C:\Windows\killwindtitle.exe','');
QuarantineFile('C:\Windows\av_soft.exe','');
QuarantineFile('C:\Windows\dns.exe','');
QuarantineFile('c:\windows\winexp.exe','');
TerminateProcessByName('c:\windows\winexp.exe');
QuarantineFile('c:\windows\w_distrib.exe','');
TerminateProcessByName('c:\windows\w_distrib.exe');
QuarantineFile('c:\windows\systemup.exe','');
TerminateProcessByName('c:\windows\systemup.exe');
QuarantineFile('c:\windows\sysdriver32.exe','');
TerminateProcessByName('c:\windows\sysdriver32.exe');
QuarantineFile('c:\windows\update.1\svchost.exe','');
TerminateProcessByName('c:\windows\update.1\svchost.exe');
QuarantineFile('c:\windows\update.2\svchost.exe','');
TerminateProcessByName('c:\windows\update.2\svchost.exe');
QuarantineFile('c:\windows\system32\pnkbstra.exe','');
QuarantineFile('c:\windows\l1rezerv.exe','');
TerminateProcessByName('c:\windows\l1rezerv.exe');
QuarantineFile('c:\windows\killwindtitle.exe','');
TerminateProcessByName('c:\windows\killwindtitle.exe');
QuarantineFile('c:\windows\dns.exe','');
TerminateProcessByName('c:\windows\dns.exe');
QuarantineFile('c:\windows\av_soft.exe','');
TerminateProcessByName('c:\windows\av_soft.exe');
DeleteFile('c:\windows\av_soft.exe');
DeleteFile('c:\windows\dns.exe');
DeleteFile('c:\windows\killwindtitle.exe');
DeleteFile('c:\windows\l1rezerv.exe');
DeleteFile('c:\windows\update.2\svchost.exe');
DeleteFile('c:\windows\update.1\svchost.exe');
DeleteFile('c:\windows\sysdriver32.exe');
DeleteFile('c:\windows\systemup.exe');
DeleteFile('c:\windows\w_distrib.exe');
DeleteFile('c:\windows\winexp.exe');
DeleteFile('C:\Windows\dns.exe');
DeleteFile('C:\Windows\av_soft.exe');
DeleteFile('C:\Windows\l1rezerv.exe');
DeleteFile('C:\Windows\sysdriver32.exe');
DeleteFile('C:\Windows\systemup.exe');
DeleteFile('C:\Windows\update.1\svchost.exe');
DeleteFile('C:\Windows\update.2\svchost.exe');
DeleteFile('C:\Windows\w_distrib.exe');
DeleteFile('C:\Windows\winexp.exe');
DeleteFile('C:\Windows\Temp\1378908.exe');
DeleteFile('C:\Windows\Temp\1630740.exe');
DeleteFile('C:\Windows\Temp\173994.exe');
DeleteFile('C:\Windows\Temp\3001334.exe');
DeleteFile('C:\Windows\Temp\46032024.exe');
DeleteFile('C:\Windows\Temp\6529852.exe');
DeleteFile('C:\Windows\killwindtitle.exe');
DeleteFile('C:\Windows\services32.exe');
DeleteFile('C:\Windows\sysdriver32_.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','sysdriver32_.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','sysdriver32.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','wxpdrv');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','l1rezerv.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','killwindtitle.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','av_soft.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','6529852.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','46032024.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','3001334.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','173994.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','delzipdrivers');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','1378908.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','systemup');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','w_distrib.exe');
DeleteFile('services32.exe');
BC_ImportAll;
ExecuteSysClean;
ExecuteWizard('TSW', 2, 2, true);
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.
После перезагрузки: