Код:
begin
SearchRootkit(true, true);
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\yodrive32.exe','');
QuarantineFile('C:\WINDOWS\yadrive32.exe','');
QuarantineFile('C:\WINDOWS\csdrive32.exe','');
QuarantineFile('C:\WINDOWS\system32\wbluel.dll','');
QuarantineFile('C:\WINDOWS\system32\NVWRSRU.DLL','');
QuarantineFile('C:\WINDOWS\ResPatch\Selector.exe','');
QuarantineFile('C:\WINDOWS\ResPatch\Set_logo.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1830\zaberg.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-12341\newcont4rnd3.exe,','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-14699\brenasa.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1830\zaberg.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-12356\newcont6rnd5.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-12367\newcont7rnd6.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-12387\newcont8rnd7.exe,','');
QuarantineFileF('C:\RECYCLER\','*newcont*.exe', true,'',0 ,0);
QuarantineFileF('C:\Documents and Settings\йа!\','*.exe', false,'',0 ,0);
QuarantineFile('C:\Documents and Settings\йа!\nvrnvw.exe','');
QuarantineFile('C:\Documents and Settings\йа!\Application Data\Wtlolk.scr','');
QuarantineFile('C:\Documents and Settings\йа!\5user.exe','');
QuarantineFile('C:\WINDOWS\csdrive32.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1830\zaberg.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12341\newcont4rnd3.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-14699\brenasa.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12356\newcont6rnd5.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12352\newcont5rnd4.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12367\newcont7rnd6.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12387\newcont8rnd7.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12389\newcont9rnd8.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12340\newcont1rnd.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12310\newcont2rnd1.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12330\newcont3rnd2.exe','');
DeleteFile('C:\Documents and Settings\йа!\5user.exe');
DeleteFile('C:\Documents and Settings\йа!\Application Data\Wtlolk.scr');
DeleteFile('C:\Documents and Settings\йа!\nvrnvw.exe');
DeleteFile('C:\WINDOWS\csdrive32.exe');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1830\zaberg.exe');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12341\newcont4rnd3.exe');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-14699\brenasa.exe');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12356\newcont6rnd5.exe');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12352\newcont5rnd4.exe');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12367\newcont7rnd6.exe');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12387\newcont8rnd7.exe');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12389\newcont9rnd8.exe');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12340\newcont1rnd.exe');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12310\newcont2rnd1.exe');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12330\newcont3rnd2.exe');
DeleteFile('C:\WINDOWS\csdrive32.exe');
DeleteFile('C:\WINDOWS\yadrive32.exe');
DeleteFile('C:\WINDOWS\yodrive32.exe');
RegKeyParamDel('HKLM','Software\Microsoft\Windows NT\CurrentVersion\Winlogon','Taskman');
RegKeyIntParamWrite('HKLM', 'SYSTEM\CurrentControlSet\Control', 'WaitToKillServiceTimeout', 20000);
RegKeyIntParamWrite('HKLM','SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer','NoDriveTypeAutoRun', 221);
DeleteFileMask('C:\RECYCLER\', '*newcont*.exe', true);
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteWizard('TSW',2,3,true);
ExecuteWizard('SCU',2,3,true);
RebootWindows(true);
end.