Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ClearQuarantine;
TerminateProcessByName('c:\documents and settings\Владелец\application data\nethosts2.exe');
TerminateProcessByName('c:\documents and settings\Владелец\local settings\temp\kxfjmqzl.exe');
TerminateProcessByName('c:\documents and settings\Владелец\msdata\explorer.exe');
TerminateProcessByName('c:\documents and settings\Владелец\local settings\temp\cwaomsgg.exe');
TerminateProcessByName('c:\documents and settings\Владелец\application data\cmdhost0.exe');
TerminateProcessByName('c:\documents and settings\Владелец\application data\a2092652348.exe');
TerminateProcessByName('c:\documents and settings\Владелец\application data\a-2079576971.exe');
QuarantineFile('C:\WINDOWS\system32\63.exe','');
QuarantineFile('C:\WINDOWS\system32\52.exe','');
QuarantineFile('C:\WINDOWS\system32\51.exe','');
QuarantineFile('C:\WINDOWS\system32\46.exe','');
QuarantineFile('C:\WINDOWS\system32\44.exe','');
QuarantineFile('C:\WINDOWS\system32\43.exe','');
QuarantineFile('C:\WINDOWS\system32\41.exe','');
QuarantineFile('C:\WINDOWS\system32\34.exe','');
QuarantineFile('C:\WINDOWS\system32\33.exe','');
QuarantineFile('C:\WINDOWS\system32\27.exe','');
QuarantineFile('C:\WINDOWS\system32\23.exe','');
QuarantineFile('C:\WINDOWS\system32\22.exe','');
QuarantineFile('C:\WINDOWS\system32\20.exe','');
QuarantineFile('C:\WINDOWS\system32\18.exe','');
QuarantineFile('C:\WINDOWS\system32\12.exe','');
QuarantineFile('C:\WINDOWS\system32\08.exe','');
QuarantineFile('C:\WINDOWS\system32\06.exe','');
QuarantineFile('C:\WINDOWS\system32\02.exe','');
QuarantineFile('C:\WINDOWS\system32\00.exe','');
QuarantineFile('C:\Documents and Settings\Владелец\Мои документы\Windows\svchoster_update.exe','');
QuarantineFile('C:\Documents and Settings\Владелец\Мои документы\Windows\newhost.exe','');
QuarantineFile('C:\Documents and Settings\Владелец\msdata\iexplorer.exe','');
QuarantineFile('C:\Documents and Settings\Владелец\msdata\comodesr.exe','');
QuarantineFile('C:\Documents and Settings\Владелец\Local Settings\Temp\znatdvje.exe','');
QuarantineFile('C:\Documents and Settings\Владелец\Local Settings\Temp\upjesmoo.exe','');
QuarantineFile('C:\Documents and Settings\Владелец\Local Settings\Temp\palwavgi.exe','');
QuarantineFile('C:\WINDOWS\system32\01.tmp','');
QuarantineFile('c:\documents and settings\Владелец\application data\nethosts2.exe','');
QuarantineFile('c:\documents and settings\Владелец\local settings\temp\kxfjmqzl.exe','');
QuarantineFile('c:\documents and settings\Владелец\msdata\explorer.exe','');
QuarantineFile('c:\documents and settings\Владелец\local settings\temp\cwaomsgg.exe','');
QuarantineFile('c:\documents and settings\Владелец\application data\cmdhost0.exe','');
QuarantineFile('c:\documents and settings\Владелец\application data\a2092652348.exe','');
QuarantineFile('c:\documents and settings\Владелец\application data\a-2079576971.exe','');
DeleteFile('c:\documents and settings\Владелец\msdata\explorer.exe');
DeleteFile('C:\WINDOWS\system32\01.tmp');
DeleteFile('C:\Documents and Settings\Владелец\Application Data\A-2079576971.exe');
DeleteFile('C:\Documents and Settings\Владелец\Application Data\A2092652348.exe');
DeleteFile('C:\Documents and Settings\Владелец\Application Data\CMDHost0.exe');
DeleteFile('C:\Documents and Settings\Владелец\Application Data\Nethosts2.exe');
DeleteFile('C:\Documents and Settings\Владелец\Local Settings\Temp\cwaomsgg.exe');
DeleteFile('C:\Documents and Settings\Владелец\Local Settings\Temp\kxfjmqzl.exe');
DeleteFile('C:\Documents and Settings\Владелец\Local Settings\Temp\palwavgi.exe');
DeleteFile('C:\Documents and Settings\Владелец\Local Settings\Temp\upjesmoo.exe');
DeleteFile('C:\Documents and Settings\Владелец\Local Settings\Temp\znatdvje.exe');
DeleteFile('C:\Documents and Settings\Владелец\msdata\comodesr.exe');
DeleteFile('C:\Documents and Settings\Владелец\msdata\iexplorer.exe');
DeleteFile('C:\Documents and Settings\Владелец\Мои документы\Windows\newhost.exe');
DeleteFile('C:\Documents and Settings\Владелец\Мои документы\Windows\svchoster_update.exe');
DeleteFile('C:\WINDOWS\system32\00.exe');
DeleteFile('C:\WINDOWS\system32\02.exe');
DeleteFile('C:\WINDOWS\system32\06.exe');
DeleteFile('C:\WINDOWS\system32\08.exe');
DeleteFile('C:\WINDOWS\system32\12.exe');
DeleteFile('C:\WINDOWS\system32\18.exe');
DeleteFile('C:\WINDOWS\system32\20.exe');
DeleteFile('C:\WINDOWS\system32\22.exe');
DeleteFile('C:\WINDOWS\system32\23.exe');
DeleteFile('C:\WINDOWS\system32\27.exe');
DeleteFile('C:\WINDOWS\system32\33.exe');
DeleteFile('C:\WINDOWS\system32\34.exe');
DeleteFile('C:\WINDOWS\system32\41.exe');
DeleteFile('C:\WINDOWS\system32\43.exe');
DeleteFile('C:\WINDOWS\system32\44.exe');
DeleteFile('C:\WINDOWS\system32\46.exe');
DeleteFile('C:\WINDOWS\system32\51.exe');
DeleteFile('C:\WINDOWS\system32\52.exe');
DeleteFile('C:\WINDOWS\system32\63.exe');
DeleteFile('C:\WINDOWS\system32\66.exe');
DeleteFile('C:\WINDOWS\system32\70.exe');
DeleteFile('C:\WINDOWS\system32\72.exe');
DeleteFile('C:\WINDOWS\system32\74.exe');
DeleteFile('C:\WINDOWS\system32\81.exe');
DeleteFile('C:\WINDOWS\system32\82.exe');
DeleteFile('C:\WINDOWS\system32\83.exe');
DeleteFile('C:\WINDOWS\system32\87.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','A-2079576971');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','A-2079576971.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','A-2079576971');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','A2092652348');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','A2092652348');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','CMDHost');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Nethosts');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','cwaomsgg.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','kxfjmqzl.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Winlogon');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','upjesmoo.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ECM');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','comodesr.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Windows Explorer');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Windows Explorer');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Nethost');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Winsvchost1');
DeleteService('vxhhi');
DeleteService('thjroyu');
DeleteService('pplaio');
DeleteService('pmtbnhxn');
DeleteService('lutdkma');
DeleteService('fhrrainia');
DeleteService('ffxvf');
DeleteService('drhqm');
DeleteService('cvtht');
DeleteService('cqchetku');
DeleteFileMask('c:\documents and settings\Владелец\msdata','*',true);
DeleteDirectory('c:\documents and settings\Владелец\msdata');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.