Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
DeleteService('dcj0797');
DeleteService('bah6240');
DeleteService('amg85d4');
QuarantineFile('C:\WINDOWS.0\System32\drivers\bah6240.sys','');
QuarantineFile('C:\WINDOWS.0\System32\drivers\dcj0797.sys','');
DeleteService('icn40cc');
DeleteService('jipf009');
DeleteService('jdo5199');
DeleteService('icn470c');
QuarantineFile('C:\WINDOWS.0\System32\drivers\icn470c.sys','');
QuarantineFile('C:\WINDOWS.0\System32\drivers\jdo5199.sys','');
QuarantineFile('C:\WINDOWS.0\System32\drivers\jipf009.sys','');
QuarantineFile('C:\WINDOWS.0\System32\drivers\kek16c6.sys','');
DeleteService('kek16c6');
DeleteService('nhn0021');
QuarantineFile('C:\WINDOWS.0\System32\drivers\nhn0021.sys','');
QuarantineFile('C:\WINDOWS.0\System32\drivers\qpce214.sys','');
QuarantineFile('C:\WINDOWS.0\System32\drivers\qqcbfc8.sys','');
DeleteService('qqcbfc8');
QuarantineFile('C:\WINDOWS.0\System32\drivers\rmd941d.sys','');
DeleteService('rmd941d');
QuarantineFile('C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Microsoft\Media\svсhоst.exe','');
QuarantineFile('C:\Documents and Settings\Admin.MICROSOF-474548\jovcfv.exe','');
QuarantineFile('C:\Documents and Settings\Admin.MICROSOF-474548\Application Data\vgdoqo.exe,explorer.exe,C:\RECYCLER\S-1-5-21-2490316588-9739061336-784036228-7438\yv8g67.exe','');
QuarantineFile('C:\WINDOWS.0\system32\3sndezp.exe','');
QuarantineFile('C:\WINDOWS.0\system32\3xtezpg.exe','');
QuarantineFile('C:\WINDOWS.0\system32\5qqghm8.exe','');
QuarantineFile('C:\WINDOWS.0\system32\SSVICHOSST.exe','');
QuarantineFile('C:\WINDOWS.0\system32\brsnt66aar.exe','');
QuarantineFile('C:\WINDOWS.0\system32\vvrhhdttpff.exe','');
QuarantineFile('C:\WINDOWS.0\system32\y86k81whidt.exe','');
QuarantineFile('C:\DOCUME~1\ADMIN~1.MIC\LOCALS~1\Temp\hlds_vcrash.exe','');
QuarantineFile('C:\DOCUME~1\ADMIN~1.MIC\LOCALS~1\Temp\svchost.exe','');
QuarantineFile('c:\windows.0\system32\svchost.exe:exe.exe:$DATA','');
QuarantineFile('c:\windows.0\svchost.exe','');
TerminateProcessByName('c:\windows.0\svchost.exe');
TerminateProcessByName('c:\windows.0\system32\lclass.exe');
QuarantineFile('c:\windows.0\system32\lclass.exe','');
DeleteFile('c:\windows.0\system32\lclass.exe');
DeleteFile('c:\windows.0\svchost.exe');
DeleteFile('c:\windows.0\system32\svchost.exe:exe.exe:$DATA');
DeleteFile('C:\DOCUME~1\ADMIN~1.MIC\LOCALS~1\Temp\svchost.exe');
DeleteFile('C:\DOCUME~1\ADMIN~1.MIC\LOCALS~1\Temp\hlds_vcrash.exe');
DeleteFile('C:\WINDOWS.0\system32\y86k81whidt.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','pfgbr');
DeleteFile('C:\WINDOWS.0\system32\vvrhhdttpff.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','mhinje');
DeleteFile('C:\WINDOWS.0\system32\brsnt66aar.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','xnojz');
DeleteFile('C:\WINDOWS.0\system32\SSVICHOSST.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Yahoo Messengger');
DeleteFile('C:\WINDOWS.0\system32\5qqghm8.exe');
DeleteFile('C:\WINDOWS.0\system32\3xtezpg.exe');
DeleteFile('C:\WINDOWS.0\system32\3sndezp.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','rnnyzp7');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','opvfb');
DeleteFile('C:\Documents and Settings\Admin.MICROSOF-474548\Application Data\vgdoqo.exe,explorer.exe,C:\RECYCLER\S-1-5-21-2490316588-9739061336-784036228-7438\yv8g67.exe');
DeleteFile('C:\Documents and Settings\Admin.MICROSOF-474548\jovcfv.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','MSConfig');
DeleteFile('C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Microsoft\Media\svсhоst.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','system');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run-','hlds_vcrash');
DeleteFile('C:\WINDOWS.0\System32\drivers\rmd941d.sys');
DeleteFile('C:\WINDOWS.0\System32\drivers\qqcbfc8.sys');
DeleteFile('C:\WINDOWS.0\System32\drivers\qpce214.sys');
DeleteFile('C:\WINDOWS.0\System32\drivers\nhn0021.sys');
DeleteFile('C:\WINDOWS.0\System32\drivers\kek16c6.sys');
DeleteFile('C:\WINDOWS.0\System32\drivers\jipf009.sys');
DeleteFile('C:\WINDOWS.0\System32\drivers\jdo5199.sys');
DeleteFile('C:\WINDOWS.0\System32\drivers\icn470c.sys');
DeleteFile('C:\WINDOWS.0\System32\drivers\icn40cc.sys');
DeleteFile('C:\WINDOWS.0\System32\drivers\dcj0797.sys');
DeleteFile('C:\WINDOWS.0\System32\drivers\bah6240.sys');
DeleteFile('C:\WINDOWS.0\System32\drivers\amg85d4.sys');
DelCLSID('{PLXO6H14-6NL1-Q5JE-5OM5-WLC111QFA8X2} ');
BC_ImportAll;
ExecuteSysClean;
ExecuteRepair(1);
ExecuteRepair(11);
ExecuteWizard('TSW', 2, 2, true);
ExecuteWizard('SCU', 2, 2, true);
RegKeyIntParamWrite('HKLM','SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer','NoDriveTypeAutoRun', 221);
BC_Activate;
RebootWindows(true);
end.
После перезагрузки: