Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\Documents and Settings\Paradise\csrss.exe','');
QuarantineFile('G:\TWINS\jutroivece.exe','');
QuarantineFile('G:\autorun.inf','');
QuarantineFile('F:\TWINS\jutroivece.exe','');
QuarantineFile('F:\autorun.inf','');
QuarantineFile('C:\WINDOWS\Temp\992.exe','');
QuarantineFile('C:\WINDOWS\Temp\841.exe','');
QuarantineFile('C:\WINDOWS\Temp\571.exe','');
QuarantineFile('C:\WINDOWS\Temp\482.exe','');
QuarantineFile('C:\WINDOWS\Temp\119.exe','');
QuarantineFile('C:\WINDOWS\Temp\040.exe','');
QuarantineFile('C:\Documents and Settings\Paradise\Local Settings\Temporary Internet Files\Content.IE5\W03B9DQB\brgtverc[1].exe','');
QuarantineFile('C:\Documents and Settings\Paradise\Local Settings\Temporary Internet Files\Content.IE5\W03B9DQB\bgvfrcweds[1].exe','');
QuarantineFile('C:\Documents and Settings\Paradise\Local Settings\Temporary Internet Files\Content.IE5\W03B9DQB\bgtvfrcd[1].exe','');
QuarantineFile('C:\Documents and Settings\Paradise\Local Settings\Temporary Internet Files\Content.IE5\03AX3P51\nhbgvfdc[1].exe','');
QuarantineFile('C:\Documents and Settings\Paradise\Local Settings\Temporary Internet Files\Content.IE5\03AX3P51\nbv[1].exe','');
QuarantineFile('c:\windows\system32\wuaucldt.exe','');
QuarantineFile('c:\documents and settings\paradise\wuaucldt.exe','');
QuarantineFile('C:\Documents and Settings\Paradise\Главное меню\Программы\Автозагрузка\yyu0qg0cs0.exe','');
QuarantineFile('C:\Documents and Settings\Paradise\Главное меню\Программы\Автозагрузка\upgw0si6y.exe','');
QuarantineFile('C:\Documents and Settings\Paradise\Главное меню\Программы\Автозагрузка\ea0wm0iy0u.exe','');
QuarantineFile('C:\Documents and Settings\Paradise\yht.exe','');
QuarantineFile('C:\Documents and Settings\Paradise\Application Data\juzjf.exe','');
QuarantineFile('C:\WINDOWS\system32\Drivers\uzhmswcc.sys','');
DeleteService('uzhmswcc');
QuarantineFile('C:\WINDOWS\System32\Drivers\veneeuuu.sys','');
DeleteService('veneeuuu');
DeleteFile('C:\WINDOWS\System32\Drivers\veneeuuu.sys');
DeleteFile('C:\WINDOWS\system32\Drivers\uzhmswcc.sys');
DeleteFile('C:\Documents and Settings\Paradise\Application Data\juzjf.exe');
DeleteFile('C:\Documents and Settings\Paradise\Application Data\juzjf.exe,explorer.exe,C:\Documents and Settings\Paradise\csrss.exe');
DeleteFile('C:\Documents and Settings\Paradise\yht.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','MSConfig');
DeleteFile('C:\Documents and Settings\Paradise\Главное меню\Программы\Автозагрузка\ea0wm0iy0u.exe');
DeleteFile('C:\Documents and Settings\Paradise\Главное меню\Программы\Автозагрузка\upgw0si6y.exe');
DeleteFile('C:\Documents and Settings\Paradise\Главное меню\Программы\Автозагрузка\yyu0qg0cs0.exe');
DeleteFile('c:\documents and settings\paradise\wuaucldt.exe');
DeleteFile('c:\windows\system32\wuaucldt.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','wuaucldt');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','wuaucldt');
DeleteFile('C:\Documents and Settings\Paradise\Local Settings\Temporary Internet Files\Content.IE5\03AX3P51\nbv[1].exe');
DeleteFile('C:\Documents and Settings\Paradise\Local Settings\Temporary Internet Files\Content.IE5\03AX3P51\nhbgvfdc[1].exe');
DeleteFile('C:\Documents and Settings\Paradise\Local Settings\Temporary Internet Files\Content.IE5\W03B9DQB\bgtvfrcd[1].exe');
DeleteFile('C:\Documents and Settings\Paradise\Local Settings\Temporary Internet Files\Content.IE5\W03B9DQB\bgvfrcweds[1].exe');
DeleteFile('C:\Documents and Settings\Paradise\Local Settings\Temporary Internet Files\Content.IE5\W03B9DQB\brgtverc[1].exe');
DeleteFile('C:\WINDOWS\Temp\040.exe');
DeleteFile('C:\WINDOWS\Temp\119.exe');
DeleteFile('C:\WINDOWS\Temp\482.exe');
DeleteFile('C:\WINDOWS\Temp\571.exe');
DeleteFile('C:\WINDOWS\Temp\841.exe');
DeleteFile('C:\WINDOWS\Temp\992.exe');
DeleteFile('F:\autorun.inf');
DeleteFile('F:\TWINS\jutroivece.exe');
DeleteFile('G:\autorun.inf');
DeleteFile('G:\TWINS\jutroivece.exe');
DeleteFile('C:\Documents and Settings\Paradise\csrss.exe'); QuarantineFile('','');
DeleteFileMask('C:\Documents and Settings\Paradise\Local Settings\Temporary Internet Files\Content.IE5', '*.*', true);
DeleteDirectory('C:\Documents and Settings\Paradise\Local Settings\Temporary Internet Files\Content.IE5');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon','Taskman ');
BC_ImportAll;
ExecuteSysClean;
ExecuteRepair(11);
ExecuteWizard('TSW', 2, 2, true);
ExecuteWizard('SCU', 2, 2, true);
RegKeyIntParamWrite('HKLM','SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer','NoDriveTypeAutoRun',221);
BC_Activate;
RebootWindows(true);
end.
После перезагрузки: