Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\update.2\svchost.exe','');
QuarantineFile('C:\WINDOWS\system32\53.exe','');
QuarantineFile('C:\WINDOWS\system32\24.exe','');
QuarantineFile('c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\acleaner.exe','');
QuarantineFile('C:\WINDOWS\system32\ac32.exe','');
QuarantineFile('C:\WINDOWS\sysdriver32_.exe','');
QuarantineFile('C:\WINDOWS\jodrive32.exe','');
QuarantineFile('C:\WINDOWS\TEMP\9549962.exe','');
QuarantineFile('C:\WINDOWS\TEMP\927557.exe','');
QuarantineFile('C:\WINDOWS\TEMP\6501670.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\Tcisil.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\Naisif.exe','');
QuarantineFile('C:\DOCUME~1\9335~1\LOCALS~1\Temp\1583070.exe','');
DeleteService('PrtSmanm');
QuarantineFile('c:\windows\system32\smsc.exe','');
TerminateProcessByName('c:\windows\system32\smsc.exe');
DeleteFile('c:\windows\system32\smsc.exe');
DeleteFile('C:\DOCUME~1\9335~1\LOCALS~1\Temp\1583070.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','1583070.exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\Naisif.exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\Tcisil.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Tcisil');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Naisif');
DeleteFile('C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','12CFG214-K641-12SF-N85P');
DeleteFile('C:\WINDOWS\TEMP\6501670.exe');
DeleteFile('C:\WINDOWS\TEMP\927557.exe');
DeleteFile('C:\WINDOWS\TEMP\9549962.exe');
DeleteFile('C:\WINDOWS\jodrive32.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Config Setup');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','9549962.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','927557.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','6501670.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Microsoft Config Setup');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','sysdriver32_.exe');
DeleteFile('C:\WINDOWS\sysdriver32_.exe');
DeleteFile('C:\WINDOWS\system32\ac32.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ac32');
DeleteFile('c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\acleaner.exe');
DeleteFile('C:\WINDOWS\system32\24.exe');
DeleteFile('C:\WINDOWS\system32\53.exe');
DeleteFile('C:\WINDOWS\update.2\svchost.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon','Taskman ');
QuarantineFile('C:\WINDOWS\services32.exe','');
QuarantineFile('C:\WINDOWS\update.3\svchost.exe','');
QuarantineFile('C:\WINDOWS\TEMP\9549962.exe','');
QuarantineFile('C:\DOCUME~1\9335~1\LOCALS~1\Temp\1583070.exe','');
DeleteFile('C:\DOCUME~1\9335~1\LOCALS~1\Temp\1583070.exe');
DeleteFile('C:\WINDOWS\TEMP\9549962.exe');
DeleteFile('C:\WINDOWS\update.3\svchost.exe');
DeleteFile('C:\WINDOWS\services32.exe');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\16.tmp','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\5F.tmp','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\2A.tmp','');
QuarantineFile('C:\WINDOWS\SET9.tmp','');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\16.tmp');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\5F.tmp');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\2A.tmp');
DeleteFile('C:\WINDOWS\SET9.tmp');
QuarantineFile('C:\WINDOWS\SET5.tmp','');
QuarantineFile('C:\WINDOWS\SET4.tmp','');
QuarantineFile('C:\WINDOWS\system32\drivers\avsqskjx.sys','');
DeleteFile('C:\WINDOWS\SET5.tmp');
DeleteFile('C:\WINDOWS\SET4.tmp');
DeleteFile('C:\WINDOWS\system32\drivers\avsqskjx.sys');
BC_ImportAll;
ExecuteSysClean;
ExecuteRepair(11);
ExecuteWizard('TSW', 2, 2, true);
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.
После перезагрузки: