Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
QuarantineFile('C:\WINDOWS\system32\config\NetLimiter.e','');
QuarantineFile('C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1015\svchost.exe','');
DelBHO('F6EE5875-4854-4408-B12D-3290883D966E');
QuarantineFile('C:\WINDOWS\vmgspntbter.dll','');
DelBHO('C5AF49A2-94F3-42BD-F234-3604812C897D');
DelBHO('A37F5943-8331-4900-972E-8CEFC43E4629');
DelBHO('96396D0B-E29A-4DD6-8E84-96A709EBFBE6');
DelBHO('1A75F101-126E-46A3-97B1-91A96D161C15');
QuarantineFile('C:\Windows\system32\YURF8E.exe','');
QuarantineFile('C:\Windows\system32\YUREAB.exe','');
QuarantineFile('C:\Windows\system32\YURE5.exe','');
QuarantineFile('C:\Windows\system32\YURDFB.exe','');
QuarantineFile('C:\Windows\system32\YURD45.exe','');
QuarantineFile('C:\Windows\system32\YURB9.exe','');
QuarantineFile('C:\Windows\system32\YURB8.exe','');
QuarantineFile('C:\Windows\system32\YUR2C.exe','');
QuarantineFile('C:\Windows\system32\YUR29.exe','');
QuarantineFile('C:\Windows\system32\YUR15D0.exe','');
QuarantineFile('C:\Windows\system32\YUR151E.exe','');
QuarantineFile('C:\Windows\system32\YUR1386.exe','');
QuarantineFile('C:\Windows\system32\YUR120F.exe','');
QuarantineFile('C:\Windows\system32\YUR10C3.exe','');
QuarantineFile('C:\WINDOWS\system32\ksfj83nwe.dll','');
QuarantineFile('C:\WINDOWS\system32\kdsxc.exe','');
QuarantineFile('C:\WINDOWS\system32\jcetxibx.dll','');
QuarantineFile('C:\WINDOWS\system32\anwsk.exe','');
QuarantineFile('C:\WINDOWS\system32\byXPiIAs.dll','');
QuarantineFile('C:\WINDOWS\system32\drivers\services.exe','');
QuarantineFile('C:\WINDOWS\dtseqrxk.dll','');
QuarantineFile('C:\WINDOWS\services.exe','');
QuarantineFile('C:\Documents and Settings\LocalService\svchost.exe','');
QuarantineFile('C:\Documents and Settings\Administrator\svchost.exe','');
QuarantineFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winlogen.exe','');
QuarantineFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\csrssc.exe','');
QuarantineFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\8\winlogon.exe','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\SkyNET.SYS','');
QuarantineFile('C:\WINDOWS\system32\Drivers\SjyPkt.sys','');
DeleteService('nrrvorqv');
QuarantineFile('C:\WINDOWS\system32\drivers\nrrvorqv.sys','');
DeleteService('abp470n5');
QuarantineFile('C:\Documents and Settings\Administrator\S87ekhV.exe','');
QuarantineFile('C:\WINDOWS\mgxfebsq.dll','');
DeleteFile('C:\WINDOWS\mgxfebsq.dll');
DeleteFile('C:\Documents and Settings\Administrator\S87ekhV.exe');
DeleteFile('C:\WINDOWS\system32\drivers\nrrvorqv.sys');
DeleteFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\8\winlogon.exe');
DeleteFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\csrssc.exe');
DeleteFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winlogen.exe');
DeleteFile('C:\Documents and Settings\Administrator\svchost.exe');
DeleteFile('C:\Documents and Settings\LocalService\svchost.exe');
DeleteFile('C:\WINDOWS\services.exe');
DeleteFile('C:\WINDOWS\dtseqrxk.dll');
DeleteFile('C:\WINDOWS\system32\drivers\services.exe');
DeleteFile('C:\WINDOWS\system32\byXPiIAs.dll');
DeleteFile('C:\WINDOWS\system32\anwsk.exe');
DeleteFile('C:\WINDOWS\system32\jcetxibx.dll');
DeleteFile('C:\WINDOWS\system32\kdsxc.exe');
DeleteFile('C:\WINDOWS\system32\ksfj83nwe.dll');
DeleteFile('C:\Windows\system32\YUR10C3.exe');
DeleteFile('C:\Windows\system32\YUR120F.exe');
DeleteFile('C:\Windows\system32\YUR1386.exe');
DeleteFile('C:\Windows\system32\YUR151E.exe');
DeleteFile('C:\Windows\system32\YUR15D0.exe');
DeleteFile('C:\Windows\system32\YUR29.exe');
DeleteFile('C:\Windows\system32\YUR2C.exe');
DeleteFile('C:\Windows\system32\YURB8.exe');
DeleteFile('C:\Windows\system32\YURB9.exe');
DeleteFile('C:\Windows\system32\YURD45.exe');
DeleteFile('C:\Windows\system32\YURDFB.exe');
DeleteFile('C:\Windows\system32\YURE5.exe');
DeleteFile('C:\Windows\system32\YUREAB.exe');
DeleteFile('C:\Windows\system32\YURF8E.exe');
DeleteFile('byXPiIAs.dll');
DeleteFile('hgGyxWoM.dll');
DeleteFile('C:\WINDOWS\vmgspntbter.dll');
QuarantineFile('C:\Program Files\Microsoft Common\wuauclt.exe','');
DeleteFile('C:\Program Files\Microsoft Common\wuauclt.exe');
DeleteFile('C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1015\svchost.exe');
BC_Importall;
ExecuteRepair(9);
ExecuteRepair(10);
ExecuteRepair(11);
ExecuteRepair(17);
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.