Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\documents and settings\12\wuaucldt.exe');
TerminateProcessByName('c:\windows\temp\wpv231273576811.exe');
QuarantineFile('C:\DOCUME~1\12\LOCALS~1\Temp\Rar$EX00.110\MagicTree.exe','');
QuarantineFile('C:\DOCUME~1\12\LOCALS~1\Temp\Rar$EX00.172\Xmas.exe','');
QuarantineFile('C:\DOCUME~1\12\LOCALS~1\Temp\Rar$EX00.438\Christmas.exe','');
QuarantineFile('C:\DOCUME~1\12\LOCALS~1\Temp\Rar$EX00.484\Xmas.exe','');
QuarantineFile('C:\DOCUME~1\12\LOCALS~1\Temp\Rar$EX00.547\Christmas.exe','');
QuarantineFile('C:\DOCUME~1\12\LOCALS~1\Temp\Rar$EX00.828\Tannenbaum.exe','');
QuarantineFile('C:\DOCUME~1\12\LOCALS~1\Temp\Rar$EX00.985\XmasSpirit.exe','');
QuarantineFile('E:\OSMICA\devetka.exe','');
QuarantineFile('E:\autorun.inf','');
QuarantineFile('c:\windows\system32\svchost.exe:exe.exe:$DATA','');
QuarantineFile('c:\windows\explorer.exe:userini.exe:$DATA','');
QuarantineFile('c:\windows\system32\wuaucldt.exe','');
QuarantineFile('C:\WINDOWS\system32\userini.exe','');
QuarantineFile('C:\WINDOWS\system32\regedit.exe','');
QuarantineFile('C:\Documents and Settings\12\seudu.exe','');
QuarantineFile('C:\Documents and Settings\12\pcqu.exe','');
QuarantineFile('C:\Documents and Settings\12\csrss.exe','');
QuarantineFile('C:\Documents and Settings\12\Application Data\zwog.exe,explorer.exe,C:\Documents and Set-tings\12\csrss.exe','');
QuarantineFile('C:\Documents and Settings\12\Application Data\zwog.exe','');
QuarantineFile('C:\WINDOWS\System32\Drivers\yyfsmyyh.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\xpnwvlwk.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\xmzqnbke.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\wyxviohe.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\vrhnqlkn.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\sqdpbdwu.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\shkdomyf.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\sdfutind.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\rzhwhmja.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\qmwfwhur.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\qefbpgdm.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\qaywmzko.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\pzxvykqj.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\pxrcaeom.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\protect.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\pbjkktjk.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\opigthza.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\ofhnypbt.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\nwdlwklp.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\nvmqsasr.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\nrawzjmi.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\mpmrvtes.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\lkzrtexv.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\koazrchr.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\ivwwcpyz.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\hsapjrcq.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\hjlfhdyg.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\gvyvbvsh.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\gnsowthx.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\fonjafni.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\fiigxhnh.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\emhdhros.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\dcacsjxp.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\cgzegjhw.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\cekvxjhc.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\buvyxgig.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\apsymwrt.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\arvsaimf.sys','');
QuarantineFile('C:\WINDOWS\system32\fookoozek.exe','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\cdrom.sys','');
QuarantineFile('c:\documents and settings\12\wuaucldt.exe','');
QuarantineFile('c:\windows\temp\wpv231273576811.exe','');
DeleteFile('c:\windows\temp\wpv231273576811.exe');
DeleteFile('c:\documents and settings\12\wuaucldt.exe');
DeleteFile('C:\WINDOWS\system32\fookoozek.exe');
DeleteFile('C:\WINDOWS\System32\Drivers\arvsaimf.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\apsymwrt.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\buvyxgig.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\cekvxjhc.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\cgzegjhw.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\dcacsjxp.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\emhdhros.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\fiigxhnh.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\fonjafni.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\gnsowthx.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\gvyvbvsh.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\hjlfhdyg.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\ivwwcpyz.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\koazrchr.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\lkzrtexv.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\mpmrvtes.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\nrawzjmi.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\nvmqsasr.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\nwdlwklp.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\ofhnypbt.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\opigthza.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\pbjkktjk.sys');
DeleteFile('C:\WINDOWS\system32\drivers\protect.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\pxrcaeom.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\pzxvykqj.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\qaywmzko.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\qefbpgdm.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\qmwfwhur.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\rzhwhmja.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\sdfutind.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\shkdomyf.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\sqdpbdwu.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\vrhnqlkn.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\wyxviohe.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\xmzqnbke.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\xpnwvlwk.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\yyfsmyyh.sys');
DeleteFile('C:\Documents and Settings\12\Application Data\zwog.exe,explorer.exe,C:\Documents and Set-tings\12\csrss.exe');
DeleteFile('C:\Documents and Settings\12\Application Data\zwog.exe');
DeleteFile('C:\Documents and Settings\12\csrss.exe');
DeleteFile('C:\Documents and Settings\12\pcqu.exe');
DeleteFile('C:\Documents and Settings\12\seudu.exe');
DeleteFile('C:\WINDOWS\system32\regedit.exe');
DeleteFile('C:\WINDOWS\system32\userini.exe');
DeleteFile('c:\windows\system32\wuaucldt.exe');
DeleteFile('c:\windows\explorer.exe:userini.exe:$DATA');
DeleteFile('c:\windows\system32\svchost.exe:exe.exe:$DATA');
DeleteFile('E:\autorun.inf');
DeleteFile('E:\OSMICA\devetka.exe');
DeleteFile('C:\DOCUME~1\12\LOCALS~1\Temp\Rar$EX00.985\XmasSpirit.exe');
DeleteFile('C:\DOCUME~1\12\LOCALS~1\Temp\Rar$EX00.828\Tannenbaum.exe');
DeleteFile('C:\DOCUME~1\12\LOCALS~1\Temp\Rar$EX00.547\Christmas.exe');
DeleteFile('C:\DOCUME~1\12\LOCALS~1\Temp\Rar$EX00.484\Xmas.exe');
DeleteFile('C:\DOCUME~1\12\LOCALS~1\Temp\Rar$EX00.438\Christmas.exe');
DeleteFile('C:\DOCUME~1\12\LOCALS~1\Temp\Rar$EX00.172\Xmas.exe');
DeleteFile('C:\DOCUME~1\12\LOCALS~1\Temp\Rar$EX00.110\MagicTree.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','syncman');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','syncman');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','userini');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','userini');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','userini');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','userini');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Regedit32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','seudu');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','MSConfig');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Magic Tree');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Xmas Tree');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Deluxe Tree');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','DesktopXmasTree');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ChristmasTree');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','deskTannenbaum');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Christmas spirit');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon','Taskman');
DeleteService('buvyxgig');
DeleteService('cekvxjhc');
DeleteService('cgzegjhw');
DeleteService('dcacsjxp');
DeleteService('emhdhros');
DeleteService('fiigxhnh');
DeleteService('fonjafni');
DeleteService('gnsowthx');
DeleteService('gvyvbvsh');
DeleteService('hjlfhdyg');
DeleteService('hsapjrcq');
DeleteService('ivwwcpyz');
DeleteService('koazrchr');
DeleteService('lkzrtexv');
DeleteService('mpmrvtes');
DeleteService('nrawzjmi');
DeleteService('nvmqsasr');
DeleteService('nwdlwklp');
DeleteService('ofhnypbt');
DeleteService('opigthza');
DeleteService('pbjkktjk');
DeleteService('protect');
DeleteService('pxrcaeom');
DeleteService('pzxvykqj');
DeleteService('qaywmzko');
DeleteService('qefbpgdm');
DeleteService('qmwfwhur');
DeleteService('rzhwhmja');
DeleteService('sdfutind');
DeleteService('shkdomyf');
DeleteService('sqdpbdwu');
DeleteService('vrhnqlkn');
DeleteService('wyxviohe');
DeleteService('xmzqnbke');
DeleteService('xpnwvlwk');
DeleteService('yyfsmyyh');
DeleteService('arvsaimf');
DeleteService('apsymwrt');
DeleteService('a19au3yygy1xal');
DeleteFileMask('E:\OSMICA', '*.*', true);
DeleteDirectory('E:\OSMICA');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.