Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
DelCLSID('{63MAD6M8-1MAD-81AD-JIM6-26OP5G1234585}');
QuarantineFile('C:\WINDOWS\system32\pabu.exe','');
QuarantineFile('C:\WINDOWS\system32\csrcs.exe','');
DeleteService('cxmzivds');
SetServiceStart('Secdrvr', 4);
DeleteService('Secdrvr');
SetServiceStart('Secdrvq', 4);
DeleteService('Secdrvq');
DeleteService('eem3e0ye6ye7');
TerminateProcessByName('c:\windows\temp\wpv441275037067.exe');
TerminateProcessByName('c:\windows\system32\userini.exe');
TerminateProcessByName('c:\windows\system32\kunnounon.exe');
TerminateProcessByName('c:\docume~1\helen\locals~1\temp\5781639.exe');
QuarantineFile('C:\WINDOWS\explorer.exe:userini.exe:$DATA','');
QuarantineFile('C:\DODA\JENE\NeST.exe','');
QuarantineFile('C:\WINDOWS\system32\ponooho.exe','');
QuarantineFile('C:\DOCUME~1\Helen\LOCALS~1\Temp\023.exe,C:\DOCUME~1\Helen\LOCALS~1\Temp\348.exe,C:\DOCUME~1\Helen\LOCALS~1\Temp\108.exe,C:\DOCUME~1\Helen\LOCALS~1\Temp\563.exe,C:\RECYCLER\S-1-5-21-2284091019-6262240817-311586092-4446\nissan.exe,explorer.exe,C:\Documents and Settings\Helen\Application Data\cift.exe','');
QuarantineFile('C:\DOCUME~1\Helen\LOCALS~1\Temp\023.exe','');
QuarantineFile('C:\DOCUME~1\Helen\LOCALS~1\Temp\348.exe','');
QuarantineFile('C:\DOCUME~1\Helen\LOCALS~1\Temp\108.exe','');
QuarantineFile('C:\DOCUME~1\Helen\LOCALS~1\Temp\563.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-2284091019-6262240817-311586092-4446\nissan.exe','');
QuarantineFile('C:\Documents and Settings\Helen\Application Data\cift.exe','');
QuarantineFile('C:\WINDOWS\system32\01.tmp','');
QuarantineFile('C:\WINDOWS\System32\DRIVERS\Secdrvr.sys','');
QuarantineFile('C:\WINDOWS\System32\DRIVERS\Secdrvq.sys','');
QuarantineFile('C:\WINDOWS\system32\myma.exe','');
QuarantineFile('c:\windows\temp\wpv441275037067.exe','');
QuarantineFile('c:\windows\system32\userini.exe','');
QuarantineFile('c:\windows\system32\kunnounon.exe','');
QuarantineFile('c:\docume~1\helen\locals~1\temp\5781639.exe','');
DeleteFile('c:\docume~1\helen\locals~1\temp\5781639.exe');
DeleteFile('c:\windows\system32\kunnounon.exe');
DeleteFile('c:\windows\system32\userini.exe');
DeleteFile('c:\windows\temp\wpv441275037067.exe');
DeleteFile('C:\WINDOWS\system32\myma.exe');
DeleteFile('C:\WINDOWS\System32\DRIVERS\Secdrvq.sys');
DeleteFile('C:\WINDOWS\System32\DRIVERS\Secdrvr.sys');
DeleteFile('C:\WINDOWS\system32\01.tmp');
DeleteFile('C:\Documents and Settings\Helen\Application Data\cift.exe');
DeleteFile('C:\DOCUME~1\Helen\LOCALS~1\Temp\023.exe,C:\DOCUME~1\Helen\LOCALS~1\Temp\348.exe,C:\DOCUME~1\Helen\LOCALS~1\Temp\108.exe,C:\DOCUME~1\Helen\LOCALS~1\Temp\563.exe,C:\RECYCLER\S-1-5-21-2284091019-6262240817-311586092-4446\nissan.exe,explorer.exe,C:\Documents and Settings\Helen\Application Data\cift.exe');
DeleteFile('C:\DOCUME~1\Helen\LOCALS~1\Temp\023.exe');
DeleteFile('C:\DOCUME~1\Helen\LOCALS~1\Temp\348.exe');
DeleteFile('C:\DOCUME~1\Helen\LOCALS~1\Temp\108.exe');
DeleteFile('C:\DOCUME~1\Helen\LOCALS~1\Temp\563.exe');
DeleteFile('C:\RECYCLER\S-1-5-21-2284091019-6262240817-311586092-4446\nissan.exe');
DeleteFile('C:\WINDOWS\system32\ponooho.exe');
DeleteFile('C:\DODA\JENE\NeST.exe');
DeleteFile('C:\WINDOWS\explorer.exe:userini.exe:$DATA');
DeleteFile('C:\WINDOWS\system32\csrcs.exe');
DeleteFile('C:\WINDOWS\system32\pabu.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','zoosoukes');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','csrcs');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','sasinou');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','userini');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','userini');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','userini');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','userini');
DeleteFileMask('C:\DODA\JENE', '*.*', true);
DeleteDirectory('C:\DODA\JENE');
DeleteFileMask('C:\DODA', '*.*', true);
DeleteDirectory('C:\DODA');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon','Taskman');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.