Код:
begin
SearchRootkit(true,true);
SetAVZGuardStatus(true);
QuarantineFile('C:\WINDOWS\system32\Drivers\atapidrv.sys','');
QuarantineFile('C:\WINDOWS\system32\Drivers\protect.sys','');
QuarantineFile('C:\WINDOWS\system32\27.scr','');
QuarantineFile('C:\WINDOWS\system32\47.scr','');
QuarantineFile('C:\WINDOWS\system32\system.exe','');
QuarantineFile('C:\WINDOWS\system32\itcadvapi.dll','');
QuarantineFile('C:\WINDOWS\system32\drivers\AtapiDrv.sys','');
QuarantineFile('C:\WINDOWS\DOWNLO~1\XCrypt10.ocx','');
QuarantineFile('c:\windows\system32\svchost.exe','');
QuarantineFile('csbdll.dll','');
QuarantineFile('C:\WINDOWS\system32\zyquefubou.exe','');
QuarantineFile('C:\WINDOWS\system32\ziwoquub.exe','');
QuarantineFile('C:\WINDOWS\system32\zahyzos.exe','');
QuarantineFile('C:\WINDOWS\system32\userini.exe','');
QuarantineFile('C:\WINDOWS\system32\loroubac.exe','');
QuarantineFile('C:\WINDOWS\system32\loojuqu.exe','');
QuarantineFile('C:\WINDOWS\system32\koukobobyc.exe','');
QuarantineFile('C:\WINDOWS\system32\itcssp.dll','');
QuarantineFile('C:\WINDOWS\system32\QASbcKDlkvg.dll','');
QuarantineFile('C:\RECYCLER\S-1-5-21-3091199524-7458011847-412269310-6391\yv8g67.exe,C:\RECYCLER\S-1-5-21-4056718751-0510617546-671414887-8380\yv8g67.exe,C:\RECYCLER\S-1-5-21-4833865677-9152238688-104747715-6574\yv8g67.exe,C:\RECYCLER\S-1-5-21-4873884379-0970966926-781795719-5819\yv8g67.exe,C:\RECYCLER\S-1-5-21-1975888611-7103606427-389737085-1700\yv8g67.exe,C:\RECYCLER\S-1-5-21-9988580441-1341761096-891391804-1582\yv8g67.exe,C:\RECYCLER\S-1-5-21-1381989723-7581347384-058304798-8632\yv8g67.exe,C:\Documents and Settings\user\msgvn.exe,C:\Documents and Settings\user\Application Data\qmkin.exe,C:\Documents and Settings\user\Application Data\yftza.exe,explorer.exe,C:\Documents and Settings\user\Application Data\yjty.exe','');
QuarantineFile('C:\Documents and Settings\NetworkService\ueukcv.exe','');
QuarantineFile('C:\Documents and Settings\NetworkService\Application Data\Microsoft\vajoofygu.exe','');
QuarantineFile('C:\Documents and Settings\All Users\Документы\Settings\cbss.dll','');
QuarantineFile('C:\WINDOWS\System32\Drivers\zdypnofu.sys','');
QuarantineFile('C:\WINDOWS\System32\DRIVERS\shqgvbngq.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\shqgvbng.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\qhejvknn.sys','');
QuarantineFile('C:\WINDOWS\System32\DRIVERS\pdujtdibr.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\pdujtdib.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\onitapvs.sys','');
QuarantineFile('C:\WINDOWS\system32\Drivers\lsstart.sys','');
QuarantineFile('C:\WINDOWS\system32\Drivers\krn.sys','');
QuarantineFile('C:\WINDOWS\System32\DRIVERS\bzmlnuprq.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\bzmlnupr.sys','');
QuarantineFile('C:\WINDOWS\system32\civijar.exe','');
QuarantineFile('C:\WINDOWS\system32\voofok.exe','');
QuarantineFile('C:\WINDOWS\system32\badicyroul.exe','');
DeleteService('krn');
DeleteService('lsstart');
DeleteService('onitapvs');
DeleteService('pdujtdib');
DeleteService('perc2');
DeleteService('qhejvknn');
DeleteService('shqgvbng');
DeleteService('shqgvbngq');
DeleteService('bzmlnuprq');
DeleteService('bzmlnupr');
DeleteService('zdypnofu');
DeleteService('gioakkehyl');
DeleteService('cbhoqiacpos6y8');
DeleteService('a94vc4q2z3');
DeleteFile('C:\WINDOWS\system32\badicyroul.exe');
DeleteFile('C:\WINDOWS\system32\voofok.exe');
DeleteFile('C:\WINDOWS\system32\civijar.exe');
DeleteFile('C:\WINDOWS\System32\Drivers\bzmlnupr.sys');
DeleteFile('C:\WINDOWS\System32\DRIVERS\bzmlnuprq.sys');
DeleteFile('C:\WINDOWS\system32\Drivers\krn.sys');
DeleteFile('C:\WINDOWS\system32\Drivers\lsstart.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\onitapvs.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\pdujtdib.sys');
DeleteFile('C:\WINDOWS\System32\DRIVERS\pdujtdibr.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\qhejvknn.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\shqgvbng.sys');
DeleteFile('C:\WINDOWS\System32\DRIVERS\shqgvbngq.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\zdypnofu.sys');
DeleteFile('C:\Documents and Settings\All Users\Документы\Settings\cbss.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbssreg','DLLName');
DeleteFile('C:\Documents and Settings\NetworkService\Application Data\Microsoft\vajoofygu.exe');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','bubouquot');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','bubouquot');
DeleteFile('C:\Documents and Settings\NetworkService\ueukcv.exe');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','MSConfig');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','MSConfig');
DeleteFile('C:\RECYCLER\S-1-5-21-3091199524-7458011847-412269310-6391\yv8g67.exe,C:\RECYCLER\S-1-5-21-4056718751-0510617546-671414887-8380\yv8g67.exe,C:\RECYCLER\S-1-5-21-4833865677-9152238688-104747715-6574\yv8g67.exe,C:\RECYCLER\S-1-5-21-4873884379-0970966926-781795719-5819\yv8g67.exe,C:\RECYCLER\S-1-5-21-1975888611-7103606427-389737085-1700\yv8g67.exe,C:\RECYCLER\S-1-5-21-9988580441-1341761096-891391804-1582\yv8g67.exe,C:\RECYCLER\S-1-5-21-1381989723-7581347384-058304798-8632\yv8g67.exe,C:\Documents and Settings\user\msgvn.exe,C:\Documents and Settings\user\Application Data\qmkin.exe,C:\Documents and Settings\user\Application Data\yftza.exe,explorer.exe,C:\Documents and Settings\user\Application Data\yjty.exe');
DeleteFile('C:\WINDOWS\system32\QASbcKDlkvg.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\ufad-dns60\Parameters','ServiceDll');
DeleteFile('C:\WINDOWS\system32\koukobobyc.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunServices','jyjoo');
DeleteFile('C:\WINDOWS\system32\loojuqu.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunServices','kuhicyp');
DeleteFile('C:\WINDOWS\system32\loroubac.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunServices','koowyk');
DeleteFile('C:\WINDOWS\system32\userini.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','userini');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','userini');
DeleteFile('C:\WINDOWS\system32\zahyzos.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunServices','quougeg');
DeleteFile('C:\WINDOWS\system32\ziwoquub.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunServices','loquoocig');
DeleteFile('C:\WINDOWS\system32\zyquefubou.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunServices','gomocor');
DeleteFile('csbdll.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\csbdll','DLLName');
DeleteFile('C:\WINDOWS\system32\itcadvapi.dll');
DeleteFile('C:\WINDOWS\system32\system.exe');
DeleteFile('C:\WINDOWS\system32\47.scr');
DeleteFile('C:\WINDOWS\system32\27.scr');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
ExecuteWizard('SCU', 2, 2, true);
ExecuteWizard('TSW', 2, 2, true);
RebootWindows(true);
end.
После перезагрузки выполните второй скрипт