Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
DeleteFileMask(GetAVZDirectory + 'Quarantine', '*.*', true);
TerminateProcessByName('c:\windows\temp\1634.exe');
QuarantineFile('c:\windows\temp\1634.exe','');
TerminateProcessByName('c:\windows\temp\23641.exe');
QuarantineFile('c:\windows\temp\23641.exe','');
TerminateProcessByName('c:\windows\temp\3704.exe');
QuarantineFile('c:\windows\temp\3704.exe','');
TerminateProcessByName('c:\windows\temp\8797.exe');
QuarantineFile('c:\windows\temp\8797.exe','');
TerminateProcessByName('c:\windows\temp\b9a5c96.exe');
QuarantineFile('c:\windows\temp\b9a5c96.exe','');
TerminateProcessByName('c:\windows\system32\ckw7awiq\c010.exe');
QuarantineFile('c:\windows\system32\ckw7awiq\c010.exe','');
TerminateProcessByName('c:\windows\system32\ajxtnjr4\d001.exe');
QuarantineFile('c:\windows\system32\ajxtnjr4\d001.exe','');
TerminateProcessByName('c:\windows\system32\vo3j5xb1\f001.exe');
QuarantineFile('c:\windows\system32\vo3j5xb1\f001.exe','');
TerminateProcessByName('c:\documents and settings\all users\application data\lanmao.exe');
QuarantineFile('c:\documents and settings\all users\application data\lanmao.exe','');
TerminateProcessByName('c:\windows\svhost4.exe');
QuarantineFile('c:\windows\svhost4.exe','');
TerminateProcessByName('c:\windows\svhost6.exe');
QuarantineFile('c:\windows\svhost6.exe','');
TerminateProcessByName('c:\windows\svhost7.exe');
QuarantineFile('c:\windows\svhost7.exe','');
QuarantineFile('c:\windows\system32\bxmrs.cc3','');
QuarantineFile('C:\WINDOWS\system32\dbr06006.ocx','');
QuarantineFile('C:\WINDOWS\system32\dbr06006.tsp','');
QuarantineFile('C:\WINDOWS\system32\dbr09006.ocx','');
QuarantineFile('C:\WINDOWS\system32\dbr09006.tsp','');
QuarantineFile('C:\WINDOWS\system32\dbr11005.tsp','');
QuarantineFile('C:\WINDOWS\system32\msctfime.iem','');
QuarantineFile('C:\WINDOWS\TEMP\kb208169.gon','');
QuarantineFile('C:\WINDOWS\TEMP\kb551178.gon','');
QuarantineFile('C:\WINDOWS\system32\0AFD20F8.sys','');
QuarantineFile('C:\Program Files\Internet Explorer\Antinoftn.scr','');
QuarantineFile('C:\Documents and Settings\All Users\Application Data\Storm\update\Console\jpqly.cc3','');
QuarantineFile('C:\Documents and Settings\All Users\Application Data\lanmao.exe','');
QuarantineFile('C:\Documents and Settings\All Users\Главное меню\Программы\Автозагрузка\ra.vbe','');
QuarantineFile('C:\Documents and Settings\All Users\Главное меню\Программы\Автозагрузка\smsrun.jse','');
QuarantineFile('C:\WINDOWS\system32\4cdd0.dll','');
QuarantineFile('c:\drivers\smss.exe','');
QuarantineFile('C:\WINDOWS\system32\msctfiem.cpl','');
DeleteFile('C:\WINDOWS\system32\msctfiem.cpl');
DeleteFile('c:\drivers\smss.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','micrososot');
DeleteFile('C:\WINDOWS\system32\4cdd0.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\.Net C2LR\Parameters','ServiceDll');
DeleteFile('C:\Documents and Settings\All Users\Главное меню\Программы\Автозагрузка\smsrun.jse');
DeleteFile('C:\Documents and Settings\All Users\Главное меню\Программы\Автозагрузка\ra.vbe');
DeleteFile('C:\Documents and Settings\All Users\Application Data\lanmao.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\WmdmPmSN\Parameters','ServiceDll');
DeleteFile('C:\WINDOWS\system32\0AFD20F8.sys');
DeleteFile('C:\WINDOWS\TEMP\kb551178.gon');
DeleteFile('C:\WINDOWS\TEMP\kb208169.gon');
DeleteFile('C:\WINDOWS\system32\msctfime.iem');
DeleteFile('C:\WINDOWS\system32\dbr11005.tsp');
DeleteFile('C:\WINDOWS\system32\dbr09006.tsp');
DeleteFile('C:\WINDOWS\system32\dbr09006.ocx');
DeleteFile('C:\WINDOWS\system32\dbr06006.tsp');
DeleteFile('C:\WINDOWS\system32\dbr06006.ocx');
DeleteFile('c:\windows\system32\bxmrs.cc3');
DeleteFile('c:\windows\svhost7.exe');
DeleteFile('c:\windows\svhost6.exe');
DeleteFile('c:\windows\svhost4.exe');
DeleteFile('c:\documents and settings\all users\application data\lanmao.exe');
DeleteFile('c:\windows\system32\vo3j5xb1\f001.exe');
DeleteFile('c:\windows\system32\ajxtnjr4\d001.exe');
DeleteFile('c:\windows\system32\ckw7awiq\c010.exe');
DeleteFile('c:\windows\temp\b9a5c96.exe');
DeleteFile('c:\windows\temp\8797.exe');
DeleteFile('c:\windows\temp\3704.exe');
DeleteFile('c:\windows\temp\23641.exe');
DeleteFile('c:\windows\temp\1634.exe');
TerminateProcessByName('c:\windows\system32\ckw7awiq\c010.exe');
QuarantineFile('c:\windows\system32\ckw7awiq\c010.exe','');
TerminateProcessByName('c:\windows\system32\vo3j5xb1\f001.exe');
QuarantineFile('c:\windows\system32\vo3j5xb1\f001.exe','');
TerminateProcessByName('c:\windows\qqmusic.exe');
SetServiceStart('sreyfyu', 4);
StopService('sreyfyu');
SetServiceStart('8ї', 4);
DeleteService('8ї');
StopService('8ї');
DeleteService('sreyfyu');
DeleteService('djsak2');
QuarantineFile('C:\WINDOWS\system32\CKW7AWIQ\C010.exe','');
QuarantineFile('C:\WINDOWS\system32\VO3J5XB1\F001.exe','');
QuarantineFile('C:\WINDOWS\system32\7165ds.exe','');
QuarantineFile('C:\WINDOWS\QQMusic.exe','');
QuarantineFile('C:\WINDOWS\system32\bxmrs.cc3','');
QuarantineFile('C:\WINDOWS\system32\wacaprnlib.dll','');
DeleteFile('C:\WINDOWS\system32\wacaprnlib.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\WacSvc\Parameters','ServiceDll');
DeleteFile('C:\WINDOWS\system32\bxmrs.cc3');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Messenger\Parameters','ServiceDll');
DeleteFile('C:\WINDOWS\QQMusic.exe');
DeleteFile('C:\WINDOWS\system32\7165ds.exe');
DeleteFile('C:\WINDOWS\system32\VO3J5XB1\F001.exe');
DeleteFile('C:\WINDOWS\system32\CKW7AWIQ\C010.exe');
BC_DeleteSvc('djsak2');
BC_DeleteSvc('sreyfyu');
BC_DeleteSvc('8ї');
DeleteFile('c:\windows\system32\vo3j5xb1\f001.exe');
DeleteFile('c:\windows\system32\ckw7awiq\c010.exe');
BC_ImportAll;
ExecuteSysClean;
ExecuteWizard('TSW',2,2,true);
ExecuteRepair(9);
BC_Activate;
RebootWindows(true);
end.
После выполнения скрипта компьютер перезагрузится.