begin ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true); SearchRootkit(true, true); SetAVZGuardStatus(True); TerminateProcessByName('c:\documents and settings\user\application data\80cd37bf-1427823888-d411-82c7-0013a944bc6d\jnsd93.tmp'); StopService('nypikyjy'); QuarantineFile('C:\WINDOWS\system32\drivers\ccnfd_1_10_0_4.sys',''); QuarantineFile('c:\documents and settings\user\application data\80cd37bf-1427823888-d411-82c7-0013a944bc6d\jnsd93.tmp', ''); QuarantineFile('C:\Documents and Settings\user\Application Data\Browsers\exe.emorhc.bat', ''); QuarantineFile('C:\Documents and Settings\user\Application Data\Browsers\exe.erolpxei.bat', ''); DeleteFile('C:\WINDOWS\system32\drivers\ccnfd_1_10_0_4.sys','32'); DeleteFile('c:\documents and settings\user\application data\80cd37bf-1427823888-d411-82c7-0013a944bc6d\jnsd93.tmp', '32'); DeleteFile('C:\Documents and Settings\user\Application Data\Browsers\exe.emorhc.bat', '32'); DeleteFile('C:\Documents and Settings\user\Application Data\Browsers\exe.erolpxei.bat', '32'); DeleteService('ccnfd_1_10_0_4'); DeleteService('nypikyjy'); BC_ImportALL; ExecuteSysClean; BC_Activate; ExecuteWizard('SCU', 2, 3, true); RebootWindows(true); end.