Код:
begin
ExecuteAVUpdate;
SearchRootkit(true, true);
SetAVZGuardStatus(True);
StopService('dopuxire');
StopService('hypixyje');
StopService('zexufuve');
StopService('35D491D');
StopService('429B8A7');
StopService('4E5D8D2');
QuarantineFile('C:\Users\1\AppData\Local\Smart Island\{60822D1E-69F4-3924-1778-76B787ECC192}\hrsx.dll', '');
QuarantineFile('C:\Users\1\AppData\Local\Smart Island\{60822D1E-69F4-3924-1778-76B787ECC192}\{309A96AF-8F7D-999E-ABA5-769450750B58}.dat', '');
QuarantineFile('C:\Users\1\AppData\Local\Smart Island\{60822D1E-69F4-3924-1778-76B787ECC192}\SmartIsland.dll', '');
QuarantineFile('C:\ProgramData\ApplicationHosting\ApplicationHosting.exe', '');
QuarantineFile('C:\Users\TEMP\AppData\Local\581FC700-1427058836-11DE-BAB5-90E6BAB8671B\insb1EEC.tmp', '');
QuarantineFile('C:\Users\TEMP\AppData\Roaming\581FC700-1427046144-11DE-BAB5-90E6BAB8671B\nsf5D68.tmpfs', '');
QuarantineFile('C:\Program Files\581FC700-1449255592-11DE-BAB5-90E6BAB8671B\knsu6709.tmp', '');
QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQPCRtp.exe', '');
QuarantineFile('C:\Program Files\581FC700-1449255592-11DE-BAB5-90E6BAB8671B\jnswD9F9.tmp', '');
QuarantineFile('C:\Users\TEMP\AppData\Local\581FC700-1427057231-11DE-BAB5-90E6BAB8671B\snsr9B89.tmp', '');
QuarantineFile('C:\Windows\TEMP\35D491D.sys', '');
QuarantineFile('C:\Windows\TEMP\429B8A7.sys', '');
QuarantineFile('C:\Windows\TEMP\4E5D8D2.sys', '');
QuarantineFile('C:\Windows\system32\drivers\innfd_1_10_0_13.sys', '');
QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QMUdisk.sys', '');
QuarantineFile('C:\Windows\system32\drivers\swsedrvr_vt_1_10_0_25.sys', '');
QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TS888.sys', '');
QuarantineFile('C:\Windows\system32\DRIVERS\TSDEFENSEBT.SYS', '');
QuarantineFile('C:\Windows\SYSTEM32\DRIVERS\TSFLTMGR.SYS', '');
QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TSKsp.sys', '');
QuarantineFile('C:\Windows\system32\tssk.sys', '');
QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TSSysKit.sys', '');
QuarantineFile('C:\Users\TEMP\AppData\Local\581FC700-1427057035-11DE-BAB5-90E6BAB8671B\bnsfA0A8.exe', '');
QuarantineFile('C:\Users\1\AppData\Local\Microsoft\Windows\system.vbs', '');
QuarantineFile('C:\Users\TEMP\AppData\Local\SmartWeb\SmartWebHelper.exe', '');
QuarantineFile('C:\Users\1\AppData\Roaming\Microsoft\Windows\Protect\Windows Protect.exe', '');
QuarantineFile('C:\Program Files\Softobase\SoftobaseUpdater.exe', '');
QuarantineFile('C:\Users\1\AppData\Local\Mail.Ru\MailRuUpdater.exe', '');
QuarantineFile('C:\Users\1\AppData\Local\Kometa\Panel\KometaLaunchPanel.exe', '');
QuarantineFile('C:\Users\1\AppData\Roaming\eTranslator\eTranslator.exe', '');
QuarantineFile('C:\Users\1\AppData\Local\coprofit\coprofit_stb.exe', '');
QuarantineFile('C:\Users\1\AppData\Local\coprofit\config.json', '');
QuarantineFile('C:\Users\1\AppData\Roaming\mydive\vosst1.vbs', '');
QuarantineFile('C:\ProgramData\Tmp0x0x\P', '');
QuarantineFile('C:\ProgramData\Kbupdater Utility\kbupdater-utility.exe', '');
QuarantineFile('C:\Users\1\AppData\Local\Microsoft\Extensions\safebrowser.exe', '');
QuarantineFile('C:\ProgramData\IbRjYiMDBRSC\YmqBUBCxsL0.bat', '');
QuarantineFile('C:\Users\1\AppData\Local\XvovgEhnxurrvzL\sBFdrXNBDENmgh0.bat', '');
QuarantineFile('C:\Program Files\Common Files\{C9E3BD8C-E2D3-4E6E-8908-251F83973C09}\0.8', '');
QuarantineFile('C:\Users\1\AppData\Local\nrIIWMyetwdrxKN\OawnIqL1.bat', '');
QuarantineFile('C:\Users\1\AppData\Local\Mail.Ru\Sputnik\IESearchPlugin.dll', '');
QuarantineFile('C:\PROGRA~1\GROOVE~2\Ilaeea.bat', '');
QuarantineFile('C:\Program Files\OLBPre\OLBPre.exe', '');
QuarantineFile('C:\Users\1\AppData\Roaming\WindowsUpdater\Updater.exe', '');
QuarantineFile('C:\Users\1\appdata\local\smartweb\__u.exe', '');
DeleteFile('C:\Users\1\AppData\Local\Smart Island\{60822D1E-69F4-3924-1778-76B787ECC192}\hrsx.dll', '32');
DeleteFile('C:\Users\1\AppData\Local\Smart Island\{60822D1E-69F4-3924-1778-76B787ECC192}\{309A96AF-8F7D-999E-ABA5-769450750B58}.dat', '32');
DeleteFile('C:\Users\1\AppData\Local\Smart Island\{60822D1E-69F4-3924-1778-76B787ECC192}\SmartIsland.dll', '32');
DeleteFile('C:\ProgramData\ApplicationHosting\ApplicationHosting.exe', '32');
DeleteFile('C:\Users\TEMP\AppData\Local\581FC700-1427058836-11DE-BAB5-90E6BAB8671B\insb1EEC.tmp', '32');
DeleteFile('C:\Users\TEMP\AppData\Roaming\581FC700-1427046144-11DE-BAB5-90E6BAB8671B\nsf5D68.tmpfs', '32');
DeleteFile('C:\Program Files\581FC700-1449255592-11DE-BAB5-90E6BAB8671B\knsu6709.tmp', '32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQPCRtp.exe', '32');
DeleteFile('C:\Program Files\581FC700-1449255592-11DE-BAB5-90E6BAB8671B\jnswD9F9.tmp', '32');
DeleteFile('C:\Users\TEMP\AppData\Local\581FC700-1427057231-11DE-BAB5-90E6BAB8671B\snsr9B89.tmp', '32');
DeleteFile('C:\Windows\TEMP\35D491D.sys', '32');
DeleteFile('C:\Windows\TEMP\429B8A7.sys', '32');
DeleteFile('C:\Windows\TEMP\4E5D8D2.sys', '32');
DeleteFile('C:\Windows\system32\drivers\innfd_1_10_0_13.sys', '32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QMUdisk.sys', '32');
DeleteFile('C:\Windows\system32\drivers\swsedrvr_vt_1_10_0_25.sys', '32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TS888.sys', '32');
DeleteFile('C:\Windows\system32\DRIVERS\TSDEFENSEBT.SYS', '32');
DeleteFile('C:\Windows\SYSTEM32\DRIVERS\TSFLTMGR.SYS', '32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TSKsp.sys', '32');
DeleteFile('C:\Windows\system32\tssk.sys', '32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TSSysKit.sys', '32');
DeleteFile('C:\Users\TEMP\AppData\Local\581FC700-1427057035-11DE-BAB5-90E6BAB8671B\bnsfA0A8.exe', '32');
DeleteFile('C:\Users\1\AppData\Local\Microsoft\Windows\system.vbs', '32');
DeleteFile('C:\Users\TEMP\AppData\Local\SmartWeb\SmartWebHelper.exe', '32');
DeleteFile('C:\Users\1\AppData\Roaming\Microsoft\Windows\Protect\Windows Protect.exe', '32');
DeleteFile('C:\Program Files\Softobase\SoftobaseUpdater.exe', '32');
DeleteFile('C:\Users\1\AppData\Local\Mail.Ru\MailRuUpdater.exe', '32');
DeleteFile('C:\Users\1\AppData\Local\Kometa\Panel\KometaLaunchPanel.exe', '32');
DeleteFile('C:\Users\1\AppData\Roaming\eTranslator\eTranslator.exe', '32');
DeleteFile('C:\Users\1\AppData\Local\coprofit\coprofit_stb.exe', '32');
DeleteFile('C:\Users\1\AppData\Local\coprofit\config.json', '32');
DeleteFile('C:\Users\1\AppData\Roaming\mydive\vosst1.vbs', '32');
DeleteFile('C:\ProgramData\Tmp0x0x\P', '32');
DeleteFile('C:\ProgramData\Kbupdater Utility\kbupdater-utility.exe', '32');
DeleteFile('C:\Users\1\AppData\Local\Microsoft\Extensions\safebrowser.exe', '32');
DeleteFile('C:\ProgramData\IbRjYiMDBRSC\YmqBUBCxsL0.bat', '32');
DeleteFile('C:\Users\1\AppData\Local\XvovgEhnxurrvzL\sBFdrXNBDENmgh0.bat', '32');
DeleteFile('C:\Program Files\Common Files\{C9E3BD8C-E2D3-4E6E-8908-251F83973C09}\0.8', '32');
DeleteFile('C:\Users\1\AppData\Local\nrIIWMyetwdrxKN\OawnIqL1.bat', '32');
DeleteFile('C:\Users\1\AppData\Local\Mail.Ru\Sputnik\IESearchPlugin.dll', '32');
DeleteFile('C:\PROGRA~1\GROOVE~2\Ilaeea.bat', '32');
DeleteFile('C:\Program Files\OLBPre\OLBPre.exe', '32');
DeleteFile('C:\Users\1\AppData\Roaming\WindowsUpdater\Updater.exe', '32');
DeleteFile('C:\Users\1\appdata\local\smartweb\__u.exe', '32');
DeleteService('ApplicationHosting');
DeleteService('dopuxire');
DeleteService('hypixyje');
DeleteService('hyvugyti');
DeleteService('QQPCRtp');
DeleteService('roqenufe');
DeleteService('zexufuve');
DeleteService('35D491D');
DeleteService('429B8A7');
DeleteService('4E5D8D2');
DeleteService('innfd_1_10_0_13');
DeleteService('QMUdisk');
DeleteService('swsedrvr_vt_1_10_0_25');
DeleteService('TS888');
DeleteService('TsDefenseBt');
DeleteService('TsFltMgr');
DeleteService('Tsksp');
DeleteService('TSSK');
DeleteService('TSSysKit');
DeleteFileMask('C:\Users\1\AppData\Local\Smart Island', '*', true);
DeleteFileMask('C:\ProgramData\ApplicationHosting', '*', true);
DeleteFileMask('C:\Program Files\Tencent', '*', true);
DeleteFileMask('C:\Users\1\AppData\Roaming\Microsoft\Windows\Protect', '*', true);
DeleteFileMask('C:\Program Files\Softobase', '*', true);
DeleteFileMask('C:\Users\1\AppData\Local\Mail.Ru', '*', true);
DeleteFileMask('C:\Users\1\AppData\Local\Kometa', '*', true);
DeleteFileMask('C:\Users\1\AppData\Roaming\eTranslator', '*', true);
DeleteFileMask('C:\Users\1\AppData\Local\coprofit', '*', true);
DeleteFileMask('C:\ProgramData\Tmp0x0x', '*', true);
DeleteFileMask('C:\ProgramData\Kbupdater Utility', '*', true);
DeleteFileMask('C:\Users\1\AppData\Local\Microsoft\Extensions', '*', true);
DeleteFileMask('C:\Program Files\OLBPre', '*', true);
DeleteFileMask('C:\Users\1\AppData\Roaming\WindowsUpdater', '*', true);
DeleteFileMask('C:\Users\1\appdata\local\smartweb', '*', true);
DeleteDirectory('C:\Users\1\AppData\Local\Smart Island');
DeleteDirectory('C:\ProgramData\ApplicationHosting');
DeleteDirectory('C:\Program Files\Tencent');
DeleteDirectory('C:\Users\1\AppData\Roaming\Microsoft\Windows\Protect');
DeleteDirectory('C:\Program Files\Softobase');
DeleteDirectory('C:\Users\1\AppData\Local\Mail.Ru');
DeleteDirectory('C:\Users\1\AppData\Local\Kometa');
DeleteDirectory('C:\Users\1\AppData\Roaming\eTranslator');
DeleteDirectory('C:\Users\1\AppData\Local\coprofit');
DeleteDirectory('C:\ProgramData\Tmp0x0x');
DeleteDirectory('C:\ProgramData\Kbupdater Utility');
DeleteDirectory('C:\Users\1\AppData\Local\Microsoft\Extensions');
DeleteDirectory('C:\Program Files\OLBPre');
DeleteDirectory('C:\Users\1\AppData\Roaming\WindowsUpdater');
DeleteDirectory('C:\Users\1\appdata\local\smartweb');
DelBHO('{8E8F97CD-60B5-456F-A201-73065652D099}');
ExecuteFile('schtasks.exe', '/delete /TN "Havmixc" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "LaunchPreSignup" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Smart Island" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Smart Island2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "WindowsUpdater" /F', 0, 15000, true);
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'WinCheck');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'SystemScript');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'SmartWeb');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Windows Protect');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Softobase');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'MailRuUpdater');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'KometaLaunchPanel');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'eTranslator Update');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'coprofit');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'vosst');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.