Код:
begin
TerminateProcessByName('c:\progra~1\common files\sogou.exe');
DelCLSID('{9FC6AA6A-86E6-4F28-B87B-CBA71435C390}');
QuarantineFile('C:\WINDOWS\system32\winhelp32.exe','');
QuarantineFile('C:\WINDOWS\system32\ntcsvr.exe','');
QuarantineFile('C:\WINDOWS\System32\FileName.jpg','');
QuarantineFile('C:\WINDOWS\WinSxS\x86_Microsoft.Windows.WinHTTP_6595b64144ccf1df_5.1.3790.4929_x-ww_00269083\winhttp.dll','');
QuarantineFile('C:\WINDOWS\system32\RcmrtqC.dll','');
QuarantineFile('C:\WINDOWS\system32\Server.dll','');
QuarantineFile('C:\Windows\System32\Rspdateseq.dll','');
QuarantineFile('C:\progra~1\Common Files\Sogou.exe','');
QuarantineFile('C:\Windows\svchosts.exe','');
QuarantineFile('C:\WINDOWS\XXXXXXA3155759\svchsot.exe','');
QuarantineFile('C:\WINDOWS\0C89D327\svchsot.exe','');
QuarantineFile('C:\WINDOWS\56B06D10\svchsot.exe','');
QuarantineFile('C:\WINDOWS\8A69C25E\svchsot.exe','');
QuarantineFile('C:\WINDOWS\CBF27CB9\svchsot.exe','');
QuarantineFile('C:\WINDOWS\FileName.jpg','');
QuarantineFile('C:\RECYCLER\woai.exe','');
QuarantineFile('C:\Program Files\Windows NT\gserver.exe','');
QuarantineFile('C:\Program Files\Itje\Pdmvaulhv.jpg','');
QuarantineFile('C:\Program Files\Iefg\Nefghijkl.pic','');
QuarantineFile('C:\1852400.dll','');
QuarantineFile('C:\WINDOWS\system32\qgwiue.exe','');
QuarantineFile('C:\WINDOWS\system32\WinHbdx32.exe','');
QuarantineFile('C:\WINDOWS\system32\WinHacc32.exe','');
QuarantineFile('C:\WINDOWS\system32\WinHelp32.exe','');
QuarantineFile('C:\WINDOWS\system32\sqlserv.exe','');
QuarantineFile('C:\WINDOWS\system32\xs.exe','');
QuarantineFile('C:\WINDOWS\system32\s1433.exe','');
QuarantineFile('C:\WINDOWS\system32\zqhvgu.exe','');
QuarantineFile('C:\WINDOWS\system32\Sougou.exe','');
QuarantineFile('C:\WINDOWS\WinSxS\x86_Microsoft.Windows.WinHTTP_6595b64144ccf1df_5.1.3790.4929_x-ww_00269083\WINHTTP.dll','');
QuarantineFile('c:\windows\system32\rspdateseq.dll','');
QuarantineFile('c:\windows\system32\filename.jpg','');
QuarantineFile('c:\progra~1\common files\sogou.exe','');
DeleteFile('c:\progra~1\common files\sogou.exe');
DeleteFile('c:\windows\system32\filename.jpg');
DeleteFile('c:\windows\system32\rspdateseq.dll');
DeleteFile('C:\WINDOWS\system32\Sougou.exe');
DeleteFile('C:\WINDOWS\system32\zqhvgu.exe');
DeleteFile('C:\WINDOWS\system32\s1433.exe');
DeleteFile('C:\WINDOWS\system32\xs.exe');
DeleteFile('C:\WINDOWS\system32\sqlserv.exe');
DeleteFile('C:\WINDOWS\system32\WinHelp32.exe');
DeleteFile('C:\WINDOWS\system32\WinHacc32.exe');
DeleteFile('C:\WINDOWS\system32\WinHbdx32.exe');
DeleteFile('C:\WINDOWS\system32\qgwiue.exe');
DeleteFile('C:\1852400.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\RemoteAccess\RouterManagers\Ip','DLLPath');
DeleteFile('C:\Program Files\Iefg\Nefghijkl.pic');
DeleteFileMask('C:\Program Files\Iefg','*',true);
DeleteDirectory('C:\Program Files\Iefg');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Defghi Klmnopqr Tuv\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Nplert Xiopiytj Qld\Parameters','ServiceDll');
DeleteFile('C:\Program Files\Itje\Pdmvaulhv.jpg');
DeleteFileMask('C:\Program Files\Itje','*',true);
DeleteDirectory('C:\Program Files\Itje');
DeleteFile('C:\RECYCLER\woai.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Aut2');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','vvt');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','xuegou');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','acao');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','0C89D327');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','56B06D10');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','8A69C25E');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','CBF27CB9');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Please Input Service Name\Parameters','ServiceDll');
DeleteFile('C:\WINDOWS\FileName.jpg');
DeleteFile('C:\WINDOWS\CBF27CB9\svchsot.exe');
DeleteFileMask('C:\WINDOWS\CBF27CB9','*',true);
DeleteDirectory('C:\WINDOWS\CBF27CB9');
DeleteFile('C:\WINDOWS\8A69C25E\svchsot.exe');
DeleteFileMask('C:\WINDOWS\8A69C25E','*',true);
DeleteDirectory('C:\WINDOWS\8A69C25E');
DeleteFile('C:\WINDOWS\56B06D10\svchsot.exe');
DeleteFileMask('C:\WINDOWS\56B06D10','*',true);
DeleteDirectory('C:\WINDOWS\56B06D10');
DeleteFile('C:\WINDOWS\0C89D327\svchsot.exe');
DeleteFileMask('C:\WINDOWS\0C89D327','*',true);
DeleteDirectory('C:\WINDOWS\0C89D327');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gserver');
DeleteFile('C:\Program Files\Windows NT\gserver.exe');
DeleteFileMask('C:\Program Files\Windows NT','*',true);
DeleteDirectory('C:\Program Files\Windows NT');
DeleteFile('C:\WINDOWS\XXXXXXA3155759\svchsot.exe');
DeleteFileMask('C:\WINDOWS\XXXXXXA3155759','*',true);
DeleteDirectory('C:\WINDOWS\XXXXXXA3155759');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','XXXXXXA3155759');
DeleteFile('C:\Windows\svchosts.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','360.');
DeleteFile('C:\progra~1\Common Files\Sogou.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Ball');
DeleteFile('C:\Windows\System32\Rspdateseq.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Rspdates Apxplicatioan\Parameters','ServiceDll');
DeleteFile('C:\WINDOWS\system32\Server.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Microsoft Devicger\Parameters','ServiceDll');
DeleteFile('C:\WINDOWS\system32\RcmrtqC.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\MediasCenter\Parameters','ServiceDll');
DeleteFile('C:\WINDOWS\System32\FileName.jpg');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Please SeRSice Name\Parameters','ServiceDll');
DeleteFile('C:\WINDOWS\system32\ntcsvr.exe');
DeleteFile('C:\WINDOWS\system32\winhelp32.exe');
BC_ImportAll;
ExecuteSysClean;
BC_DeleteSvc('netscvre');
BC_DeleteSvc('oejuvpvabo');
BC_DeleteSvc('aspnet server');
BC_DeleteSvc('tlnsrv');
BC_DeleteSvc('WinHelp32');
BC_DeleteSvc('WinHlme32');
BC_DeleteSvc('WinHyuh32');
BC_DeleteSvc('DirectX jrq');
BC_DeleteSvc('xhatmuudqb');
BC_Activate;
end.