Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
TerminateProcessByName('c:\docume~1\admini~1\locals~1\temp\ipuels.exe');
TerminateProcessByName('c:\docume~1\admini~1\locals~1\temp\idwupkxxqvijgdipaqxf.exe');
QuarantineFile('C:\bltgqacrz.bat','');
QuarantineFile('C:\vdjuckk.bat','');
QuarantineFile('D:\autorun.inf','');
QuarantineFile('D:\vdjuckk.bat','');
QuarantineFile('F:\autorun.inf','');
QuarantineFile('F:\vdjuckk.bat','');
QuarantineFile('C:\DOCUME~1\KURNOS~1\LOCALS~1\Temp\7\xtnmiestnthjhfltfwenb.exe','');
QuarantineFile('C:\DOCUME~1\KURNOS~1\LOCALS~1\Temp\7\ulaulclhwxgdwpqt.exe','');
QuarantineFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xtnmiestnthjhfltfwenb.exe','');
QuarantineFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\vpheysedvzllhdhnxms.exe .','');
QuarantineFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ulaulclhwxgdwpqt.exe .','');
QuarantineFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ulaulclhwxgdwpqt.exe','');
QuarantineFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\f\ulaulclhwxgdwpqt.exe','');
QuarantineFile('c:\docume~1\admini~1\locals~1\temp\ipuels.exe','');
QuarantineFile('c:\docume~1\admini~1\locals~1\temp\idwupkxxqvijgdipaqxf.exe','');
DeleteFile('c:\docume~1\admini~1\locals~1\temp\idwupkxxqvijgdipaqxf.exe','32');
DeleteFile('c:\docume~1\admini~1\locals~1\temp\ipuels.exe','32');
DeleteFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\f\ulaulclhwxgdwpqt.exe','32');
DeleteFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ulaulclhwxgdwpqt.exe','32');
DeleteFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ulaulclhwxgdwpqt.exe .','32');
DeleteFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\vpheysedvzllhdhnxms.exe .','32');
DeleteFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xtnmiestnthjhfltfwenb.exe','32');
DeleteFile('C:\DOCUME~1\KURNOS~1\LOCALS~1\Temp\7\ulaulclhwxgdwpqt.exe','32');
DeleteFile('C:\DOCUME~1\KURNOS~1\LOCALS~1\Temp\7\xtnmiestnthjhfltfwenb.exe','32');
DeleteFile('F:\vdjuckk.bat','32');
DeleteFile('F:\autorun.inf','32');
DeleteFile('D:\vdjuckk.bat','32');
DeleteFile('D:\autorun.inf','32');
DeleteFile('C:\vdjuckk.bat','32');
DeleteFile('C:\bltgqacrz.bat','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Runonce','xdhqw');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run','otwe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ufocnybrav');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','bltgqacrz');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','xdhqw');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','otwe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','hln');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ufocnybrav','command');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','xdhqw');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','xdhqw');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','otwe');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','otwe');
BC_ImportALL;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
ExecuteWizard('TSW',2,2,true);
BC_Activate;
end.