Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\recycler\s-1-5-21-0243556031-888888379-781863308-61208711\zy126d0107.exe');
TerminateProcessByName('c:\users\admin\appdata\local\temp\wtoazpovqwl.exe');
TerminateProcessByName('c:\users\admin\appdata\local\temp\a1182.exe');
TerminateProcessByName('c:\recycler\s-1-5-21-0243556031-888888379-781863308-90811\75hg76.exe');
TerminateProcessByName('c:\recycler\s-1-5-21-0243556031-888888379-781863308-90624311\75455476.exe');
TerminateProcessByName('c:\recycler\s-1-5-21-0243556031-888888379-781863308-34212254\67788j1.exe');
TerminateProcessByName('c:\recycler\s-1-5-21-0243556031-888888379-781863308-3421154\618j1.exe');
TerminateProcessByName('c:\users\admin\appdata\local\temp\5r72p.exe');
ClearQuarantine;
QuarantineFile('G:\Tracker Software\PDF-XChange 4\Drivers\PrnInstaller.exe','');
QuarantineFile('C:\Program Files\Мобильный офис\USBDriverInstaller_x86.exe','');
QuarantineFile('H:\софт\260.89_notebook_winvista_win7_64bit_international_whql.exe','');
QuarantineFile('C:\Windows\System32\wsqmcons.exe','');
QuarantineFile('C:\Users\Admin\smss.exe','');
QuarantineFile('C:\Users\Admin\AppData\Roaming\Update\MSupdate.exe','');
QuarantineFile('C:\Users\Admin\AppData\Roaming\Identities\ovcen\ovcen.exe','');
QuarantineFile('C:\Users\Admin\AppData\Local\Temp\wtoazpovqwl.exe','');
QuarantineFile('C:\Users\Admin\AppData\Local\Temp\Adobe\Reader_sl.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-34212254\67788j1.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-6087311\7da5k656.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-61208711\zy126d0107.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-69024711\7d43ee3.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-69032111\7d43j31.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-69537311\7da5353.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-901137311\731j7376.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-90624311\75455476.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-90811\75hg76.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-3421154\618j1.exe','');
QuarantineFile('C:\ProgramData\CreativeAudio\xsytzecrn.exe','');
QuarantineFile('C:\PROGRA~2\mslrzz.exe','');
QuarantineFile('C:\PROGRA~2\mskey.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-61208711\zy126d0107.exe','');
QuarantineFile('c:\users\admin\appdata\local\temp\wtoazpovqwl.exe','');
QuarantineFile('c:\users\admin\appdata\local\temp\a1182.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-90811\75hg76.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-90624311\75455476.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-34212254\67788j1.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-3421154\618j1.exe','');
QuarantineFile('c:\users\admin\appdata\local\temp\5r72p.exe','');
DeleteFile('c:\users\admin\appdata\local\temp\5r72p.exe','32');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-3421154\618j1.exe','32');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-34212254\67788j1.exe','32');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-90624311\75455476.exe','32');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-90811\75hg76.exe','32');
DeleteFile('c:\users\admin\appdata\local\temp\a1182.exe','32');
DeleteFile('c:\users\admin\appdata\local\temp\wtoazpovqwl.exe','32');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-61208711\zy126d0107.exe','32');
DeleteFile('C:\PROGRA~2\mskey.exe','32');
DeleteFile('C:\PROGRA~2\mslrzz.exe','32');
DeleteFile('C:\ProgramData\CreativeAudio\xsytzecrn.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','248552041');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','1055042128');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','CreativeAudio');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-3421154\618j1.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-90811\75hg76.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-90624311\75455476.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-901137311\731j7376.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-69537311\7da5353.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-69032111\7d43j31.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','73hf521');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-69024711\7d43ee3.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-61208711\zy126d0107.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-6087311\7da5k656.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-34212254\67788j1.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','k186431');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','k886431');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','7a8k771');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','zy1725d0006');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','74ee3j1');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','743433j1');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','7a453531');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','731j771');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','732521');
DeleteFile('C:\Users\Admin\AppData\Local\Temp\Adobe\Reader_sl.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Adobe System Incorporated');
DeleteFile('C:\Users\Admin\AppData\Local\Temp\wtoazpovqwl.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','MicrosoftStCnt');
DeleteFile('C:\Users\Admin\AppData\Roaming\Identities\ovcen\ovcen.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Windows Update');
DeleteFile('C:\Users\Admin\AppData\Roaming\Update\MSupdate.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Windows Update Manager');
DeleteFile('C:\Users\Admin\smss.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','smss');
DeleteFile('C:\Windows\system32\Tasks\Windows Update Check - 0x0E7302EC','32');
BC_ImportAll;
ExecuteSysClean;
ExecuteWizard('TSW',2,2,true);
ExecuteWizard('SCU',2,2,true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.