Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\program files\00000000-1448283910-0000-0000-001d7dd1f5e3\hnsh1b4.tmp');
TerminateProcessByName('c:\program files\00000000-1448283910-0000-0000-001d7dd1f5e3\jnsm1a6.tmp');
TerminateProcessByName('c:\docume~1\07c4~1\locals~1\temp\nsw38.tmp');
TerminateProcessByName('c:\docume~1\07c4~1\locals~1\temp\nsw95.tmp');
TerminateProcessByName('c:\documents and settings\Алексей\local settings\application data\00000000-1448334776-0000-0000-001d7dd1f5e3\qnsi7c.tmp');
TerminateProcessByName('c:\documents and settings\Алексей\local settings\application data\00000000-1448298356-0000-0000-001d7dd1f5e3\snsh1f4.tmp');
StopService('kunitile');
StopService('xeqywyby');
StopService('zexovuji');
StopService('4587AC435F701424');
QuarantineFile('c:\program files\00000000-1448283910-0000-0000-001d7dd1f5e3\hnsh1b4.tmp', '');
QuarantineFile('c:\program files\00000000-1448283910-0000-0000-001d7dd1f5e3\jnsm1a6.tmp', '');
QuarantineFile('c:\docume~1\07c4~1\locals~1\temp\nsw38.tmp', '');
QuarantineFile('c:\docume~1\07c4~1\locals~1\temp\nsw95.tmp', '');
QuarantineFile('c:\documents and settings\Алексей\local settings\application data\00000000-1448334776-0000-0000-001d7dd1f5e3\qnsi7c.tmp', '');
QuarantineFile('c:\documents and settings\Алексей\local settings\application data\00000000-1448298356-0000-0000-001d7dd1f5e3\snsh1f4.tmp', '');
QuarantineFile('C:\DOCUME~1\07C4~1\LOCALS~1\Temp\nsz98.tmp\Math.dll', '');
QuarantineFile('C:\DOCUME~1\07C4~1\LOCALS~1\Temp\nsz98.tmp\nsCBHTML5.dll', '');
QuarantineFile('c:\documents and settings\администратор\local settings\temp\D6234440-495FEF40-18C13F8-2D17E2C8\768192da85.sys', '');
QuarantineFile('C:\Documents and Settings\Алексей\Application Data\repulsion_1033\s_inst.exe', '');
QuarantineFile('C:\Documents and Settings\Алексей\Application Data\WindowsUpdater\Updater.exe', '');
DeleteFile('c:\program files\00000000-1448283910-0000-0000-001d7dd1f5e3\hnsh1b4.tmp', '32');
DeleteFile('c:\program files\00000000-1448283910-0000-0000-001d7dd1f5e3\jnsm1a6.tmp', '32');
DeleteFile('c:\docume~1\07c4~1\locals~1\temp\nsw38.tmp', '32');
DeleteFile('c:\docume~1\07c4~1\locals~1\temp\nsw95.tmp', '32');
DeleteFile('c:\documents and settings\Алексей\local settings\application data\00000000-1448334776-0000-0000-001d7dd1f5e3\qnsi7c.tmp', '32');
DeleteFile('c:\documents and settings\Алексей\local settings\application data\00000000-1448298356-0000-0000-001d7dd1f5e3\snsh1f4.tmp', '32');
DeleteFile('C:\DOCUME~1\07C4~1\LOCALS~1\Temp\nsz98.tmp\Math.dll', '32');
DeleteFile('C:\DOCUME~1\07C4~1\LOCALS~1\Temp\nsz98.tmp\nsCBHTML5.dll', '32');
DeleteFile('c:\documents and settings\администратор\local settings\temp\D6234440-495FEF40-18C13F8-2D17E2C8\768192da85.sys', '32');
DeleteFile('C:\Program Files\SmartSaver+ 15\1cf28f6a-6d0b-4255-a4c9-552367005f19.exe', '32');
DeleteFile('C:\Documents and Settings\Алексей\Local Settings\Application Data\Mail.Ru\MailRuUpdater.exe', '32');
DeleteFile('C:\Documents and Settings\Application', '32');
DeleteFile('C:\Documents and Settings\Алексей\Application Data\repulsion_1033\s_inst.exe', '32');
DeleteFile('C:\Documents and Settings\Алексей\Application Data\WindowsUpdater\Updater.exe', '32');
DeleteFile('C:\Documents and Settings\All Users\Application Data\AlterGeo\Update', '32');
DeleteService('kunitile');
DeleteService('xeqywyby');
DeleteService('zexovuji');
DeleteService('4587AC435F701424');
DeleteService('nypikyjy');
DeleteService('benyhuse');
DeleteService('Updater.Mail.Ru');
DeleteFileMask('C:\Program Files\SmartSaver+ 15', '*', true);
DeleteFileMask('C:\Documents and Settings\Алексей\Application Data\repulsion_1033', '*', true);
DeleteFileMask('C:\Documents and Settings\Алексей\Application Data\WindowsUpdater', '*', true);
DeleteDirectory('C:\Program Files\SmartSaver+ 15');
DeleteDirectory('C:\Documents and Settings\Алексей\Application Data\repulsion_1033');
DeleteDirectory('C:\Documents and Settings\Алексей\Application Data\WindowsUpdater');
ExecuteFile('schtasks.exe', '/delete /TN "1cf28f6a-6d0b-4255-a4c9-552367005f19b" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "MailRuUpdateTask" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "OXDX" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "PDMA" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "repulsion_1033" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "WindowsUpdater" /F', 0, 15000, true);
BC_ImportALL;
ExecuteSysClean;
BC_DeleteSvc('zexovuji');
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.