Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\users\Светик\appdata\local\gmsd_ru_005010238\upgmsd_ru_005010238.exe');
TerminateProcessByName('C:\Users\Светик\AppData\Local\gmsd_ru_005010238\Download\wizzupdater.exe');
QuarantineFile('c:\users\Светик\appdata\local\gmsd_ru_005010238\upgmsd_ru_005010238.exe', '');
QuarantineFile('C:\Program Files\WajaNetEn\b6068e2dd7db19c83ca2fa3c131e16b6.exe', '');
QuarantineFile('C:\Users\Светик\AppData\Local\gmsd_ru_005010238\Download\wizzupdater.exe', ''
QuarantineFile('C:\Windows\system32\drivers\ccnfd_1_10_0_5.sys', '');
QuarantineFile('C:\Program Files\gmsd_ru_005010238\gmsd_ru_005010238.exe', '');
QuarantineFile('C:\Program Files\Mail.Ru\Guard\GuardMailRu.exe', '');
QuarantineFile('C:\Users\Светик\AppData\Local\Mail.Ru\MailRuUpdater.exe', '');
QuarantineFile('C:\Program Files\rec_ru_199\rec_ru_199.exe', '');
QuarantineFile('C:\Program Files\rec_ru_200\rec_ru_200.exe', '');
QuarantineFile('C:\Program Files\rec_ru_204\rec_ru_204.exe', '');
QuarantineFile('C:\Program Files\rec_ru_205\rec_ru_205.exe', '');
QuarantineFile('C:\Program Files\rec_ru_209\rec_ru_209.exe', '');
QuarantineFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe', '');
QuarantineFile('C:\ProgramData\TimeTasks\timetasks.exe', '');
QuarantineFile('C:\Program Files\Zaxar\ZaxarGameBrowser.exe', '');
QuarantineFile('C:\Program Files\Zaxar\ZaxarLoader.exe', '');
QuarantineFile('C:\Program Files\NewExt\nssm.exe', '');
QuarantineFile('C:\Users\DBFE~1\AppData\Local\Temp\svchosts.exe', '');
QuarantineFile('C:\ProgramData\GWhnAm\LewCNqpw5.bat', '');
QuarantineFile('C:\ProgramData\wAEscnzNY\XHdmnPoqb1.bat', '');
DeleteFile('C:\Windows\Tasks\Sentry.UUYZXSBRRAAOKWGV7INNXACQRQ.restart.job', '32');
DeleteFile('c:\users\Светик\appdata\local\gmsd_ru_005010238\upgmsd_ru_005010238.exe', '32');
DeleteFile('C:\Program Files\WajaNetEn\b6068e2dd7db19c83ca2fa3c131e16b6.exe', '32');
DeleteFile('C:\Windows\system32\drivers\ccnfd_1_10_0_5.sys', '32');
DeleteFile('C:\Program Files\gmsd_ru_005010238\gmsd_ru_005010238.exe', '32');
DeleteFile('C:\Program Files\Mail.Ru\Guard\GuardMailRu.exe', '32');
DeleteFile('C:\Users\Светик\AppData\Local\Mail.Ru\MailRuUpdater.exe', '32');
DeleteFile('C:\Program Files\rec_ru_199\rec_ru_199.exe', '32');
DeleteFile('C:\Program Files\rec_ru_200\rec_ru_200.exe', '32');
DeleteFile('C:\Program Files\rec_ru_204\rec_ru_204.exe', '32');
DeleteFile('C:\Program Files\rec_ru_205\rec_ru_205.exe', '32');
DeleteFile('C:\Program Files\rec_ru_209\rec_ru_209.exe', '32');
DeleteFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe', '32');
DeleteFile('C:\ProgramData\TimeTasks\timetasks.exe', '32');
DeleteFile('C:\Program Files\Zaxar\ZaxarGameBrowser.exe', '32');
DeleteFile('C:\Program Files\Zaxar\ZaxarLoader.exe', '32');
DeleteFile('C:\Program Files\NewExt\nssm.exe', '32');
DeleteFile('C:\Users\DBFE~1\AppData\Local\Temp\svchosts.exe', '32');
DeleteFile('C:\ProgramData\GWhnAm\LewCNqpw5.bat', '32');
DeleteFile('C:\ProgramData\wAEscnzNY\XHdmnPoqb1.bat', '32');
DeleteFile('C:\Users\Светик\AppData\Local\Amigo\Application\amigo.exe', '32');
DeleteFile('sentry.exe', '32');
DeleteFile('C:\ProgramData\UpService\UpService.exe', '32');
DeleteService('WajaNetEn Monitor');
DeleteService('ccnfd_1_10_0_5');
DeleteFileMask('C:\Program Files\WajaNetEn', '*', true);
DeleteFileMask('C:\Program Files\Mail.Ru', '*', true);
DeleteFileMask('C:\Users\Светик\AppData\Local\Mail.Ru', '*', true);
DeleteFileMask('C:\Program Files\rec_ru', '*', true);
DeleteFileMask('C:\Program Files\SpaceSoundPro', '*', true);
DeleteFileMask('C:\Program Files\Zaxar', '*', true);
DeleteFileMask('C:\Users\Светик\AppData\Local\Amigo', '*', true);
DeleteFileMask('C:\ProgramData\UpService', '*', true);
DeleteDirectory('C:\Program Files\WajaNetEn');
DeleteDirectory('C:\Program Files\Mail.Ru');
DeleteDirectory('C:\Users\Светик\AppData\Local\Mail.Ru');
DeleteDirectory('C:\Program Files\rec_ru');
DeleteDirectory('C:\Program Files\SpaceSoundPro');
DeleteDirectory('C:\Program Files\Zaxar');
DeleteDirectory('C:\Users\Светик\AppData\Local\Amigo');
DeleteDirectory('C:\ProgramData\UpService');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "UpService" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Sentry.UUYZXSBRRAAOKWGV7INNXACQRQ" /F', 0, 15000, true);
BC_ImportALL;
ExecuteSysClean;
ExecuteRepair(22);
ExecuteRepair(23);
ExecuteRepair(13);
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.