Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFileF('c:\programdata\microsoft\macromed\flash player\dbc9c0fe-9696-4b56-8689-ea7c2a653284', '*', true, '', 0 ,0);
QuarantineFileF('c:\users\mystery\appdata\local\microsoft\extensions', '*', true, '', 0 ,0);
QuarantineFile('C:\ProgramData\Microsoft\Macromed\Flash Player\DBC9C0FE-9696-4B56-8689-EA7C2A653284\C848EB57-DB3C-46BB-8C54-4DA071A1F814.exe', '');
QuarantineFile('C:\Users\Mystery\AppData\Local\Microsoft\Extensions\extsetup.exe', '');
ExecuteFile('schtasks.exe', '/delete /TN "extsetup" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SafeBrowser" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ADBC9C0FE-9696-4B56-8689-EA7C2A653284" /F', 0, 15000, true);
DeleteFile('C:\ProgramData\Microsoft\Macromed\Flash Player\DBC9C0FE-9696-4B56-8689-EA7C2A653284\C848EB57-DB3C-46BB-8C54-4DA071A1F814.exe', '32');
DeleteFile('C:\Users\Mystery\AppData\Local\Microsoft\Extensions\extsetup.exe', '32');
DeleteFileMask('c:\users\mystery\appdata\local\microsoft\extensions', '*', true);
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','DBC9C0FE-9696-4B56-8689-EA7C2A653284');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','SafeBrowser');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
Компьютер