Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\Program Files (x86)\YTDownloader\YTDownloader.exe','');
QuarantineFile('C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.1390\jsdrv.exe','');
QuarantineFile('C:\Program Files (x86)\ShopperPro\updater.exe','');
QuarantineFile('C:\Program Files (x86)\winter web\winter_web_notification_service.exe','');
QuarantineFile('C:\Users\1\AppData\Roaming\SFPECH.exe','');
QuarantineFile('C:\Users\1\AppData\Roaming\PYAVA.exe','');
QuarantineFile('C:\Program Files (x86)\mr fun\mr_fun_updating_service.exe','');
QuarantineFile('C:\Program Files (x86)\mr fun\mr_fun_notification_service.exe','');
QuarantineFile('C:\Program Files (x86)\Mega Shop\mega_shop_helper_service.exe','');
QuarantineFile('C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe','');
QuarantineFile('C:\Program Files (x86)\fun coupons\fun_coupons_notification_service.exe','');
QuarantineFile('C:\Program Files (x86)\HQ-Video-Pro-2.1cV31.10\f5318192-afe1-462c-b8ef-60f7051e7767-5.exe','');
QuarantineFile('C:\Program Files (x86)\HQ-Video-Pro-2.1cV31.10\f5318192-afe1-462c-b8ef-60f7051e7767-4.exe','');
QuarantineFile('C:\Program Files (x86)\HQ-Video-Pro-2.1cV31.10\f5318192-afe1-462c-b8ef-60f7051e7767-3.exe','');
QuarantineFile('C:\Program Files (x86)\HQ-Video-Pro-2.1cV31.10\f5318192-afe1-462c-b8ef-60f7051e7767-11.exe','');
QuarantineFile('C:\Program Files (x86)\HQ-Video-Pro-2.1cV31.10\HQ-Video-Pro-2.1cV31.10-codedownloader.exe','');
QuarantineFile('C:\Users\1\AppData\Roaming\CXR.exe','');
QuarantineFile('C:\Users\1\AppData\Roaming\ASTWJAG.exe','');
QuarantineFile('C:\Program Files (x86)\Ge-Force\a72ea835-0f0f-4c6c-96f0-00c04f46e4b5-5.exe','');
QuarantineFile('C:\Program Files (x86)\Ge-Force\a72ea835-0f0f-4c6c-96f0-00c04f46e4b5-4.exe','');
QuarantineFile('C:\Program Files (x86)\Ge-Force\a72ea835-0f0f-4c6c-96f0-00c04f46e4b5-11.exe','');
QuarantineFile('C:\Program Files (x86)\Ge-Force\Ge-Force-codedownloader.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\9f9459ba-b822-4db2-b7bd-11dc564798ee-5.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\9f9459ba-b822-4db2-b7bd-11dc564798ee-4.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\9f9459ba-b822-4db2-b7bd-11dc564798ee-11.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-codedownloader.exe','');
QuarantineFile('C:\Program Files (x86)\48 dresses\48_dresses_notification_service.exe','');
QuarantineFile('C:\Windows\system32\drivers\sbmntr.sys','');
QuarantineFile('C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe','');
DeleteFile('C:\Program Files (x86)\winter web\winter_web_notification_service.exe');
DeleteFile('C:\Program Files (x86)\fun coupons\fun_coupons_notification_service.exe');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-codedownloader.exe');
DeleteFile('C:\Program Files (x86)\48 dresses\48_dresses_notification_service.exe');
DeleteFile('C:\Windows\system32\drivers\sbmntr.sys');
DeleteFile('C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe','32');
DeleteFile('C:\Program Files (x86)\Sense\Sense-codedownloader.exe','32');
DeleteFile('C:\Windows\Tasks\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-1.job','32');
DeleteFile('C:\Program Files (x86)\Sense\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-11.exe','32');
DeleteFile('C:\Windows\Tasks\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-11.job','32');
DeleteFile('C:\Program Files (x86)\Sense\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-2.exe','32');
DeleteFile('C:\Windows\Tasks\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-2.job','32');
DeleteFile('C:\Program Files (x86)\Sense\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-3.exe','32');
DeleteFile('C:\Windows\Tasks\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-3.job','32');
DeleteFile('C:\Program Files (x86)\Sense\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-4.exe','32');
DeleteFile('C:\Windows\Tasks\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-4.job','32');
DeleteFile('C:\Program Files (x86)\Sense\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-5.exe','32');
DeleteFile('C:\Windows\Tasks\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-5.job','32');
DeleteFile('C:\Windows\Tasks\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-5_user.job','32');
DeleteFile('C:\Windows\Tasks\48_dresses_notification_service.job','32');
DeleteFile('C:\Windows\Tasks\48_dresses_updating_service.job','32');
DeleteFile('C:\Windows\Tasks\9f9459ba-b822-4db2-b7bd-11dc564798ee-1.job','32');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\9f9459ba-b822-4db2-b7bd-11dc564798ee-11.exe','32');
DeleteFile('C:\Windows\Tasks\9f9459ba-b822-4db2-b7bd-11dc564798ee-11.job','32');
DeleteFile('C:\Windows\Tasks\9f9459ba-b822-4db2-b7bd-11dc564798ee-4.job','32');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\9f9459ba-b822-4db2-b7bd-11dc564798ee-4.exe','32');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\9f9459ba-b822-4db2-b7bd-11dc564798ee-5.exe','32');
DeleteFile('C:\Windows\Tasks\9f9459ba-b822-4db2-b7bd-11dc564798ee-5.job','32');
DeleteFile('C:\Windows\Tasks\9f9459ba-b822-4db2-b7bd-11dc564798ee-5_user.job','32');
DeleteFile('C:\Program Files (x86)\Ge-Force\Ge-Force-codedownloader.exe','32');
DeleteFile('C:\Windows\Tasks\a72ea835-0f0f-4c6c-96f0-00c04f46e4b5-1.job','32');
DeleteFile('C:\Program Files (x86)\Ge-Force\a72ea835-0f0f-4c6c-96f0-00c04f46e4b5-11.exe','32');
DeleteFile('C:\Windows\Tasks\a72ea835-0f0f-4c6c-96f0-00c04f46e4b5-11.job','32');
DeleteFile('C:\Program Files (x86)\Ge-Force\a72ea835-0f0f-4c6c-96f0-00c04f46e4b5-4.exe','32');
DeleteFile('C:\Windows\Tasks\a72ea835-0f0f-4c6c-96f0-00c04f46e4b5-4.job','32');
DeleteFile('C:\Program Files (x86)\Ge-Force\a72ea835-0f0f-4c6c-96f0-00c04f46e4b5-5.exe','32');
DeleteFile('C:\Windows\Tasks\a72ea835-0f0f-4c6c-96f0-00c04f46e4b5-5.job','32');
DeleteFile('C:\Windows\Tasks\a72ea835-0f0f-4c6c-96f0-00c04f46e4b5-5_user.job','32');
DeleteFile('C:\Users\1\AppData\Roaming\ASTWJAG.exe','32');
DeleteFile('C:\Windows\Tasks\ASTWJAG.job','32');
DeleteFile('C:\Users\1\AppData\Roaming\CXR.exe','32');
DeleteFile('C:\Windows\Tasks\CXR.job','32');
DeleteFile('C:\Windows\Tasks\f5318192-afe1-462c-b8ef-60f7051e7767-1.job','32');
DeleteFile('C:\Program Files (x86)\HQ-Video-Pro-2.1cV31.10\HQ-Video-Pro-2.1cV31.10-codedownloader.exe','32');
DeleteFile('C:\Program Files (x86)\HQ-Video-Pro-2.1cV31.10\f5318192-afe1-462c-b8ef-60f7051e7767-11.exe','32');
DeleteFile('C:\Windows\Tasks\f5318192-afe1-462c-b8ef-60f7051e7767-11.job','32');
DeleteFile('C:\Program Files (x86)\HQ-Video-Pro-2.1cV31.10\f5318192-afe1-462c-b8ef-60f7051e7767-3.exe','32');
DeleteFile('C:\Windows\Tasks\f5318192-afe1-462c-b8ef-60f7051e7767-3.job','32');
DeleteFile('C:\Program Files (x86)\HQ-Video-Pro-2.1cV31.10\f5318192-afe1-462c-b8ef-60f7051e7767-4.exe','32');
DeleteFile('C:\Windows\Tasks\f5318192-afe1-462c-b8ef-60f7051e7767-4.job','32');
DeleteFile('C:\Program Files (x86)\HQ-Video-Pro-2.1cV31.10\f5318192-afe1-462c-b8ef-60f7051e7767-5.exe','32');
DeleteFile('C:\Windows\Tasks\f5318192-afe1-462c-b8ef-60f7051e7767-5.job','32');
DeleteFile('C:\Windows\Tasks\f5318192-afe1-462c-b8ef-60f7051e7767-5_user.job','32');
DeleteFile('C:\Windows\Tasks\fun_coupons_notification_service.job','32');
DeleteFile('C:\Windows\Tasks\fun_coupons_updating_service.job','32');
DeleteFile('C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe','32');
DeleteFile('C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job','32');
DeleteFile('C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job','32');
DeleteFile('C:\Windows\Tasks\max_deal_helper_service.job','32');
DeleteFile('C:\Windows\Tasks\mega_shop_helper_service.job','32');
DeleteFile('C:\Program Files (x86)\Mega Shop\mega_shop_helper_service.exe','32');
DeleteFile('C:\Windows\Tasks\mr_fun_notification_service.job','32');
DeleteFile('C:\Program Files (x86)\mr fun\mr_fun_notification_service.exe','32');
DeleteFile('C:\Windows\Tasks\mr_fun_updating_service.job','32');
DeleteFile('C:\Program Files (x86)\mr fun\mr_fun_updating_service.exe','32');
DeleteFile('C:\Users\1\AppData\Roaming\PYAVA.exe','32');
DeleteFile('C:\Windows\Tasks\PYAVA.job','32');
DeleteFile('C:\Users\1\AppData\Roaming\SFPECH.exe','32');
DeleteFile('C:\Windows\Tasks\SFPECH.job','32');
DeleteFile('C:\Windows\Tasks\winter_web_notification_service.job','32');
DeleteFile('C:\Windows\Tasks\winter_web_updating_service.job','32');
DeleteFile('C:\Windows\system32\Tasks\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-1','64');
DeleteFile('C:\Windows\system32\Tasks\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-11','64');
DeleteFile('C:\Windows\system32\Tasks\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-2','64');
DeleteFile('C:\Windows\system32\Tasks\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-3','64');
DeleteFile('C:\Windows\system32\Tasks\27656fbc-5b32-4b14-a0b3-780d65a1e0a7-4','64');
DeleteFile('C:\Windows\system32\Tasks\48_dresses_notification_service','64');
DeleteFile('C:\Windows\system32\Tasks\48_dresses_updating_service','64');
DeleteFile('C:\Windows\system32\Tasks\fun_coupons_notification_service','64');
DeleteFile('C:\Windows\system32\Tasks\fun_coupons_updating_service','64');
DeleteFile('C:\Windows\system32\Tasks\max_deal_helper_service','64');
DeleteFile('C:\Windows\system32\Tasks\mega_shop_helper_service','64');
DeleteFile('C:\Windows\system32\Tasks\mr_fun_notification_service','64');
DeleteFile('C:\Windows\system32\Tasks\mr_fun_updating_service','64');
DeleteFile('C:\Program Files (x86)\ShopperPro\ShopperPro.exe','32');
DeleteFile('C:\Windows\system32\Tasks\ShopperPro','64');
DeleteFile('C:\Program Files (x86)\ShopperPro\updater.exe','32');
DeleteFile('C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.1390\jsdrv.exe','32');
DeleteFile('C:\Windows\system32\Tasks\SPDriver','64');
DeleteFile('C:\Windows\system32\Tasks\winter_web_notification_service','64');
DeleteFile('C:\Windows\system32\Tasks\winter_web_updating_service','64');
DeleteFile('C:\Windows\system32\Tasks\YTDownloader','64');
DeleteFile('C:\Program Files (x86)\YTDownloader\YTDownloader.exe','32');
DeleteFile('C:\Program Files (x86)\YTDownloader\updater.exe','32');
DeleteFile('C:\Windows\system32\Tasks\YTDownloaderUpd','64');
DeleteService('WindowsMangerProtect');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('TSW',2,2,true);
RebootWindows(true);
end.
После перезагрузки выполните скрипт: