Код:
begin
TerminateProcessByName('C:\Windows\SysWOW64\systemx64\time.exe');
QuarantineFile('C:\Windows\reg\REBE1l.exe','');
QuarantineFileF('C:\Windows\reg', '*.exe,*.dll,*.sys', false,'', 0, 0);
QuarantineFile('C:\Windows\System32\de-DE\win32\query.bat','');
QuarantineFileF('C:\Windows\System32\de-DE\win32', '*.exe,*.dll,*.sys', false,'', 0, 0);
QuarantineFile('c:\Windows\fonts\com33.{241D7C960-F8BF-4F95-B01F-E2B053341A5B}\com4.{241D7C960-F9BF-4F85-B01F-E3B043341A4B}\com4.{241D7C960-F8BF-4F85-B01F-E2B043341A4B}\key.bat','');
QuarantineFile('c:\Windows\fonts\com17.{241D7C960-F8BF-4F95-B01F-E2B053341A5B}\com4.{241D7C960-F9BF-4F85-B01F-E3B043341A4B}\com4.{241D7C960-F8BF-4F85-B01F-E2B043341A4B}\conhoste.bat','');
QuarantineFile('c:\Windows\fonts\com23.{241D7C960-F8BF-4F95-B01F-E2B053341A5B}\com4.{241D7C960-F9BF-4F85-B01F-E3B043341A4B}\com4.{241D7C960-F8BF-4F85-B01F-E2B043341A4B}\installer.bat','');
QuarantineFile('c:\Windows\fonts\com10.{241D7C960-F8BF-4F95-B01F-E2B053341A5B}\com4.{241D7C960-F9BF-4F85-B01F-E3B043341A4B}\com4.{241D7C960-F8BF-4F85-B01F-E2B043341A4B}\cmd.bat','');
QuarantineFile('C:\Users\admin\Desktop\BR\tr\csrs.exe','');
QuarantineFile('C:\Users\Администратор\AppData\Roaming\Roaming\Microsoft\Crypto\RSA\svchost.exe','');
QuarantineFileF('C:\Users\Администратор\AppData\Roaming\Roaming\Microsoft\Crypto\RSA', '*.exe,*.dll,*.sys', false,'', 0, 0);
QuarantineFile('C:\Windows\SysWOW64\systemx64\time.exe','');
QuarantineFile('C:\Windows\system32\systemx64\systemx64.exe','');
QuarantineFileF('C:\Windows\SysWOW64\systemx64', '*.exe,*.dll,*.sys', false,'', 0, 0);
DeleteFile('C:\Windows\SysWOW64\systemx64\time.exe','32');
DeleteFile('C:\Users\Администратор\AppData\Roaming\Roaming\Microsoft\Crypto\RSA\svchost.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe','command');
DeleteFile('c:\Windows\fonts\com10.{241D7C960-F8BF-4F95-B01F-E2B053341A5B}\com4.{241D7C960-F9BF-4F85-B01F-E3B043341A4B}\com4.{241D7C960-F8BF-4F85-B01F-E2B043341A4B}\cmd.bat','32');
DeleteFile('c:\Windows\fonts\com23.{241D7C960-F8BF-4F95-B01F-E2B053341A5B}\com4.{241D7C960-F9BF-4F85-B01F-E3B043341A4B}\com4.{241D7C960-F8BF-4F85-B01F-E2B043341A4B}\installer.bat','32');
DeleteFile('c:\Windows\fonts\com17.{241D7C960-F8BF-4F95-B01F-E2B053341A5B}\com4.{241D7C960-F9BF-4F85-B01F-E3B043341A4B}\com4.{241D7C960-F8BF-4F85-B01F-E2B043341A4B}\conhoste.bat','32');
DeleteFile('c:\Windows\fonts\com33.{241D7C960-F8BF-4F95-B01F-E2B053341A5B}\com4.{241D7C960-F9BF-4F85-B01F-E3B043341A4B}\com4.{241D7C960-F8BF-4F85-B01F-E2B043341A4B}\key.bat','32');
DeleteFile('C:\Windows\System32\de-DE\win32\query.bat','32');
DeleteFile('C:\Windows\reg\REBE1l.exe','32');
BC_ImportAll;
ExecuteSysClean;
ExecuteRepair(9);
ExecuteRepair(11);
BC_Activate;
end.
После выполнения скрипта перезагрузите сервер вручную.