Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
TerminateProcessByName('c:\program files\win32_computersystemproduct-1457333261---\knsb9c.tmpfs');
StopService('qozuvofozbt');
QuarantineFileF('c:\program files\spacesoundpro', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\documents and settings\администратор\local settings\application data\gmsd_ru_005010220', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\documents and settings\администратор\local settings\application data\mbot_ru_014010220', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\documents and settings\администратор\application data\7ad133b8-988e-42d9-a90a-eebb18a86286', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\documents and settings\администратор\local settings\application data\hostinstaller', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFile('c:\program files\win32_computersystemproduct-1457333261---\knsb9c.tmpfs', '');
QuarantineFile('C:\WINDOWS\system32\365.exe', '');
QuarantineFile('C:\WINDOWS\mcdrive32.exe', '');
QuarantineFile('C:\DOCUME~1\9335~1\LOCALS~1\Temp\setup.exe', '');
QuarantineFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe', '');
QuarantineFile('C:\DOCUME~1\9335~1\LOCALS~1\Temp\un.exe', '');
QuarantineFile('C:\Documents and Settings\Администратор\Local Settings\Application Data\gmsd_ru_005010220\upgmsd_ru_005010220.exe', '');
QuarantineFile('C:\Documents and Settings\Администратор\Local Settings\Application Data\mbot_ru_014010220\upmbot_ru_014010220.exe', '');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\7ad133b8-988e-42d9-a90a-eebb18a86286\7ad133b8-988e-42d9-a90a-eebb18a86286.exe', '');
QuarantineFile('C:\Documents and Settings\Администратор\Local Settings\Application Data\Hostinstaller\1956731036_installcube.exe', '');
QuarantineFile('C:\Documents and Settings\Администратор\Local Settings\Application Data\SystemMonitor2016\1956731036.exe', '');
QuarantineFile('C:\Documents and Settings\Администратор\Local Settings\Temp\nsf30E.tmp\blowfish.dll', '');
DeleteFile('c:\program files\win32_computersystemproduct-1457333261---\knsb9c.tmpfs', '32');
DeleteFile('C:\WINDOWS\system32\365.exe', '32');
DeleteFile('C:\WINDOWS\mcdrive32.exe', '32');
DeleteFile('C:\DOCUME~1\9335~1\LOCALS~1\Temp\setup.exe', '32');
DeleteFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe', '32');
DeleteFile('C:\DOCUME~1\9335~1\LOCALS~1\Temp\un.exe', '32');
DeleteFile('C:\Documents and Settings\Администратор\Local Settings\Application Data\gmsd_ru_005010220\upgmsd_ru_005010220.exe', '32');
DeleteFile('C:\Documents and Settings\Администратор\Local Settings\Application Data\mbot_ru_014010220\upmbot_ru_014010220.exe', '32');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\7ad133b8-988e-42d9-a90a-eebb18a86286\7ad133b8-988e-42d9-a90a-eebb18a86286.exe', '32');
DeleteFile('C:\Documents and Settings\Администратор\Local Settings\Application Data\Hostinstaller\1956731036_installcube.exe', '32');
DeleteFile('C:\Documents and Settings\Администратор\Local Settings\Application Data\SystemMonitor2016\1956731036.exe', '32');
DeleteFile('C:\Documents and Settings\Администратор\Local Settings\Temp\nsf30E.tmp\blowfish.dll', '32');
QuarantineFile('C:\WINDOWS\system32\calc.exe','');
QuarantineFileF('C:\Documents and Settings\Администратор\Application Data\7ad133b8-988e-42d9-a90a-eebb18a86286\', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFile('C:\Documents and Settings\Администратор\Local Settings\Application Data\Chromium\Application\45.0.2433.0\Installer\updater\updater.exe', '');
QuarantineFileF('C:\Documents and Settings\Администратор\Local Settings\Application Data\SystemMonitor2016\', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0, 0);
DeleteFileMask('C:\Documents and Settings\Администратор\Local Settings\Application Data\SystemMonitor2016\', '*', true);
DeleteDirectory('C:\Documents and Settings\Администратор\Local Settings\Application Data\SystemMonitor2016\');
ExecuteFile('schtasks.exe', '/delete /TN "7ad133b8-988e-42d9-a90a-eebb18a86286" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Soft installer" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SystemMonitor2016" /F', 0, 15000, true);
DeleteService('qozuvofozbt');
DeleteFileMask('c:\program files\spacesoundpro', '*', true);
DeleteFileMask('c:\documents and settings\администратор\local settings\application data\gmsd_ru_005010220', '*', true);
DeleteFileMask('c:\documents and settings\администратор\local settings\application data\mbot_ru_014010220', '*', true);
DeleteFileMask('c:\documents and settings\администратор\application data\7ad133b8-988e-42d9-a90a-eebb18a86286', '*', false);
DeleteFileMask('c:\documents and settings\администратор\local settings\application data\hostinstaller', '*', true);
DeleteDirectory('c:\program files\spacesoundpro');
DeleteDirectory('c:\documents and settings\администратор\local settings\application data\gmsd_ru_005010220');
DeleteDirectory('c:\documents and settings\администратор\local settings\application data\mbot_ru_014010220');
DeleteDirectory('c:\documents and settings\администратор\local settings\application data\hostinstaller');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\365', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IconRunner', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Microsoft Driver Setup', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\setup', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SpaceSoundPro', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\un', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\upgmsd_ru_005010220.exe', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\upmbot_ru_014010220.exe', 'command');
BC_ImportALL;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
BC_Activate;
RebootWindows(true);
end.