Код:
begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
TerminateProcessByName('c:\windows\microsoft\svchost.exe');
TerminateProcessByName('c:\users\Лёха\appdata\roaming\opqwsyo05ws\pqrufr0drfy.exe');
TerminateProcessByName('c:\program files\mail.ru\mailruupdater\mailruupdater.exe');
TerminateProcessByName('c:\users\Лёха\appdata\local\mail.ru\mailruupdater.exe');
TerminateProcessByName('c:\users\Лёха\appdata\roaming\1zaaa1rvy04\m3kcyikwtxi.exe');
TerminateProcessByName('c:\users\Лёха\appdata\local\kometa\application\kometa.exe');
TerminateProcessByName('c:\program files\f5rnu3q78x\f5rnu3q78.exe');
TerminateProcessByName('c:\program files\chmz0qtfxhr\896ql.exe');
TerminateProcessByName('c:\program files\4t0l93vqxg\4t0l93vqx.exe');
TerminateProcessByName('c:\program files\1tmd5x6cib\1tmd5x6ci.exe');
TerminateProcessByName('C:\Program Files\3OBAGMQFN1\3OBAGMQFN.exe');
TerminateProcessByName('C:\Users\Лёха\AppData\Roaming\r0uz4wx1jso\miwmu1foygl.exe');
StopService('Updater.Mail.Ru');
DeleteService('Updater.Mail.Ru');
QuarantineFile('C:\Users\Лёха\AppData\Roaming\r0uz4wx1jso\miwmu1foygl.exe','');
QuarantineFileF('C:\Users\Лёха\AppData\Roaming\r0uz4wx1jso', '*', false, '', 0, 0);
QuarantineFile('c:\program files\1tmd5x6cib\1tmd5x6ci.exe','');
QuarantineFileF('c:\program files\1tmd5x6cib', '*', false, '', 0, 0);
QuarantineFile('C:\Program Files\3OBAGMQFN1\3OBAGMQFN.exe','');
QuarantineFileF('C:\Program Files\3OBAGMQFN1', '*', false, '', 0, 0);
QuarantineFile('c:\program files\4t0l93vqxg\4t0l93vqx.exe','');
QuarantineFileF('c:\program files\4t0l93vqxg', '*', false, '', 0, 0);
QuarantineFile('c:\program files\chmz0qtfxhr\896ql.exe','');
QuarantineFile('C:\Program Files\chmz0qtfxhr\AKOYCSFL9BAGU0C.exe','');
QuarantineFileF('c:\program files\chmz0qtfxhr', '*', false, '', 0, 0);
QuarantineFile('c:\users\Лёха\appdata\roaming\1zaaa1rvy04\m3kcyikwtxi.exe','');
QuarantineFileF('c:\users\Лёха\appdata\roaming\1zaaa1rvy04', '*', false, '', 0, 0);
QuarantineFile('c:\users\Лёха\appdata\roaming\opqwsyo05ws\pqrufr0drfy.exe','');
QuarantineFileF('c:\users\Лёха\appdata\roaming\opqwsyo05ws', '*', false, '', 0, 0);
QuarantineFile('C:\Program Files\F5RNU3Q78X\F5RNU3Q78.exe','');
QuarantineFileF('C:\Program Files\F5RNU3Q78X', '*', false, '', 0, 0);
QuarantineFile('C:\Users\Лёха\appdata\roaming\microsoft\msi.exe','');
QuarantineFile('C:\Users\Лёха\AppData\Local\wupdate\wupdate.exe','');
QuarantineFileF('C:\Users\Лёха\AppData\Local\wupdate', '*', false, '', 0, 0);
QuarantineFile('C:\Users\Лёха\AppData\Local\wmipr\wmipr.exe','');
QuarantineFileF('C:\Users\Лёха\AppData\Local\wmipr', '*', false, '', 0, 0);
QuarantineFile('C:\Users\Лёха\AppData\Local\SearchGo\searchgo.exe','');
QuarantineFile('C:\Users\Лёха\AppData\LocalLow\SearchGo\searchgo.dll','');
QuarantineFile('C:\Users\Лёха\AppData\Local\Kometa\Application\kometa.exe','');
QuarantineFile('C:\Users\Лёха\AppData\Local\Kometa\Panel\KometaLaunchPanel.exe','');
QuarantineFile('C:\Users\Лёха\AppData\Local\Temp\XqQajGACXsJI.exe','');
QuarantineFile('C:\Users\Лёха\AppData\Local\Kometa\Application\52.0.2743.82\kometa-client-util.dll','');
QuarantineFile('C:\Users\Лёха\AppData\Local\Kometa\Application\52.0.2743.82\chrome_elf.dll','');
QuarantineFile('C:\Users\Лёха\AppData\Local\Kometa\Application\52.0.2743.82\chrome_child.dll','');
QuarantineFile('C:\Users\Лёха\AppData\Local\Kometa\Application\52.0.2743.82\chrome.dll','');
QuarantineFile('c:\windows\microsoft\svchost.exe','');
QuarantineFileF('c:\windows\microsoft', '*', false, '', 0, 0);
QuarantineFile('C:\Program Files\DiskP\DiskPower.exe','');
QuarantineFile('C:\Windows\system32\drivers\yoFY94fcylVk.sys','');
DelBHO('{2BC46CFA-4B00-4193-A7BD-6AD1D0BCB5BC}');
DelBHO('{598AEFC6-DD3C-4A63-9AC3-53FCF6155931}');
DeleteFile('C:\Users\Лёха\AppData\Roaming\r0uz4wx1jso\miwmu1foygl.exe','32');
DeleteFileMask('C:\Users\Лёха\AppData\Roaming\r0uz4wx1jso','*',true);
DeleteDirectory('C:\Users\Лёха\AppData\Roaming\r0uz4wx1jso');
DeleteFile('c:\program files\1tmd5x6cib\1tmd5x6ci.exe','32');
DeleteFileMask('c:\program files\1tmd5x6cib','*',true);
DeleteDirectory('c:\program files\1tmd5x6cib');
DeleteFile('C:\Program Files\3OBAGMQFN1\3OBAGMQFN.exe','32');
DeleteFileMask('C:\Program Files\3OBAGMQFN1','*',true);
DeleteDirectory('C:\Program Files\3OBAGMQFN1');
DeleteFile('c:\program files\4t0l93vqxg\4t0l93vqx.exe','32');
DeleteFileMask('c:\program files\4t0l93vqxg','*',true);
DeleteDirectory('c:\program files\4t0l93vqxg');
DeleteFile('c:\program files\chmz0qtfxhr\896ql.exe','32');
DeleteFile('C:\Program Files\chmz0qtfxhr\AKOYCSFL9BAGU0C.exe','32');
DeleteFileMask('c:\program files\chmz0qtfxhr','*',true);
DeleteDirectory('c:\program files\chmz0qtfxhr');
DeleteFile('c:\program files\f5rnu3q78x\F5RNU3Q78.exe','32');
DeleteFileMask('c:\program files\f5rnu3q78x','*',true);
DeleteDirectory('c:\program files\f5rnu3q78x');
DeleteFile('c:\users\Лёха\appdata\local\kometa\application\kometa.exe','32');
DeleteFile('C:\Users\Лёха\AppData\Local\Kometa\Application\52.0.2743.82\chrome.dll','32');
DeleteFile('C:\Users\Лёха\AppData\Local\Kometa\Application\52.0.2743.82\chrome_child.dll','32');
DeleteFile('C:\Users\Лёха\AppData\Local\Kometa\Application\52.0.2743.82\chrome_elf.dll','32');
DeleteFile('C:\Users\Лёха\AppData\Local\Kometa\Application\52.0.2743.82\kometa-client-util.dll','32');
DeleteFile('C:\Users\Лёха\AppData\Local\Kometa\Panel\KometaLaunchPanel.exe','32');
DeleteFileMask('C:\Users\Лёха\AppData\Local\Kometa','*',true);
DeleteDirectory('C:\Users\Лёха\AppData\Local\Kometa');
DeleteFile('c:\users\Лёха\appdata\roaming\1zaaa1rvy04\m3kcyikwtxi.exe','32');
DeleteFileMask('c:\users\Лёха\appdata\roaming\1zaaa1rvy04','*',true);
DeleteDirectory('c:\users\Лёха\appdata\roaming\1zaaa1rvy04');
DeleteFile('c:\users\Лёха\appdata\local\mail.ru\mailruupdater.exe','32');
DeleteFile('c:\program files\mail.ru\mailruupdater\mailruupdater.exe','32');
DeleteFile('c:\users\Лёха\appdata\roaming\opqwsyo05ws\pqrufr0drfy.exe','32');
DeleteFileMask('c:\users\Лёха\appdata\roaming\opqwsyo05ws','*',true);
DeleteDirectory('c:\users\Лёха\appdata\roaming\opqwsyo05ws');
DeleteFile('c:\windows\microsoft\svchost.exe','32');
DeleteFileMask('c:\windows\microsoft','*',true);
DeleteDirectory('c:\windows\microsoft');
DeleteFile('C:\Windows\system32\drivers\yoFY94fcylVk.sys','32');
DeleteFile('C:\Users\Лёха\AppData\Local\Amigo\Application\amigo.exe','32');
DeleteFileMask('C:\Users\Лёха\AppData\Local\Amigo','*',true);
DeleteDirectory('C:\Users\Лёха\AppData\Local\Amigo');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Windows');
DeleteFile('C:\Program Files\Internet Explorer\Windows.lnk','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','DiskPower');
DeleteFile('C:\Program Files\DiskP\DiskPower.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','OMEWPRODUCT_SCAIU');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','yigsksofix');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','SystemScript');
DeleteFile('C:\Users\Лёха\AppData\Local\Temp\XqQajGACXsJI.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','MailRuUpdater');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','KometaLaunchPanel');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','8ENCH3FPAZBSLHU');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','KEH0FU1LG8YFEMD');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','1pegykkm40u');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ftwcu25i5rw');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','UMX3HOI5S1L77D3');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ZOGKYHZXJTI3JOS');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','KometaAutoLaunch_A9687BB76EC1048ABC3539211EC03894');
DeleteFile('C:\Users\Лёха\AppData\LocalLow\SearchGo\searchgo.dll','32');
DeleteFile('C:\Windows\system32\Tasks\MailRuUpdater','32');
DeleteFile('C:\Windows\system32\Tasks\MSI','32');
DeleteFile('C:\Windows\system32\Tasks\SearchGo Task','32');
DeleteFile('C:\Users\Лёха\AppData\Local\SearchGo\searchgo.exe','32');
DeleteFile('C:\Windows\system32\Tasks\StartMenuCache','32');
DeleteFile('C:\Windows\system32\Tasks\wmipr','32');
DeleteFile('C:\Users\Лёха\AppData\Local\wmipr\wmipr.exe','32');
DeleteFileMask('C:\Users\Лёха\AppData\Local\wmipr','*',true);
DeleteDirectory('C:\Users\Лёха\AppData\Local\wmipr');
DeleteFile('C:\Windows\system32\Tasks\wupdate','32');
DeleteFile('C:\Users\Лёха\AppData\Local\wupdate\wupdate.exe','32');
DeleteFileMask('C:\Users\Лёха\AppData\Local\wupdate','*',true);
DeleteDirectory('C:\Users\Лёха\AppData\Local\wupdate');
DeleteFile('C:\Users\Лёха\appdata\roaming\microsoft\msi.exe','32');
BC_ImportAll;
ExecuteSysClean;
ExecuteRepair(2);
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('TSW',2,3,true);
ExecuteWizard('SCU',2,2,true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.