Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
SearchRootkit(true, true);
SetAVZGuardStatus(True);
StopService('DocineDL');
StopService('LegassSU');
StopService('PearhasSU');
QuarantineFile('C:\Program Files\MIO\MIO.exe', '');
QuarantineFile('c:\program files\winarcher\archer.dll', '');
QuarantineFile('c:\users\fedor\appdata\local\snare\snare.dll', '');
QuarantineFile('C:\Users\FeDor\appdata\local\snare\snarer.dll', '');
QuarantineFile('C:\Users\FeDor\AppData\Local\Temp\1\BaofengUpdate_U.exe', '');
QuarantineFile('C:\Users\FeDor\AppData\Local\Temp\2\ttff.exe', '');
QuarantineFile('C:\Users\FeDor\AppData\Local\Temp\ist16BC.tmp\tools\chr.exe', '');
QuarantineFile('C:\Users\FeDor\AppData\Roaming\Microsoft\Windows\Cookies\reedus.dll', '');
QuarantineFile('C:\Users\FeDor\appdata\roaming\tsv\tsvr.exe', '');
QuarantineFile('C:\Windows\System32\ihctrl32.dll', '');
QuarantineFile('C:\Windows\System32\wsaudio.dll', '');
QuarantineFile('C:\Windows\TEMP\clearcache.dll', '');
QuarantineFileF('c:\program files\winarcher', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\users\fedor\appdata\local\snare', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\users\fedor\appdata\roaming\tsv', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
DeleteFile('C:\Program Files\MIO\MIO.exe', '32');
DeleteFile('c:\program files\winarcher\archer.dll', '32');
DeleteFile('c:\users\fedor\appdata\local\snare\snare.dll', '32');
DeleteFile('C:\Users\FeDor\appdata\local\snare\snarer.dll', '32');
DeleteFile('C:\Users\FeDor\AppData\Local\Temp\1\BaofengUpdate_U.exe', '32');
DeleteFile('C:\Users\FeDor\AppData\Local\Temp\2\ttff.exe', '32');
DeleteFile('C:\Users\FeDor\AppData\Local\Temp\ist16BC.tmp\tools\chr.exe', '32');
DeleteFile('C:\Users\FeDor\AppData\Roaming\Microsoft\Windows\Cookies\reedus.dll', '32');
DeleteFile('C:\Users\FeDor\appdata\roaming\tsv\tsvr.exe', '32');
DeleteFile('C:\Windows\System32\ihctrl32.dll', '32');
DeleteFile('C:\Windows\System32\wsaudio.dll', '32');
DeleteFile('C:\Windows\TEMP\clearcache.dll', '32');
ExecuteFile('schtasks.exe', '/delete /TN "Milimili" /F', 0, 15000, true);
DeleteService('DocineDL');
DeleteService('LegassSU');
DeleteService('PearhasSU');
DeleteFileMask('c:\program files\winarcher', '*', true);
DeleteFileMask('c:\users\fedor\appdata\local\snare', '*', true);
DeleteFileMask('c:\users\fedor\appdata\roaming\tsv', '*', true);
DeleteDirectory('c:\program files\winarcher');
DeleteDirectory('c:\users\fedor\appdata\local\snare');
DeleteDirectory('c:\users\fedor\appdata\roaming\tsv');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'Application Restart #0');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks', '{98C066AB-D735-4339-9E52-A34875141B56}');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\Archer\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\ihctrl32\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\SNARE\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\wsaudio\Parameters', 'ServiceDll');
BC_ImportALL;
ExecuteSysClean;
ExecuteRepair(1);
ExecuteRepair(9);
ExecuteWizard('SCU', 2, 3, true);
BC_Activate;
RebootWindows(true);
end.
Компьютер