begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ClearQuarantine;
QuarantineFile('C:\Windows\System32\Winlogon.exe', '');
QuarantineFile('C:\Windows\System32\MSPaint.exe',' ');
QuarantineFile('C:\Windows\System32\SVChost.exe',' ');
QuarantineFile('C:\Windows\System32\Wmprph.exe','' );
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
DeleteFile('C:\Users\User\AppData\Roaming\18D3.exe ');
DeleteFile('C:\Users\User\AppData\Roaming\692.exe' );
DeleteFile('C:\Program Files\Mail.ru\Guard\GuardMailRu.exe');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-5181719\enowpea40.exe');
DeleteFile('C:\Users\User\AppData\Roaming\Microsof t\Fcrkrp.exe');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-5135689\hbweaaa.exe');
DeleteFile('C:\Users\User\AppData\Roaming\Microsof t\Jcrkrt.exe');
DeleteFile('C:\RECYCLER\webhost.exe');
DeleteFile('C:\ProgramData\OnvijdekNatw.dll');
DeleteFile('C:\Program Files\Microsoft Word 2010. Полный курс обучения\info.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Micro soft\Windows NT\CurrentVersion\Winlogon','Shell');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Micro soft\Windows\CurrentVersion\Run','enowpea4');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Micr osoft\Windows NT\CurrentVersion\Winlogon','Taskman');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.