Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
StopService('Sysconfig');
StopService('SuperFitch_x86');
StopService('Officecompiler');
StopService('MicrosoapFileManager');
StopService('Loadmnge32');
StopService('Host32manager');
StopService('FirewallIntegrityChecker');
StopService('dsp');
StopService('DiskAnalysis');
QuarantineFile('C:\ProgramData\Sysconfig\Sysconfig.exe','');
QuarantineFile('C:\Users\Default\AppData\Local\Microsoft\Super Fitch x86\SuperFitch_x86.exe','');
QuarantineFile('C:\Users\Default\AppData\Local\Microsoft\Windows\Officecompiler\Officecompiler.exe','');
QuarantineFile('C:\Users\Default\AppData\Roaming\Microsoft\Windows\Microsoap File Manager\MicrosoapFileManager.exe','');
QuarantineFile('C:\Users\Default\AppData\Roaming\Microsoft\Windows\Loadmnge32\Loadmnge32.exe','');
QuarantineFile('C:\ProgramData\Host32manager\Host32manager.exe','');
QuarantineFile('C:\ProgramData\Firewall Integrity Checker\FirewallIntegrityChecker.exe','');
QuarantineFile('C:\Users\Default\AppData\Local\Microsoft\Windows\Default settings protector\dsp.exe','');
QuarantineFile('C:\ProgramData\Disk Analysis\DiskAnalysis.exe','');
DeleteFile('C:\ProgramData\Disk Analysis\DiskAnalysis.exe','32');
DeleteFile('C:\Users\Default\AppData\Local\Microsoft\Windows\Default settings protector\dsp.exe','32');
DeleteFile('C:\ProgramData\Firewall Integrity Checker\FirewallIntegrityChecker.exe','32');
DeleteFile('C:\ProgramData\Host32manager\Host32manager.exe','32');
DeleteFile('C:\Users\Default\AppData\Roaming\Microsoft\Windows\Loadmnge32\Loadmnge32.exe','32');
DeleteFile('C:\Users\Default\AppData\Roaming\Microsoft\Windows\Microsoap File Manager\MicrosoapFileManager.exe','32');
DeleteFile('C:\Users\Default\AppData\Local\Microsoft\Windows\Officecompiler\Officecompiler.exe','32');
DeleteFile('C:\Users\Default\AppData\Local\Microsoft\Super Fitch x86\SuperFitch_x86.exe','32');
DeleteFile('C:\ProgramData\Sysconfig\Sysconfig.exe','32');
DeleteFile('C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job','32');
DeleteFile('C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job','32');
DeleteFile('C:\Windows\system32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA','32');
DeleteFile('C:\Windows\system32\Tasks\BonanzaDealsUpdate','32');
DeleteFile('C:\Windows\system32\Tasks\UpnCH','32');
DeleteFile('C:\Windows\system32\Tasks\VuuPCUpdate','32');
DeleteFile('C:\Windows\system32\Tasks\VuuPCUpdateLogin','32');
DelBHO('{fe063412-bea4-4d76-8ed3-183be6220d17}');
DelBHO('{ad708c09-d51b-45b3-9d28-4eba2681febf}');
DelBHO('{8984B388-A5BB-4DF7-B274-77B879E179DB}');
DelBHO('{11111111-1111-1111-1111-110211771193}');
DelBHO('{0FB6A909-6086-458F-BD92-1F8EE10042A0}');
DelBHO('{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}');
DeleteService('VuuPCConnectivity');
DeleteService('Sysconfig');
DeleteService('SuperFitch_x86');
DeleteService('RemoteEngineService');
DeleteService('Officecompiler');
DeleteService('MicrosoapFileManager');
DeleteService('Loadmnge32');
DeleteService('Host32manager');
DeleteService('FirewallIntegrityChecker');
DeleteService('dsp');
DeleteService('DiskAnalysis');
DeleteService('BrowserDefendert');
DeleteService('bonanzadealslivem');
DeleteService('bonanzadealslive');
DeleteFileMask('C:\ProgramData\Sysconfig','*',true);
DeleteFileMask('C:\Users\Default\AppData\Local\Microsoft\Super Fitch x86','*',true);
DeleteFileMask('C:\Users\Default\AppData\Local\Microsoft\Windows\Officecompiler','*',true);
DeleteFileMask('C:\Users\Default\AppData\Roaming\Microsoft\Windows\Microsoap File Manager','*',true);
DeleteFileMask('C:\Users\Default\AppData\Roaming\Microsoft\Windows\Loadmnge32','*',true);
DeleteFileMask('C:\ProgramData\Host32manager','*',true);
DeleteFileMask('C:\ProgramData\Firewall Integrity Checker','*',true);
DeleteFileMask('C:\Users\Default\AppData\Local\Microsoft\Windows\Default settings protector','*',true);
DeleteFileMask('C:\ProgramData\Disk Analysis','*',true);
DeleteDirectory('C:\ProgramData\Sysconfig');
DeleteDirectory('C:\Users\Default\AppData\Local\Microsoft\Super Fitch x86');
DeleteDirectory('C:\Users\Default\AppData\Local\Microsoft\Windows\Officecompiler');
DeleteDirectory('C:\Users\Default\AppData\Roaming\Microsoft\Windows\Microsoap File Manager');
DeleteDirectory('C:\Users\Default\AppData\Roaming\Microsoft\Windows\Loadmnge32');
DeleteDirectory('C:\ProgramData\Host32manager');
DeleteDirectory('C:\ProgramData\Firewall Integrity Checker');
DeleteDirectory('C:\Users\Default\AppData\Local\Microsoft\Windows\Default settings protector');
DeleteDirectory('C:\ProgramData\Disk Analysis');
BC_ImportDeletedList;
ExecuteWizard('TSW',2,2,true);
ExecuteWizard('SCU',2,2,true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.