Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\program files\innoapp\updateinnoapp.exe');
TerminateProcessByName('c:\programdata\windowsmangerprotect\protectwindowsmanager.exe');
TerminateProcessByName('c:\programdata\iepluginservices\pluginservice.exe');
TerminateProcessByName('c:\program files\newplayer\newvideoplayerupdaterservice.exe');
TerminateProcessByName('c:\program files\003\buuoujqmrk32.exe');
TerminateProcessByName('c:\program files\asp\advancedsystemprotector.exe');
QuarantineFile('C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe','');
QuarantineFile('C:\PROGRA~1\COMMON~1\System\SysMenu.dll','');
QuarantineFile('C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-updater.exe','');
QuarantineFile('C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-firefoxinstaller.exe','');
QuarantineFile('C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-enabler.exe','');
QuarantineFile('C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-codedownloader.exe','');
QuarantineFile('C:\Program Files\ss8\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-5.exe','');
QuarantineFile('C:\Program Files\ss8\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-3.exe','');
QuarantineFile('C:\Program Files\ss8\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-2.exe','');
QuarantineFile('C:\Program Files\ss8\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-11.exe','');
QuarantineFile('C:\Program Files\ss8\ss8-codedownloader.exe','');
QuarantineFile('C:\Users\C5DE~1\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE','');
QuarantineFile('C:\Program Files\iWebar\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-5.exe','');
QuarantineFile('C:\Program Files\iWebar\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-4.exe','');
QuarantineFile('C:\Program Files\iWebar\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-2.exe','');
QuarantineFile('C:\Program Files\iWebar\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-11.exe','');
QuarantineFile('C:\Program Files\iWebar\iWebar-codedownloader.exe','');
QuarantineFile('C:\Program Files\iWebar\iWebar-nova.exe','');
QuarantineFile('C:\Program Files\iWebar\iWebar-novainstaller.exe','');
QuarantineFile('C:\Program Files\iWebar\bc4e0748-8534-4111-b13b-b5a49952e799-5.exe','');
QuarantineFile('C:\Program Files\iWebar\bc4e0748-8534-4111-b13b-b5a49952e799-4.exe','');
QuarantineFile('C:\Program Files\iWebar\bc4e0748-8534-4111-b13b-b5a49952e799-2.exe','');
QuarantineFile('C:\Program Files\ss8\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-4.exe','');
QuarantineFile('C:\Program Files\video MediaPlay-Air\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-5.exe','');
QuarantineFile('C:\Program Files\video MediaPlay-Air\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-4.exe','');
QuarantineFile('C:\Program Files\video MediaPlay-Air\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-3.exe','');
QuarantineFile('C:\Program Files\video MediaPlay-Air\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-2.exe','');
QuarantineFile('C:\Program Files\video MediaPlay-Air\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-11.exe','');
QuarantineFile('C:\PROGRA~1\SupTab\SEARCH~1.DLL','');
QuarantineFile('C:\PROGRA~1\YTDOWN~1\sbmntr.sys','');
QuarantineFile('C:\Windows\system32\drivers\{9a9157bb-003e-4fef-8bd1-c09bc4586a28}w.sys','');
QuarantineFile('C:\Program Files\SupTab\DpInterface32.dll','');
QuarantineFile('c:\program files\innoapp\updateinnoapp.exe','');
QuarantineFile('c:\programdata\windowsmangerprotect\protectwindowsmanager.exe','');
QuarantineFile('c:\programdata\iepluginservices\pluginservice.exe','');
QuarantineFile('c:\program files\newplayer\newvideoplayerupdaterservice.exe','');
QuarantineFile('c:\program files\003\buuoujqmrk32.exe','');
QuarantineFile('c:\program files\asp\advancedsystemprotector.exe','');
DeleteFile('c:\program files\asp\advancedsystemprotector.exe','32');
DeleteFile('c:\program files\003\buuoujqmrk32.exe','32');
DeleteFile('c:\programdata\iepluginservices\pluginservice.exe','32');
DeleteFile('c:\programdata\windowsmangerprotect\protectwindowsmanager.exe','32');
DeleteFile('c:\program files\innoapp\updateinnoapp.exe','32');
DeleteFile('C:\Program Files\SupTab\DpInterface32.dll','32');
DeleteFile('C:\Program Files\NewPlayer\NewVideoPlayerUpdaterService.exe','32');
DeleteFile('C:\Windows\system32\drivers\{9a9157bb-003e-4fef-8bd1-c09bc4586a28}w.sys','32');
DeleteFile('C:\PROGRA~1\YTDOWN~1\sbmntr.sys','32');
DeleteFile('C:\PROGRA~1\SupTab\SEARCH~1.DLL','32');
DeleteFile('c:\program files\movies toolbar\datamngr\x64\apcrtldr.dll','32');
DeleteFile('C:\Windows\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-1.job','32');
DeleteFile('C:\Program Files\video MediaPlay-Air\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-11.exe','32');
DeleteFile('C:\Windows\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-11.job','32');
DeleteFile('C:\Program Files\video MediaPlay-Air\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-2.exe','32');
DeleteFile('C:\Windows\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-2.job','32');
DeleteFile('C:\Program Files\video MediaPlay-Air\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-3.exe','32');
DeleteFile('C:\Windows\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-3.job','32');
DeleteFile('C:\Program Files\video MediaPlay-Air\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-4.exe','32');
DeleteFile('C:\Windows\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-4.job','32');
DeleteFile('C:\Program Files\video MediaPlay-Air\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-5.exe','32');
DeleteFile('C:\Windows\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-5.job','32');
DeleteFile('C:\Windows\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-5_user.job','32');
DeleteFile('C:\Windows\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-6.job','32');
DeleteFile('C:\Windows\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-7.job','32');
DeleteFile('C:\Program Files\ss8\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-4.exe','32');
DeleteFile('C:\Windows\Tasks\2ca4f36e-f8c2-4e34-910f-f5de1aeb702f.job','32');
DeleteFile('C:\Program Files\iWebar\bc4e0748-8534-4111-b13b-b5a49952e799-2.exe','32');
DeleteFile('C:\Windows\Tasks\bc4e0748-8534-4111-b13b-b5a49952e799-2.job','32');
DeleteFile('C:\Program Files\iWebar\bc4e0748-8534-4111-b13b-b5a49952e799-4.exe','32');
DeleteFile('C:\Windows\Tasks\bc4e0748-8534-4111-b13b-b5a49952e799-4.job','32');
DeleteFile('C:\Program Files\iWebar\bc4e0748-8534-4111-b13b-b5a49952e799-5.exe','32');
DeleteFile('C:\Windows\Tasks\bc4e0748-8534-4111-b13b-b5a49952e799-5.job','32');
DeleteFile('C:\Windows\Tasks\bc4e0748-8534-4111-b13b-b5a49952e799-5_user.job','32');
DeleteFile('C:\Program Files\iWebar\iWebar-novainstaller.exe','32');
DeleteFile('C:\Windows\Tasks\bc4e0748-8534-4111-b13b-b5a49952e799-6.job','32');
DeleteFile('C:\Program Files\iWebar\iWebar-nova.exe','32');
DeleteFile('C:\Windows\Tasks\bc4e0748-8534-4111-b13b-b5a49952e799-7.job','32');
DeleteFile('C:\Program Files\iWebar\iWebar-codedownloader.exe','32');
DeleteFile('C:\Windows\Tasks\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-1.job','32');
DeleteFile('C:\Program Files\iWebar\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-11.exe','32');
DeleteFile('C:\Windows\Tasks\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-11.job','32');
DeleteFile('C:\Program Files\iWebar\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-2.exe','32');
DeleteFile('C:\Windows\Tasks\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-2.job','32');
DeleteFile('C:\Program Files\iWebar\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-4.exe','32');
DeleteFile('C:\Windows\Tasks\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-4.job','32');
DeleteFile('C:\Program Files\iWebar\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-5.exe','32');
DeleteFile('C:\Windows\Tasks\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-5.job','32');
DeleteFile('C:\Windows\Tasks\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-5_user.job','32');
DeleteFile('C:\Windows\Tasks\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-6.job','32');
DeleteFile('C:\Windows\Tasks\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-7.job','32');
DeleteFile('C:\Users\C5DE~1\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE','32');
DeleteFile('C:\Windows\Tasks\Digital Sites.job','32');
DeleteFile('C:\Windows\Tasks\ec6947a1-3226-4d49-a509-173f926eb3e5-1.job','32');
DeleteFile('C:\Windows\Tasks\ec6947a1-3226-4d49-a509-173f926eb3e5-11.job','32');
DeleteFile('C:\Windows\Tasks\ec6947a1-3226-4d49-a509-173f926eb3e5-2.job','32');
DeleteFile('C:\Windows\Tasks\ec6947a1-3226-4d49-a509-173f926eb3e5-4.job','32');
DeleteFile('C:\Windows\Tasks\ec6947a1-3226-4d49-a509-173f926eb3e5-5.job','32');
DeleteFile('C:\Windows\Tasks\ec6947a1-3226-4d49-a509-173f926eb3e5-5_user.job','32');
DeleteFile('C:\Windows\Tasks\ec6947a1-3226-4d49-a509-173f926eb3e5-6.job','32');
DeleteFile('C:\Windows\Tasks\ec6947a1-3226-4d49-a509-173f926eb3e5-7.job','32');
DeleteFile('C:\Program Files\ss8\ss8-codedownloader.exe','32');
DeleteFile('C:\Windows\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-1.job','32');
DeleteFile('C:\Program Files\ss8\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-11.exe','32');
DeleteFile('C:\Windows\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-11.job','32');
DeleteFile('C:\Program Files\ss8\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-2.exe','32');
DeleteFile('C:\Windows\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-2.job','32');
DeleteFile('C:\Program Files\ss8\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-3.exe','32');
DeleteFile('C:\Windows\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-3.job','32');
DeleteFile('C:\Windows\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-4.job','32');
DeleteFile('C:\Program Files\ss8\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-5.exe','32');
DeleteFile('C:\Windows\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-5.job','32');
DeleteFile('C:\Windows\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-5_user.job','32');
DeleteFile('C:\Windows\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-6.job','32');
DeleteFile('C:\Windows\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-7.job','32');
DeleteFile('C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-codedownloader.exe','32');
DeleteFile('C:\Windows\Tasks\Plus-HD-1.6-codedownloader.job','32');
DeleteFile('C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-enabler.exe','32');
DeleteFile('C:\Windows\Tasks\Plus-HD-1.6-enabler.job','32');
DeleteFile('C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-firefoxinstaller.exe','32');
DeleteFile('C:\Windows\Tasks\Plus-HD-1.6-firefoxinstaller.job','32');
DeleteFile('C:\Program Files\Plus-HD-1.6\Plus-HD-1.6-updater.exe','32');
DeleteFile('C:\Windows\Tasks\Plus-HD-1.6-updater.job','32');
DeleteFile('C:\Windows\system32\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-1','32');
DeleteFile('C:\Windows\system32\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-11','32');
DeleteFile('C:\Windows\system32\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-2','32');
DeleteFile('C:\Windows\system32\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-3','32');
DeleteFile('C:\Windows\system32\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-4','32');
DeleteFile('C:\Windows\system32\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-5','32');
DeleteFile('C:\Windows\system32\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-6','32');
DeleteFile('C:\Windows\system32\Tasks\2b6328a9-11c8-46e0-8547-2efb3aafcaa4-7','32');
DeleteFile('C:\Windows\system32\Tasks\2ca4f36e-f8c2-4e34-910f-f5de1aeb702f','32');
DeleteFile('C:\Windows\system32\Tasks\bc4e0748-8534-4111-b13b-b5a49952e799-1','32');
DeleteFile('C:\Windows\system32\Tasks\bc4e0748-8534-4111-b13b-b5a49952e799-2','32');
DeleteFile('C:\Windows\system32\Tasks\bc4e0748-8534-4111-b13b-b5a49952e799-4','32');
DeleteFile('C:\Windows\system32\Tasks\bc4e0748-8534-4111-b13b-b5a49952e799-5','32');
DeleteFile('C:\Windows\system32\Tasks\bc4e0748-8534-4111-b13b-b5a49952e799-6','32');
DeleteFile('C:\Windows\system32\Tasks\bc4e0748-8534-4111-b13b-b5a49952e799-7','32');
DeleteFile('C:\Windows\system32\Tasks\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-1','32');
DeleteFile('C:\Windows\system32\Tasks\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-11','32');
DeleteFile('C:\Windows\system32\Tasks\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-2','32');
DeleteFile('C:\Windows\system32\Tasks\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-4','32');
DeleteFile('C:\Windows\system32\Tasks\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-6','32');
DeleteFile('C:\Windows\system32\Tasks\bdbf8cf3-247b-428d-9c8b-f421fd38d5b4-7','32');
DeleteFile('C:\Windows\system32\Tasks\ec6947a1-3226-4d49-a509-173f926eb3e5-1','32');
DeleteFile('C:\Windows\system32\Tasks\ec6947a1-3226-4d49-a509-173f926eb3e5-11','32');
DeleteFile('C:\Windows\system32\Tasks\ec6947a1-3226-4d49-a509-173f926eb3e5-2','32');
DeleteFile('C:\Windows\system32\Tasks\ec6947a1-3226-4d49-a509-173f926eb3e5-4','32');
DeleteFile('C:\Windows\system32\Tasks\ec6947a1-3226-4d49-a509-173f926eb3e5-5','32');
DeleteFile('C:\Windows\system32\Tasks\ec6947a1-3226-4d49-a509-173f926eb3e5-6','32');
DeleteFile('C:\Windows\system32\Tasks\ec6947a1-3226-4d49-a509-173f926eb3e5-7','32');
DeleteFile('C:\Windows\system32\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-1','32');
DeleteFile('C:\Windows\system32\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-11','32');
DeleteFile('C:\Windows\system32\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-2','32');
DeleteFile('C:\Windows\system32\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-3','32');
DeleteFile('C:\Windows\system32\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-4','32');
DeleteFile('C:\Windows\system32\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-5','32');
DeleteFile('C:\Windows\system32\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-6','32');
DeleteFile('C:\Windows\system32\Tasks\ef7ffb6b-ffb6-465d-b517-64a8dd9e3f95-7','32');
DeleteFile('C:\Windows\system32\Tasks\FGRun','32');
DeleteFile('C:\Windows\system32\Tasks\LaunchSignup','32');
DeleteFile('C:\PROGRA~1\COMMON~1\System\SysMenu.dll','32');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\Maintenance\SMupdate2','32');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\Multimedia\SMupdate3','32');
DeleteFile('C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe','32');
DeleteFile('C:\Windows\system32\Tasks\ReimageUpdater','32');
DeleteFile('C:\Windows\system32\Tasks\SMupdate1','32');
DelBHO('{d1dac034-9fd9-4c13-a388-d2e10e57707f}');
DelBHO('{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}');
DelBHO('{68f4dacb-10fa-ca10-ad7d-91b574356f1d}');
DelBHO('{59e47ef9-5163-4e82-9c17-3d6f63dda496}');
DelBHO('{377e5d4d-77e5-476a-8716-7e70a9272da0}');
DelBHO('{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}');
DelBHO('{11111111-1111-1111-1111-110611181104}');
DelBHO('{11111111-1111-1111-1111-110511951199}');
DelBHO('{11111111-1111-1111-1111-110311551110}');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','iLivid');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Only-search');
DeleteService('Util ToggleMark');
DeleteService('Update ToggleMark');
BC_ImportDeletedList;
RegKeyStrParamWrite('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings', 'ProxyServer', '');
RegKeyParamWrite('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings', 'ProxyEnable', 'REG_DWORD', '0');
ExecuteSysClean;
ExecuteWizard('TSW',2,2,true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.