Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\programdata\appmgr2.49.6826863\appmgr.exe');
TerminateProcessByName('c:\program files\browsemark\bin\browsemark.browseradapter.exe');
TerminateProcessByName('c:\program files\browsemark\bin\browsemark.expext.exe');
TerminateProcessByName('c:\program files\browsemark\bin\browsemark.purbrowse.exe');
TerminateProcessByName('c:\programdata\602bb5c5-64ca-4d9f-8688-8581d865cedf\maintainer.exe');
TerminateProcessByName('c:\programdata\appmgr2.49.6826863\1\plugin.exe');
TerminateProcessByName('c:\program files\browsemark\updatebrowsemark.exe');
TerminateProcessByName('c:\program files\browsemark\bin\utilbrowsemark.exe');
StopService('AppMgr2.49.6826863');
StopService('MaintainerSvc2.49.6826863');
StopService('Update BrowseMark');
StopService('Util BrowseMark');
StopService('{1d80e5b5-4071-4723-b69d-7303dd29b08f}w');
StopService('{4a17b2a1-9a19-4f33-9c1a-453c32556d00}w');
StopService('{5e58d02b-6bcf-4282-80e0-3181dfa24f06}w');
StopService('{90b6a102-782f-4c36-a3a9-17de29ea9425}w');
StopService('{b99c8534-7800-48fa-bd71-519a46cdc7e1}w');
StopService('{f4af1644-0425-4875-acd7-e31b7a10de1c}w');
QuarantineFileF('c:\programdata\appmgr2.49.6826863', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js', true, '', 0 , 0);
QuarantineFileF('c:\programdata\602bb5c5-64ca-4d9f-8688-8581d865cedf', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js', true, '', 0 , 0);
QuarantineFile('c:\programdata\appmgr2.49.6826863\appmgr.exe', '');
QuarantineFile('c:\program files\browsemark\bin\browsemark.browseradapter.exe', '');
QuarantineFile('c:\program files\browsemark\bin\browsemark.expext.exe', '');
QuarantineFile('c:\program files\browsemark\bin\browsemark.purbrowse.exe', '');
QuarantineFile('c:\programdata\602bb5c5-64ca-4d9f-8688-8581d865cedf\maintainer.exe', '');
QuarantineFile('c:\programdata\appmgr2.49.6826863\1\plugin.exe', '');
QuarantineFile('c:\program files\browsemark\updatebrowsemark.exe', '');
QuarantineFile('c:\program files\browsemark\bin\utilbrowsemark.exe', '');
QuarantineFile('C:\Program Files\BrowseMark\bin\1d80.dll', '');
QuarantineFile('C:\Program Files\BrowseMark\bin\1d80e5b540.dll', '');
QuarantineFile('C:\Windows\system32\drivers\{1d80e5b5-4071-4723-b69d-7303dd29b08f}w.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{4a17b2a1-9a19-4f33-9c1a-453c32556d00}w.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{5e58d02b-6bcf-4282-80e0-3181dfa24f06}w.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{90b6a102-782f-4c36-a3a9-17de29ea9425}w.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{b99c8534-7800-48fa-bd71-519a46cdc7e1}w.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{f4af1644-0425-4875-acd7-e31b7a10de1c}w.sys', '');
QuarantineFile('C:\Program Files\Mobogenie\DaemonProcess.exe', '');
QuarantineFile('C:\Windows\system32\ezShellStart.exe', '');
QuarantineFile('C:\Program Files\BrowseMark\BrowseMarkBHO.dll', '');
QuarantineFile('C:\Windows\system32\gatherNetworkInfo.vbs', '');
QuarantineFile('C:\Users\User\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.26.12\..\updt.js', '');
QuarantineFile('C:\Users\User\appdata\local\pay-by-ads\yahoo! search\1.3.12.4\dsrlte.exe', '');
QuarantineFile('C:\Users\User\appdata\local\pay-by-ads\yahoo! search\1.3.12.4\dsrsetup.exe', '');
QuarantineFile('C:\Users\User\appdata\local\pay-by-ads\yahoo! search\1.3.15.4\dsrsetup.exe', '');
QuarantineFile('C:\Program Files\browsemark\bin\browsemark.browseradapter64.exe', '');
QuarantineFile('C:\Program Files\browsemark\bin\{B99C8534-7800-48FA-BD71-519A46CDC7E1}.dll', '');
DeleteFile('c:\programdata\appmgr2.49.6826863\appmgr.exe', '32');
DeleteFile('c:\program files\browsemark\bin\browsemark.browseradapter.exe', '32');
DeleteFile('c:\program files\browsemark\bin\browsemark.expext.exe', '32');
DeleteFile('c:\program files\browsemark\bin\browsemark.purbrowse.exe', '32');
DeleteFile('c:\programdata\602bb5c5-64ca-4d9f-8688-8581d865cedf\maintainer.exe', '32');
DeleteFile('c:\programdata\appmgr2.49.6826863\1\plugin.exe', '32');
DeleteFile('c:\program files\browsemark\updatebrowsemark.exe', '32');
DeleteFile('c:\program files\browsemark\bin\utilbrowsemark.exe', '32');
DeleteFile('C:\Program Files\BrowseMark\bin\1d80.dll', '32');
DeleteFile('C:\Program Files\BrowseMark\bin\1d80e5b540.dll', '32');
DeleteFile('C:\Windows\system32\drivers\{1d80e5b5-4071-4723-b69d-7303dd29b08f}w.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{4a17b2a1-9a19-4f33-9c1a-453c32556d00}w.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{5e58d02b-6bcf-4282-80e0-3181dfa24f06}w.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{90b6a102-782f-4c36-a3a9-17de29ea9425}w.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{b99c8534-7800-48fa-bd71-519a46cdc7e1}w.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{f4af1644-0425-4875-acd7-e31b7a10de1c}w.sys', '32');
DeleteFile('C:\Program Files\Mobogenie\DaemonProcess.exe', '32');
DeleteFile('C:\Windows\system32\ezShellStart.exe', '32');
DeleteFile('C:\Program Files\BrowseMark\BrowseMarkBHO.dll', '32');
DeleteFile('C:\Windows\system32\gatherNetworkInfo.vbs', '32');
DeleteFile('C:\Users\User\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.26.12\..\updt.js', '32');
DeleteFile('C:\Users\User\appdata\local\pay-by-ads\yahoo! search\1.3.12.4\dsrlte.exe', '32');
DeleteFile('C:\Users\User\appdata\local\pay-by-ads\yahoo! search\1.3.12.4\dsrsetup.exe', '32');
DeleteFile('C:\Users\User\appdata\local\pay-by-ads\yahoo! search\1.3.15.4\dsrsetup.exe', '32');
DeleteFile('C:\Program Files\browsemark\bin\browsemark.browseradapter64.exe', '32');
DeleteFile('C:\Program Files\browsemark\bin\{B99C8534-7800-48FA-BD71-519A46CDC7E1}.dll', '32');
DeleteService('AppMgr2.49.6826863');
DeleteService('MaintainerSvc2.49.6826863');
DeleteService('Update BrowseMark');
DeleteService('Util BrowseMark');
DeleteService('{1d80e5b5-4071-4723-b69d-7303dd29b08f}w');
DeleteService('{4a17b2a1-9a19-4f33-9c1a-453c32556d00}w');
DeleteService('{5e58d02b-6bcf-4282-80e0-3181dfa24f06}w');
DeleteService('{90b6a102-782f-4c36-a3a9-17de29ea9425}w');
DeleteService('{b99c8534-7800-48fa-bd71-519a46cdc7e1}w');
DeleteService('{f4af1644-0425-4875-acd7-e31b7a10de1c}w');
DeleteFileMask('c:\programdata\appmgr2.49.6826863', '*', true);
DeleteFileMask('c:\program files\browsemark', '*', true);
DeleteFileMask('c:\programdata\602bb5c5-64ca-4d9f-8688-8581d865cedf', '*', true);
DeleteFileMask('C:\Program Files\Mobogenie', '*', true);
DeleteFileMask('C:\Users\User\AppData\Local\Pay-By-Ads', '*', true);
DeleteDirectory('c:\programdata\appmgr2.49.6826863');
DeleteDirectory('c:\program files\browsemark');
DeleteDirectory('c:\programdata\602bb5c5-64ca-4d9f-8688-8581d865cedf');
DeleteDirectory('C:\Program Files\Mobogenie');
DeleteDirectory('C:\Users\User\AppData\Local\Pay-By-Ads');
DelBHO('{aeac172e-2e4b-4b92-9af6-b0cdb1acecdb}');
ExecuteFile('schtasks.exe', '/delete /TN "Yahoo! Search Updater" /F', 0, 15000, true);
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'mobilegeni daemon');
RegKeyStrParamWrite('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'ctfmon', 'C:Windows\system32\ctfmon.exe');
BC_ImportALL;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.