Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\windows\temp\4242.tmp');
TerminateProcessByName('c:\program files\contentprotector\contentprotector.exe');
TerminateProcessByName('c:\program files\contentprotector\contentprotectorupdate.exe');
TerminateProcessByName('c:\program files\drivertoolkit\drivertoolkit.exe');
TerminateProcessByName('c:\program files\hostify\idscservice.exe');
TerminateProcessByName('c:\program files\003a006c-1458592622-e011-9c9c-947016e3f785\knspc9a1.tmp');
TerminateProcessByName('c:\users\Оксана\appdata\roaming\nssm.exe');
TerminateProcessByName('c:\program files\rec_ru_231\rec_ru_231.exe');
TerminateProcessByName('c:\program files\sunnyday21\sunnyday.exe');
TerminateProcessByName('c:\users\Оксана\appdata\local\sunnyday21\usun.exe');
TerminateProcessByName('c:\program files\win_en_77\win_en_77.exe');
StopService('ContentProtector');
StopService('ContentProtectorUpdate');
StopService('ContentProtectorDrv');
QuarantineFileF('c:\program files\contentprotector', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\program files\rec_ru_231', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\program files\win_en_77', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFile('c:\windows\temp\4242.tmp', '');
QuarantineFile('c:\program files\contentprotector\contentprotector.exe', '');
QuarantineFile('c:\program files\contentprotector\contentprotectorupdate.exe', '');
QuarantineFile('c:\program files\drivertoolkit\drivertoolkit.exe', '');
QuarantineFile('c:\program files\hostify\idscservice.exe', '');
QuarantineFile('c:\program files\003a006c-1458592622-e011-9c9c-947016e3f785\knspc9a1.tmp', '');
QuarantineFile('c:\users\Оксана\appdata\roaming\nssm.exe', '');
QuarantineFile('c:\program files\rec_ru_231\rec_ru_231.exe', '');
QuarantineFile('c:\program files\sunnyday21\sunnyday.exe', '');
QuarantineFile('c:\users\Оксана\appdata\local\sunnyday21\usun.exe', '');
QuarantineFile('c:\program files\win_en_77\win_en_77.exe', '');
QuarantineFile('C:\Program Files\ContentProtector\SSLEAY32.dll', '');
QuarantineFile('C:\Program Files\ContentProtector\LIBEAY32.dll', '');
QuarantineFile('C:\Program Files\DriverToolkit\network.dll', '');
QuarantineFile('C:\Program Files\DriverToolkit\zlibwapi.dll', '');
QuarantineFile('C:\Windows\system32\drivers\ContentProtectorDrv.sys', '');
QuarantineFile('C:\Users\Оксана\AppData\Roaming\ASPackage\ASPackage.exe', '');
QuarantineFile('C:\Program Files\WinTaske\WinTaske\WinTaske.exe', '');
QuarantineFile('C:\Program Files\contentprotector\condefclean.exe', '');
QuarantineFile('C:\Program Files\contentprotector\contentprotectorconrol.exe', '');
QuarantineFile('C:\Program Files\contentprotector\import_root_cert.exe', '');
QuarantineFile('C:\Program Files\contentprotector\nfregdrv.exe', '');
QuarantineFile('C:\Program Files\contentprotector\nss\certutil.exe', '');
QuarantineFile('C:\Program Files\contentprotector\nss\mozcrt19.dll', '');
QuarantineFile('C:\Program Files\contentprotector\nss\nspr4.dll', '');
QuarantineFile('C:\Program Files\contentprotector\nss\nss3.dll', '');
QuarantineFile('C:\Program Files\contentprotector\nss\plc4.dll', '');
QuarantineFile('C:\Program Files\contentprotector\nss\plds4.dll', '');
QuarantineFile('C:\Program Files\contentprotector\nss\smime3.dll', '');
QuarantineFile('C:\Program Files\contentprotector\nss\softokn3.dll', '');
QuarantineFile('C:\Program Files\sunnyday3\sunnyday.exe', '');
DeleteFile('C:\Windows\Tasks\DriverToolkit Autorun.job', '32');
DeleteFile('c:\windows\temp\4242.tmp', '32');
DeleteFile('c:\program files\contentprotector\contentprotector.exe', '32');
DeleteFile('c:\program files\contentprotector\contentprotectorupdate.exe', '32');
DeleteFile('c:\program files\drivertoolkit\drivertoolkit.exe', '32');
DeleteFile('c:\program files\hostify\idscservice.exe', '32');
DeleteFile('c:\program files\003a006c-1458592622-e011-9c9c-947016e3f785\knspc9a1.tmp', '32');
DeleteFile('c:\users\Оксана\appdata\roaming\nssm.exe', '32');
DeleteFile('c:\program files\rec_ru_231\rec_ru_231.exe', '32');
DeleteFile('c:\program files\sunnyday21\sunnyday.exe', '32');
DeleteFile('c:\users\Оксана\appdata\local\sunnyday21\usun.exe', '32');
DeleteFile('c:\program files\win_en_77\win_en_77.exe', '32');
DeleteFile('C:\Program Files\ContentProtector\SSLEAY32.dll', '32');
DeleteFile('C:\Program Files\ContentProtector\LIBEAY32.dll', '32');
DeleteFile('C:\Program Files\DriverToolkit\network.dll', '32');
DeleteFile('C:\Program Files\DriverToolkit\zlibwapi.dll', '32');
DeleteFile('C:\Windows\system32\drivers\ContentProtectorDrv.sys', '32');
DeleteFile('C:\Users\Оксана\AppData\Roaming\ASPackage\ASPackage.exe', '32');
DeleteFile('C:\Program Files\WinTaske\WinTaske\WinTaske.exe', '32');
DeleteFile('C:\Program Files\contentprotector\condefclean.exe', '32');
DeleteFile('C:\Program Files\contentprotector\contentprotectorconrol.exe', '32');
DeleteFile('C:\Program Files\contentprotector\import_root_cert.exe', '32');
DeleteFile('C:\Program Files\contentprotector\nfregdrv.exe', '32');
DeleteFile('C:\Program Files\contentprotector\nss\certutil.exe', '32');
DeleteFile('C:\Program Files\contentprotector\nss\mozcrt19.dll', '32');
DeleteFile('C:\Program Files\contentprotector\nss\nspr4.dll', '32');
DeleteFile('C:\Program Files\contentprotector\nss\nss3.dll', '32');
DeleteFile('C:\Program Files\contentprotector\nss\plc4.dll', '32');
DeleteFile('C:\Program Files\contentprotector\nss\plds4.dll', '32');
DeleteFile('C:\Program Files\contentprotector\nss\smime3.dll', '32');
DeleteFile('C:\Program Files\contentprotector\nss\softokn3.dll', '32');
DeleteFile('C:\Program Files\sunnyday3\sunnyday.exe', '32');
DeleteService('clr_optimization_v1.0');
DeleteService('ContentProtector');
DeleteService('ContentProtectorUpdate');
DeleteService('ContentProtectorDrv');
DeleteFileMask('c:\program files\contentprotector', '*', true);
DeleteFileMask('c:\program files\drivertoolkit', '*', true);
DeleteFileMask('c:\program files\hostify', '*', true);
DeleteFileMask('c:\program files\rec_ru_231', '*', true);
DeleteFileMask('c:\program files\sunnyday21', '*', true);
DeleteFileMask('c:\users\оксана\appdata\local\sunnyday21', '*', true);
DeleteFileMask('c:\program files\win_en_77', '*', true);
DeleteFileMask('c:\users\оксана\appdata\roaming\aspackage', '*', true);
DeleteFileMask('c:\program files\wintaske', '*', true);
DeleteFileMask('c:\program files\sunnyday3', '*', true);
DeleteDirectory('c:\program files\contentprotector');
DeleteDirectory('c:\program files\drivertoolkit');
DeleteDirectory('c:\program files\hostify');
DeleteDirectory('c:\program files\rec_ru_231');
DeleteDirectory('c:\program files\sunnyday21');
DeleteDirectory('c:\users\оксана\appdata\local\sunnyday21');
DeleteDirectory('c:\program files\win_en_77');
DeleteDirectory('c:\users\оксана\appdata\roaming\aspackage');
DeleteDirectory('c:\program files\wintaske');
DeleteDirectory('c:\program files\sunnyday3');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "DriverToolkit Autorun" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "WinTaske" /F', 0, 15000, true);
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'rec_ru_231');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'win_en_77');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'usun.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'Update');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'GoogleChromeAutoLaunch_9E601395944699F2AAB8B0F5A99A82A1');
BC_ImportALL;
ExecuteSysClean;
BC_DeleteSvc('clr_optimization_v1.0');
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.