Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
TerminateProcessByName('C:\Program Files\QS\V8DSQOUQ8QNFU2V0EPFIYUED5DBLDJL9ZC6OQH12UYY2TEVIW0VGDXAA3AXNMJNYENPR6HK7YNXA6MU0R2YMYF5BC5UQUOPLK9XFYDLPPXR09AERP65TUAA8SNPBX4NJ8MZ7YP\yd765wa1f1.exe');
TerminateProcessByName('C:\Program Files\QS\V8DSQOUQ8QNFU2V0EPFIYUED5DBLDJL9ZC6OQH12UYY2TEVIW0VGDXAA3AXNMJNYENPR6HK7YNXA6MU0R2YMYF5BC5UQUOPLK9XFYDLPPXR09AERP65TUAA8SNPBX4NJ8MZ7YP\-VmqAKdNaX.exe');
TerminateProcessByName('C:\Users\ASUS\AppData\Roaming\MyDesktop\linkme.exe');
TerminateProcessByName('C:\Users\ASUS\AppData\Roaming\Adobe\Manager.exe');
QuarantineFileF('c:\program files\zaxar', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFile('C:\Program Files\Zaxar\ZaxarLoader.exe', '');
QuarantineFileF('C:\Users\ASUS\AppData\Roaming\Adobe\', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', false, '', 0, 0);
QuarantineFile('C:\Users\ASUS\AppData\Local\Temp\327EC64-CFD4E288-8F7CC012-DAB818BE\696e0c34b.sys', '');
QuarantineFileF('C:\Program Files\Zaxar\', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\Users\ASUS\AppData\Roaming\MyDesktop\', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFile('C:\Program Files\QS\V8DSQOUQ8QNFU2V0EPFIYUED5DBLDJL9ZC6OQH12UYY2TEVIW0VGDXAA3AXNMJNYENPR6HK7YNXA6MU0R2YMYF5BC5UQUOPLK9XFYDLPPXR09AERP65TUAA8SNPBX4NJ8MZ7YP\yd765wa1f1.exe', '');
QuarantineFile('C:\Program Files\QS\V8DSQOUQ8QNFU2V0EPFIYUED5DBLDJL9ZC6OQH12UYY2TEVIW0VGDXAA3AXNMJNYENPR6HK7YNXA6MU0R2YMYF5BC5UQUOPLK9XFYDLPPXR09AERP65TUAA8SNPBX4NJ8MZ7YP\-VmqAKdNaX.exe', '');
QuarantineFile('C:\Users\ASUS\AppData\Roaming\MyDesktop\linkme.exe', '');
QuarantineFile('C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gооglе Сhrome.lnk', '');
QuarantineFile('C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Lаunсh Internеt Eхрlorer Brоwser.lnk', '');
QuarantineFile('C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Мozillа Firefох.lnk', '');
QuarantineFile('C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Орera.lnk', '');
QuarantineFile('C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Мozilla Firеfox.lnk', '');
QuarantineFile('C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Intеrnet Ехрlоrеr (Nо Add-оns).lnk', '');
QuarantineFile('C:\Users\Public\Desktop\Gооgle Сhromе.lnk', '');
QuarantineFile('C:\Users\Public\Desktop\Мozilla Firefоx.lnk', '');
QuarantineFile('C:\Users\Public\Desktop\Орerа.lnk', '');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Chrоme.lnk', '');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox\Мozillа Firefoх (Безoпaсный режим).lnk', '');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox\Моzillа Firefоx.lnk', '');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Мozillа Firеfох.lnk', '');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Оpera.lnk', '');
QuarantineFile('C:\Users\ASUS\AppData\Roaming\Adobe\Manager.exe', '');
QuarantineFile('C:\Users\Public\Desktop\DАЕМON Тоols Ultrа.lnk', '');
QuarantineFile('C:\Users\Public\Desktop\LightSсribe.lnk', '');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Ultra\DАEMОN Тools Ultrа.lnk', '');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling\Gеtting Started.lnk', '');
QuarantineFile('C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\!Играть в War Thunder.lnk', '');
QuarantineFile('C:\Users\ASUS\AppData\Roaming\Browsers\exe.rehcnualtd.bat', '');
QuarantineFile('C:\Users\ASUS\AppData\Roaming\Browsers\exe.rehcnualsl.bat', '');
DeleteFile('C:\Program Files\Zaxar\ZaxarLoader.exe', '32');
DeleteFile('C:\Users\ASUS\AppData\Local\Temp\327EC64-CFD4E288-8F7CC012-DAB818BE\696e0c34b.sys', '32');
DeleteFile('C:\Program Files\QS\V8DSQOUQ8QNFU2V0EPFIYUED5DBLDJL9ZC6OQH12UYY2TEVIW0VGDXAA3AXNMJNYENPR6HK7YNXA6MU0R2YMYF5BC5UQUOPLK9XFYDLPPXR09AERP65TUAA8SNPBX4NJ8MZ7YP\yd765wa1f1.exe');
DeleteFile('C:\Program Files\QS\V8DSQOUQ8QNFU2V0EPFIYUED5DBLDJL9ZC6OQH12UYY2TEVIW0VGDXAA3AXNMJNYENPR6HK7YNXA6MU0R2YMYF5BC5UQUOPLK9XFYDLPPXR09AERP65TUAA8SNPBX4NJ8MZ7YP\-VmqAKdNaX.exe');
DeleteFile('C:\Users\ASUS\AppData\Roaming\MyDesktop\linkme.exe');
DeleteFile('C:\Users\ASUS\AppData\Roaming\Browsers\exe.rehcnualtd.bat', '');
DeleteFile('C:\Users\ASUS\AppData\Roaming\Browsers\exe.rehcnualsl.bat', '');
DeleteFile('C:\Users\ASUS\AppData\Roaming\Adobe\Manager.exe');
ExecuteFile('schtasks.exe', '/delete /TN "Windows desktop installer" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Fofery" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Manager" /F', 0, 15000, true);
DeleteFileMask('C:\Program Files\Zaxar\', '*', true);
DeleteFileMask('c:\program files\zaxar', '*', true);
DeleteFileMask('C:\Users\ASUS\AppData\Roaming\MyDesktop\', '*', true);
DeleteDirectory('C:\Program Files\Zaxar\');
DeleteDirectory('C:\Users\ASUS\AppData\Roaming\MyDesktop\');
DeleteDirectory('c:\program files\zaxar');
BC_ImportALL;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
BC_Activate;
RebootWindows(true);
end.