Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\users\user\appdata\roaming\mozilla\cmozilla.exe');
TerminateProcessByName('c:\users\user\appdata\local\temp\cb0.tmp\cpu.exe');
TerminateProcessByName('c:\users\user\appdata\roaming\svchost.exe');
TerminateProcessByName('c:\users\user\appdata\roaming\googlesoftware\tousb.exe');
TerminateProcessByName('c:\users\user\appdata\roaming\googlesoftware\winlg.exe');
QuarantineFile('c:\users\user\appdata\roaming\mozilla\cmozilla.exe', '');
QuarantineFile('c:\users\user\appdata\local\temp\cb0.tmp\cpu.exe', '');
QuarantineFile('c:\users\user\appdata\roaming\svchost.exe', '');
QuarantineFile('c:\users\user\appdata\roaming\googlesoftware\tousb.exe', '');
QuarantineFile('c:\users\user\appdata\roaming\googlesoftware\winlg.exe', '');
QuarantineFile('C:\Windows\System32\themctrl.dll', '');
QuarantineFile('C:\Windows\System32\wbiosrvp.dll', '');
QuarantineFile('C:\Users\User\AppData\Local\PowerMonitor\PowerMonitor.exe', '');
QuarantineFile('C:\Users\User\AppData\Local\ScriptWriter\ScriptWriter.exe', '');
QuarantineFile('C:\Users\User\appdata\local\temp\pzd.exe', '');
DeleteFile('c:\users\user\appdata\roaming\mozilla\cmozilla.exe', '32');
DeleteFile('c:\users\user\appdata\local\temp\cb0.tmp\cpu.exe', '32');
DeleteFile('c:\users\user\appdata\roaming\svchost.exe', '32');
DeleteFile('c:\users\user\appdata\roaming\googlesoftware\tousb.exe', '32');
DeleteFile('c:\users\user\appdata\roaming\googlesoftware\winlg.exe', '32');
DeleteFile('C:\Windows\System32\themctrl.dll', '32');
DeleteFile('C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk', '32');
DeleteFile('C:\Windows\System32\wbiosrvp.dll', '32');
DeleteFile('C:\Users\User\AppData\Local\PowerMonitor\PowerMonitor.exe', '32');
DeleteFile('C:\Users\User\AppData\Local\ScriptWriter\ScriptWriter.exe', '32');
DeleteFile('C:\Users\User\appdata\local\temp\pzd.exe', '32');
DeleteFileMask('c:\users\user\appdata\roaming\googlesoftware', '*', true);
DeleteFileMask('c:\users\user\appdata\local\powermonitor', '*', true);
DeleteFileMask('c:\users\user\appdata\local\scriptwriter', '*', true);
DeleteDirectory('c:\users\user\appdata\roaming\googlesoftware');
DeleteDirectory('c:\users\user\appdata\local\powermonitor');
DeleteDirectory('c:\users\user\appdata\local\scriptwriter');
ExecuteFile('schtasks.exe', '/delete /TN "Google_SU" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "PowerMonitor" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ScriptWriter" /F', 0, 15000, true);
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'nggumonevw');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\themctrl\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\wbiosrvp\Parameters', 'ServiceDll');
BC_ImportALL;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.