Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
TerminateProcessByName('c:\users\cd92~1\appdata\local\temp\8nqcg.exe');
TerminateProcessByName('c:\users\cd92~1\appdata\local\temp\u4xrs.exe');
TerminateProcessByName('c:\users\cd92~1\appdata\local\temp\wfnrm.exe');
QuarantineFile('c:\users\cd92~1\appdata\local\temp\8nqcg.exe', '');
QuarantineFile('c:\users\cd92~1\appdata\local\temp\u4xrs.exe', '');
QuarantineFile('c:\users\cd92~1\appdata\local\temp\wfnrm.exe', '');
QuarantineFile('C:\Users\Рамиль\AppData\Roaming\WindowsUpdate\mobsync.exe', '');
QuarantineFile('C:\Users\Рамиль\AppData\Roaming\WindowsUpdate\VGA.exe', '');
QuarantineFile('C:\Users\Рамиль\AppData\Roaming\WindowsUpdate\MSupdate.exe', '');
QuarantineFile('C:\Users\Рамиль\AppData\Roaming\Update\MSupdate.exe', '');
QuarantineFileF('c:\users\Рамиль\appdata\roaming\{d67a5d9d-d39f-1459-2602-c06c185ec843}\', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('c:\programdata\{ecf74365-8a01-c79e-4158-a40b033f1953}\', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFile('C:\Users\Рамиль\AppData\Roaming\Microsoft\Windows\Qlauak.exe', '');
TerminateProcessByName('C:\Users\Рамиль\AppData\Roaming\Windows Live\rxoaefqeqi.exe');
QuarantineFile('C:\Users\Рамиль\AppData\Roaming\Windows Live\rxoaefqeqi.exe', '');
DeleteFile('C:\Users\Рамиль\AppData\Roaming\Windows Live\rxoaefqeqi.exe');
TerminateProcessByName('C:\Users\Рамиль\appdata\roaming\update\explorer.exe');
QuarantineFile('C:\Users\Рамиль\appdata\roaming\update\explorer.exe', '');
DeleteFile('C:\Users\Рамиль\appdata\roaming\update\explorer.exe');
TerminateProcessByName('C:\Users\Рамиль\appdata\roaming\update\update.exe');
QuarantineFile('C:\Users\Рамиль\appdata\roaming\update\update.exe', '');
DeleteFile('C:\Users\Рамиль\appdata\roaming\update\update.exe');
TerminateProcessByName('C:\Users\Рамиль\appdata\roaming\windowsupdate\live.exe');
QuarantineFile(' QuarantineFile('C:\Users\Рамиль\appdata\roaming\windowsupdate\live.exe', '');', '');
DeleteFile(' QuarantineFile('C:\Users\Рамиль\appdata\roaming\windowsupdate\live.exe', '');');
QuarantineFile(' DeleteFile('C:\Users\Рамиль\appdata\roaming\windowsupdate\live.exe');', '');
DeleteFile(' DeleteFile('C:\Users\Рамиль\appdata\roaming\windowsupdate\live.exe');');
DeleteFile('C:\Users\Рамиль\AppData\Roaming\Microsoft\Windows\Qlauak.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Qlauak');
QuarantineFile('C:\Users\Рамиль\appdata\roaming\c731200','');
DeleteFile('C:\Users\Рамиль\appdata\roaming\c731200','32');
DeleteFile('c:\users\cd92~1\appdata\local\temp\8nqcg.exe', '32');
DeleteFile('c:\users\cd92~1\appdata\local\temp\u4xrs.exe', '32');
DeleteFile('c:\users\cd92~1\appdata\local\temp\wfnrm.exe', '32');
DeleteFile('C:\Users\Рамиль\AppData\Roaming\WindowsUpdate\mobsync.exe', '32');
DeleteFile('C:\Users\Рамиль\AppData\Roaming\WindowsUpdate\VGA.exe', '32');
DeleteFile('C:\Users\Рамиль\AppData\Roaming\WindowsUpdate\MSupdate.exe', '32');
DeleteFile('C:\Users\Рамиль\AppData\Roaming\Update\MSupdate.exe', '32');
DeleteFileMask('c:\users\Рамиль\appdata\roaming\{d67a5d9d-d39f-1459-2602-c06c185ec843}\', '*', true);
DeleteFileMask('c:\programdata\{ecf74365-8a01-c79e-4158-a40b033f1953}\', '*', true);
DeleteDirectory('c:\users\Рамиль\appdata\roaming\{d67a5d9d-d39f-1459-2602-c06c185ec843}\');
DeleteDirectory('c:\programdata\{ecf74365-8a01-c79e-4158-a40b033f1953}\');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\{4A6A75AD-FBAF-8849-2602-C06C185EC843}', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\{70E76B55-A231-5B8E-4158-A40B033F1953}', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows NT\CurrentVersion\Winlogon', 'Taskman');
BC_ImportALL;
ExecuteSysClean;
ExecuteWizard('TSW', 2, 3, true);
ExecuteWizard('SCU', 2, 3, true);
BC_Activate;
RebootWindows(true);
end.