Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\windows\microsoftu\csrss.exe');
TerminateProcessByName('c:\program files\my web shield\mweshield.exe');
TerminateProcessByName('c:\program files\my web shield\mweshieldup.exe');
TerminateProcessByName('c:\windows\microsoftu\srvanyx.exe');
StopService('MicrosoftU');
StopService('mweshield');
StopService('mweshieldup');
StopService('mwescontroller');
QuarantineFile('c:\windows\microsoftu\csrss.exe', '');
QuarantineFile('c:\program files\my web shield\mweshield.exe', '');
QuarantineFile('c:\program files\my web shield\mweshieldup.exe', '');
QuarantineFile('c:\windows\microsoftu\srvanyx.exe', '');
QuarantineFile('C:\Windows\system32\drivers\mwescontroller.sys', '');
QuarantineFile('C:\Users\Energy\AppData\Roaming\Vofer2\ml.py', '');
QuarantineFile('C:\Users\Energy\AppData\Roaming\TeleWIKI\ml.py', '');
QuarantineFile('C:\Users\Energy\AppData\Roaming\gastproffite\ml.py', '');
QuarantineFile('C:\Users\Energy\AppData\Roaming\gastproffite\app.py', '');
QuarantineFile('C:\ProgramData\vCore\VCore.exe', '');
QuarantineFile('C:\Users\Energy\AppData\Roaming\setupsk\ml.py', '');
QuarantineFile('C:\Users\Energy\AppData\Roaming\setupsk\python\pythonw.exe', '');
QuarantineFile('C:\Users\Energy\AppData\Roaming\setupsk\app.py', '');
QuarantineFile('C:\Users\Energy\AppData\Roaming\TeleWIKI\update.py', '');
QuarantineFile('C:\Users\Energy\AppData\Roaming\Vofer2\updater.py', '');
DeleteFile('c:\windows\microsoftu\csrss.exe', '32');
DeleteFile('c:\program files\my web shield\mweshield.exe', '32');
DeleteFile('c:\program files\my web shield\mweshieldup.exe', '32');
DeleteFile('c:\windows\microsoftu\srvanyx.exe', '32');
DeleteFile('C:\Windows\system32\drivers\mwescontroller.sys', '32');
DeleteFile('C:\Users\Energy\AppData\Roaming\Vofer2\ml.py', '32');
DeleteFile('C:\Users\Energy\AppData\Roaming\TeleWIKI\ml.py', '32');
DeleteFile('C:\Users\Energy\AppData\Roaming\gastproffite\ml.py', '32');
DeleteFile('C:\Users\Energy\AppData\Roaming\gastproffite\app.py', '32');
DeleteFile('C:\ProgramData\vCore\VCore.exe', '32');
DeleteFile('C:\Users\Energy\AppData\Roaming\setupsk\ml.py', '32');
DeleteFile('C:\Users\Energy\AppData\Roaming\setupsk\python\pythonw.exe', '32');
DeleteFile('C:\Users\Energy\AppData\Roaming\setupsk\app.py', '32');
DeleteFile('C:\Users\Energy\AppData\Roaming\TeleWIKI\update.py', '32');
DeleteFile('C:\Users\Energy\AppData\Roaming\Vofer2\updater.py', '32');
DeleteFile('C:\Users\Energy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk');
DeleteService('MicrosoftU');
DeleteService('mweshield');
DeleteService('mweshieldup');
DeleteService('mwescontroller');
DeleteFileMask('c:\windows\microsoftu', '*', true);
DeleteFileMask('c:\program files\my web shield', '*', true);
DeleteFileMask('c:\users\energy\appdata\roaming\vofer2', '*', true);
DeleteFileMask('c:\users\energy\appdata\roaming\telewiki', '*', true);
DeleteFileMask('c:\users\energy\appdata\roaming\gastproffite', '*', true);
DeleteFileMask('c:\programdata\vcore', '*', true);
DeleteFileMask('c:\users\energy\appdata\roaming\setupsk', '*', true);
DeleteDirectory('c:\windows\microsoftu');
DeleteDirectory('c:\program files\my web shield');
DeleteDirectory('c:\users\energy\appdata\roaming\vofer2');
DeleteDirectory('c:\users\energy\appdata\roaming\telewiki');
DeleteDirectory('c:\users\energy\appdata\roaming\gastproffite');
DeleteDirectory('c:\programdata\vcore');
DeleteDirectory('c:\users\energy\appdata\roaming\setupsk');
ExecuteFile('schtasks.exe', '/delete /TN "gastproffite" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "gastproffite2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Media Center\VCore" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "setupsk" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "setupsk2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "TeleWIKI" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "TeleWIKI2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Vofer2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Vofer22" /F', 0, 15000, true);
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Vofer2');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'TeleWIKI');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'gastproffite');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\gastproffite', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Vofer2', 'command');
BC_ImportDeletedList;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.