begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\ProgramData\install\cheat.exe', '');
QuarantineFile('C:\ProgramData\install\sys.exe', '');
QuarantineFile('C:\ProgramData\RealtekHD\taskhostw.exe', '');
QuarantineFile('c:\programdata\rundll\system.exe', '');
QuarantineFile('c:\programdata\windows\rfusclient.exe', '');
QuarantineFile('c:\programdata\windows\rutserv.exe', '');
QuarantineFile('c:\programdata\windowstask\audiodg.exe', '');
QuarantineFile('C:\ProgramData\WindowsTask\MicrosoftHost.exe', '');
QuarantineFile('C:\ProgramData\windowstask\winlogon.exe', '');
QuarantineFile('C:\Windows\java.exe', '');
QuarantineFile('C:\Windows\svchost.exe', '');
QuarantineFile('f:\av_block_remover\taskhostw.exe', '');
QuarantineFileF('C:\ProgramData\install\', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('C:\ProgramData\rundll', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\programdata\windows', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('C:\ProgramData\windowstask', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
DeleteFile('C:\ProgramData\install\cheat.exe', '32');
DeleteFile('C:\ProgramData\install\sys.exe', '32');
DeleteFile('C:\ProgramData\RealtekHD\taskhostw.exe', '32');
DeleteFile('C:\ProgramData\RealtekHD\taskhostw.exe', '64');
DeleteFile('c:\programdata\rundll\system.exe', '32');
DeleteFile('c:\programdata\rundll\system.exe', '64');
DeleteFile('c:\programdata\windows\rfusclient.exe', '32');
DeleteFile('c:\programdata\windows\rutserv.exe', '32');
DeleteFile('c:\programdata\windows\rutserv.exe', '64');
DeleteFile('C:\ProgramData\windowstask\audiodg.exe', '32');
DeleteFile('C:\ProgramData\windowstask\microsofthost.exe', '32');
DeleteFile('C:\ProgramData\WindowsTask\MicrosoftHost.exe', '64');
DeleteFile('C:\ProgramData\windowstask\winlogon.exe', '32');
DeleteFile('C:\Windows\java.exe', '32');
DeleteFile('C:\Windows\svchost.exe', '32');
DeleteFileMask('C:\ProgramData\install\', '*.*', true);
DeleteFileMask('C:\ProgramData\rundll', '*.*', true);
DeleteFileMask('c:\programdata\windows', '*.*', true);
DeleteFileMask('C:\ProgramData\windowstask', '*.*', true);
DeleteDirectory('C:\ProgramData\install\');
DeleteDirectory('C:\ProgramData\rundll');
DeleteDirectory('c:\programdata\windows');
DeleteDirectory('C:\ProgramData\windowstask');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Realtek HD Audio', 'x32');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Realtek HD Audio', 'x64');
ClearHostsFile;
BC_ImportALL;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
BC_Activate;
RebootWindows(true);
end.