begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\User\AppData\Local\appdater\Appdater.exe','');
QuarantineFile('C:\Users\User\AppData\Local\yaoffer50160\yaoffer50160.exe','');
QuarantineFile('c:\users\user\appdata\local\appdater\appdater.exe','');
DeleteFile('c:\users\user\appdata\local\appdater\appdater.exe','32');
DeleteFile('C:\Users\User\AppData\Local\yaoffer50160\yaoffer50160.exe','64');
DeleteFile('C:\Users\User\AppData\Local\appdater\Appdater.exe','64');
RegKeyDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\yaoffer50160','x64');
DeleteSchedulerTask('Appdater_tray.job');
DeleteSchedulerTask('Appdater_tray');
BC_Activate;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
BC_ImportALL;
RebootWindows(true);
end.