begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFileF('c:\documents and settings\user\local settings\application data\syslog', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFile('C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Start Menu\Вoйти в Интeрнeт.lnk', '');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Application Data\syslog\syslog.exe', '');
ExecuteFile('schtasks.exe', '/delete /TN "C:\WINDOWS\Tasks\syslog.job" /F', 0, 15000, true);
DeleteFile('C:\Documents and Settings\User\Local Settings\Application Data\syslog\syslog.exe', '32');
DeleteFileMask('c:\documents and settings\user\local settings\application data\syslog', '*', true);
DeleteDirectory('c:\documents and settings\user\local settings\application data\syslog');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\razmghzaoe','command');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.