Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
StopService('ginoquci');
QuarantineFileF('c:\program files (x86)\gmsd_re_005010153', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\program files (x86)\gmsd_re_005010155', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\program files (x86)\gmsd_re_005010159', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\users\acer\appdata\local\systemdir', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsxF68.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsj9354.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsj2E6D.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsrB745.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsfF305.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsz6E64.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsz36B4.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsl6FFD.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsg2B1E.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsj18C9.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsv4838.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsiF088.tmp', '');
QuarantineFile('C:\Users\Acer\AppData\Local\Temp\nsy8B3.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsa62A2.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsk2649.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsk913D.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsi64C.tmp', '');
QuarantineFile('C:\Users\Acer\AppData\Local\51D25470-1446218189-1320-0405-202021000000\qnsb1F41.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsi6363.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsc4C03.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knspBAE1.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knskF79B.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsh198.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsz9661.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsdF384.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knssE1D6.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsvE9EF.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsiC1D3.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knst18AF.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsb62B8.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knscD3E6.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knskD2FA.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsl69E5.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsw882C.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsl855.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knssC9E8.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsr9E27.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knssFAC.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knse5D38.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsz615F.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsn2C5D.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsx26BC.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsj16CA.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsmF2A7.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsrD9DF.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsdBCD2.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsn1322.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsdF8CD.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knseB20D.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knse5EB.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knstDE5.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knse126A.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsf4555.tmp', '');
QuarantineFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsrAFA6.tmp', '');
QuarantineFile('C:\Program Files (x86)\gmsd_re_005010153\gmsd_re_005010153.exe', '');
QuarantineFile('C:\Program Files (x86)\gmsd_re_005010155\gmsd_re_005010155.exe', '');
QuarantineFile('C:\Program Files (x86)\gmsd_re_005010159\gmsd_re_005010159.exe', '');
QuarantineFile('C:\Users\Acer\AppData\Roaming\Browsers\exe.resworb.bat', '');
QuarantineFile('C:\Users\Acer\AppData\Roaming\Browsers\exe.atemok.bat', '');
QuarantineFile('C:\Users\Acer\AppData\Roaming\jPv2VvTV.exe', '');
QuarantineFile('C:\Users\Acer\AppData\Roaming\MN5C2AKtEuZ7jr3P.exe', '');
QuarantineFile('C:\Users\Acer\AppData\Roaming\w26Lg1Fb.exe', '');
QuarantineFile('C:\Users\Acer\AppData\Roaming\ZbujkFeaBKMlMgZL5CfQ8iTS.exe', '');
QuarantineFile('C:\Users\Acer\AppData\Local\SystemDir\nethost.exe', '');
DeleteFile('C:\Windows\Tasks\jPv2VvTV.job', '64');
DeleteFile('C:\Windows\Tasks\MN5C2AKtEuZ7jr3P.job', '64');
DeleteFile('C:\Windows\Tasks\w26Lg1Fb.job', '64');
DeleteFile('C:\Windows\Tasks\ZbujkFeaBKMlMgZL5CfQ8iTS.job', '64');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsxF68.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsj9354.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsj2E6D.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsrB745.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsfF305.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsz6E64.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsz36B4.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsl6FFD.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsg2B1E.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsj18C9.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsv4838.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsiF088.tmp', '32');
DeleteFile('C:\Users\Acer\AppData\Local\Temp\nsy8B3.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsa62A2.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsk2649.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsk913D.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsi64C.tmp', '32');
DeleteFile('C:\Users\Acer\AppData\Local\51D25470-1446218189-1320-0405-202021000000\qnsb1F41.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsi6363.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsc4C03.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knspBAE1.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knskF79B.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsh198.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsz9661.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsdF384.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knssE1D6.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsvE9EF.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsiC1D3.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knst18AF.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsb62B8.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knscD3E6.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knskD2FA.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsl69E5.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsw882C.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsl855.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knssC9E8.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsr9E27.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knssFAC.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knse5D38.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsz615F.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsn2C5D.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsx26BC.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsj16CA.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsmF2A7.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsrD9DF.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsdBCD2.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsn1322.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsdF8CD.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knseB20D.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knse5EB.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knstDE5.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knse126A.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsf4555.tmp', '32');
DeleteFile('C:\Program Files (x86)\51D25470-1438263551-1320-0405-202021000000\knsrAFA6.tmp', '32');
DeleteFile('C:\Program Files (x86)\gmsd_re_005010153\gmsd_re_005010153.exe', '32');
DeleteFile('C:\Program Files (x86)\gmsd_re_005010155\gmsd_re_005010155.exe', '32');
DeleteFile('C:\Program Files (x86)\gmsd_re_005010159\gmsd_re_005010159.exe', '32');
DeleteFile('C:\Users\Acer\AppData\Roaming\Browsers\exe.resworb.bat', '32');
DeleteFile('C:\Users\Acer\AppData\Roaming\Browsers\exe.atemok.bat', '32');
DeleteFile('C:\Users\Acer\AppData\Roaming\jPv2VvTV.exe', '32');
DeleteFile('C:\Users\Acer\AppData\Roaming\MN5C2AKtEuZ7jr3P.exe', '32');
DeleteFile('C:\Users\Acer\AppData\Roaming\w26Lg1Fb.exe', '32');
DeleteFile('C:\Users\Acer\AppData\Roaming\ZbujkFeaBKMlMgZL5CfQ8iTS.exe', '32');
DeleteFile('C:\Users\Acer\AppData\Local\SystemDir\nethost.exe', '32');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "jPv2VvTV" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "MN5C2AKtEuZ7jr3P" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "nethost task" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "w26Lg1Fb" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ZbujkFeaBKMlMgZL5CfQ8iTS" /F', 0, 15000, true);
DeleteService('begujuqe');
DeleteService('bekumyxy');
DeleteService('bidusuty');
DeleteService('birygeme');
DeleteService('dikinoce');
DeleteService('dogimofy');
DeleteService('fehozuqy');
DeleteService('fifopysi');
DeleteService('foqoqege');
DeleteService('fymitipi');
DeleteService('fyreqoxi');
DeleteService('gegiwute');
DeleteService('ginoquci');
DeleteService('gojucysu');
DeleteService('hegozolu');
DeleteService('heleqyky');
DeleteService('hetefezi');
DeleteService('hidekoqe');
DeleteService('higumefe');
DeleteService('hucesuxo');
DeleteService('hyqugyjo');
DeleteService('kiwokyju');
DeleteService('kucypyvu');
DeleteService('ledivyko');
DeleteService('lekiviru');
DeleteService('lesuvizo');
DeleteService('lofuweki');
DeleteService('lokuzewe');
DeleteService('losozixo');
DeleteService('lumusute');
DeleteService('lytyvuwe');
DeleteService('nehesiru');
DeleteService('nibymowi');
DeleteService('nujenody');
DeleteService('nykivobu');
DeleteService('pedufoqo');
DeleteService('piqokezy');
DeleteService('pyhexiji');
DeleteService('pynifuwe');
DeleteService('qixycibo');
DeleteService('qyzemidi');
DeleteService('revitoqu');
DeleteService('sowimocu');
DeleteService('teguqesy');
DeleteService('tohebuhy');
DeleteService('tukymedo');
DeleteService('tylucywe');
DeleteService('wilowymi');
DeleteService('wojokuso');
DeleteService('zekijefe');
DeleteService('zijikige');
DeleteService('zipojune');
DeleteService('zizygyno');
DeleteService('zudyqije');
DeleteFileMask('c:\program files (x86)\gmsd_re_005010153', '*', true);
DeleteFileMask('c:\program files (x86)\gmsd_re_005010155', '*', true);
DeleteFileMask('c:\program files (x86)\gmsd_re_005010159', '*', true);
DeleteFileMask('c:\users\acer\appdata\local\systemdir', '*', true);
DeleteDirectory('c:\program files (x86)\gmsd_re_005010153');
DeleteDirectory('c:\program files (x86)\gmsd_re_005010155');
DeleteDirectory('c:\program files (x86)\gmsd_re_005010159');
DeleteDirectory('c:\users\acer\appdata\local\systemdir');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'gmsd_re_005010153');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'gmsd_re_005010155');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'gmsd_re_005010159');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'tktbuivyff');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.