Код:
begin
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
QuarantineFile('C:\Users\Костян\AppData\Local\Temp\0.1480132658013975.exe','');
QuarantineFile('C:\Users\WWW\AppData\Roaming\Browsers\exe.resworb.bat','');
QuarantineFile('C:\Users\WWW\AppData\Roaming\Browsers\exe.resworb-mooronik.bat','');
QuarantineFile('C:\Users\WWW\AppData\Roaming\Browsers\exe.erolpxei.bat','');
QuarantineFile('C:\Users\WWW\AppData\Roaming\Browsers\exe.emorhc.bat','');
QuarantineFile('C:\Users\WWW\AppData\Local\Temp\16DA.tmp','');
QuarantineFile('C:\Users\WWW\0.6673341659515754.exe','');
DeleteService('TicnoIndexator');
DeleteFile('C:\Program Files\Ticno\Indexator\SearchService.exe','32');
DeleteFile('C:\Users\WWW\0.6673341659515754.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','S1724983');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','S115368');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','S4266172');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','S859295');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','S741160');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','S4054176');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','S196101112');
DeleteFile('C:\Users\WWW\AppData\Local\Temp\16DA.tmp','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','PC Performer43885.exe');
DeleteFile('C:\Users\WWW\AppData\Roaming\Browsers\exe.emorhc.bat','32');
DeleteFile('C:\Users\WWW\AppData\Roaming\Browsers\exe.erolpxei.bat','32');
DeleteFile('C:\Users\WWW\AppData\Roaming\Browsers\exe.resworb-mooronik.bat','32');
DeleteFile('C:\Users\WWW\AppData\Roaming\Browsers\exe.resworb.bat','32');
DeleteFile('C:\Users\Костян\AppData\Local\Temp\0.1480132658013975.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\0.1480132658013975.exe','command');
DeleteFile('C:\Windows\system32\Tasks\Kbupdater Utility','32');
ExecuteSysClean;
RebootWindows(true);
end.