Код:
begin
QuarantineFile('C:\Users\SHIT\appdata\roaming\funspace\shadow\funspace.update\funspace.update.process.exe','');
QuarantineFile('C:\Windows\syswow64\netupdsrv.exe','');
QuarantineFile('C:\Windows\syswow64\nethtsrv.exe','');
QuarantineFile('C:\Windows\syswow64\hfpapi.dll','');
QuarantineFile('C:\Windows\syswow64\hfnapi.dll','');
QuarantineFile('C:\Windows\system32\netupdsrv.exe','');
QuarantineFile('C:\Windows\system32\nethtsrv.exe','');
QuarantineFile('C:\Windows\system32\hfpapi.dll','');
QuarantineFile('C:\Windows\system32\hfnapi.dll','');
QuarantineFile('F:\MusaLLaT.exe','');
DelBHO('{5db63993-952f-41bb-ad7a-483106688920}');
QuarantineFile('C:\Users\SHIT\AppData\Roaming\MusaLLaT.exe','');
QuarantineFile('C:\Users\SHIT\AppData\Roaming\Images\CNminer.exe','');
QuarantineFile('C:\Users\SHIT\AppData\Roaming\FunSpace\VKMusicUpd\FunSpace.Update.Process.exe','');
StopService('nethfdrv');
DeleteService('nethfdrv');
QuarantineFile('C:\Windows\SysWOW64\nethtsrv.exe','');
QuarantineFile('C:\Windows\SysWOW64\netupdsrv.exe','');
StopService('ServiceUpdater');
DeleteService('ServiceUpdater');
StopService('NetHttpService');
DeleteService('NetHttpService');
QuarantineFile('C:\Windows\system32\drivers\nethfdrv.sys','');
QuarantineFile('C:\Windows\SysWOW64\hfpapi.dll','');
QuarantineFile('C:\Windows\SysWOW64\hfnapi.dll','');
TerminateProcessByName('c:\windows\syswow64\netupdsrv.exe');
QuarantineFile('c:\windows\syswow64\netupdsrv.exe','');
TerminateProcessByName('c:\windows\syswow64\nethtsrv.exe');
QuarantineFile('c:\windows\syswow64\nethtsrv.exe','');
TerminateProcessByName('c:\users\shit\appdata\roaming\musallat.exe');
QuarantineFile('c:\users\shit\appdata\roaming\musallat.exe','');
DeleteFile('c:\users\shit\appdata\roaming\musallat.exe','32');
DeleteFile('c:\windows\syswow64\nethtsrv.exe','32');
DeleteFile('c:\windows\syswow64\netupdsrv.exe','32');
DeleteFile('C:\Windows\SysWOW64\hfnapi.dll','32');
DeleteFile('C:\Windows\SysWOW64\hfpapi.dll','32');
DeleteFile('C:\Windows\system32\drivers\nethfdrv.sys','32');
DeleteFile('C:\Windows\SysWOW64\netupdsrv.exe','32');
DeleteFile('C:\Windows\SysWOW64\nethtsrv.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','VKMusic update process');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\VKMusic update process','command');
DeleteFile('C:\Users\SHIT\AppData\Roaming\FunSpace\VKMusicUpd\FunSpace.Update.Process.exe','32');
DeleteFile('C:\Users\SHIT\AppData\Roaming\Images\CNminer.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','CNminer');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','MusaLLaT');
DeleteFile('C:\Users\SHIT\AppData\Roaming\MusaLLaT.exe','32');
DeleteFile('C:\Windows\Tasks\AmiUpdXp.job','64');
DeleteFile('C:\Windows\system32\Tasks\AmiUpdXp','64');
ClearHostsFile;
DeleteFile('C:\Windows\system32\hfnapi.dll','32');
DeleteFile('C:\Windows\system32\hfpapi.dll','32');
DeleteFile('C:\Windows\system32\nethtsrv.exe','32');
DeleteFile('C:\Windows\system32\netupdsrv.exe','32');
DeleteFile('C:\Windows\syswow64\hfnapi.dll','32');
DeleteFile('C:\Windows\syswow64\hfpapi.dll','32');
DeleteFile('C:\Windows\syswow64\nethtsrv.exe','32');
DeleteFile('C:\Windows\syswow64\netupdsrv.exe','32');
DeleteFile('C:\Users\SHIT\appdata\roaming\funspace\shadow\funspace.update\funspace.update.process.exe','32');
ExecuteSysClean;
Executerepair(6);
Executerepair(17);
RebootWindows(true);
end.