Код:
begin
QuarantineFile('C:\Windows\system32\Zoegceato.dll','');
QuarantineFile('C:\Program Files\groover300820151711\Euineis.bat','');
DelBHO('{36D83219-421C-436D-87A7-0682A3781DE1}');
QuarantineFile('C:\Users\Alexander\AppData\Roaming\cpuminer\sgminer\start.cmd','');
QuarantineFile('C:\Program Files\groover300820151711\dr_inst.exe','');
QuarantineFile('C:\Program Files\groover300820151711\Lotbi64.exe','');
QuarantineFile('C:\Program Files\groover300820151711\Lotbi.exe','');
QuarantineFile('C:\Program Files (x86)\YTDownloader\YTDownloader.exe','');
StopService('cherimoya');
DeleteService('cherimoya');
DeleteService('witewili');
DeleteService('WdsManPro');
DeleteService('totyseku');
DeleteService('SSFK');
DeleteService('jimocoso');
DeleteService('groover300820151711 Updater');
DeleteService('csrcc');
DeleteService('21C49BB6-7CDB-478F-8D05-44C6F236D73A');
QuarantineFile('C:\Program Files (x86)\03000200-1441585897-0500-0006-000700080009\knsw3A1B.tmpfs','');
QuarantineFile('C:\ProgramData\aWdsManProa\WdsManPro.exe','');
QuarantineFile('C:\Program Files (x86)\03000200-1441585897-0500-0006-000700080009\hnsd7018.tmp','');
QuarantineFile('C:\Program Files (x86)\SFK\SSFK.exe','');
QuarantineFile('C:\Program Files (x86)\03000200-1441585897-0500-0006-000700080009\jnst575E.tmp','');
QuarantineFile('C:\Program Files\groover300820151711\Zhyyoqam.exe','');
QuarantineFile('C:\Program Files\groover300820151711\csrcc.exe','');
QuarantineFile('C:\Program Files\groover300820151711\Gujrijo.exe','');
DeleteFile('C:\Program Files\groover300820151711\Gujrijo.exe','32');
DeleteFile('C:\Program Files\groover300820151711\csrcc.exe','32');
DeleteFile('C:\Program Files\groover300820151711\Zhyyoqam.exe','32');
DeleteFile('C:\Program Files (x86)\03000200-1441585897-0500-0006-000700080009\jnst575E.tmp','32');
DeleteFile('C:\Program Files (x86)\SFK\SSFK.exe','32');
DeleteFile('C:\Program Files (x86)\03000200-1441585897-0500-0006-000700080009\hnsd7018.tmp','32');
DeleteFile('C:\ProgramData\aWdsManProa\WdsManPro.exe','32');
DeleteFile('C:\Program Files (x86)\03000200-1441585897-0500-0006-000700080009\knsw3A1B.tmpfs','32');
DeleteFile('C:\Windows\system32\drivers\cherimoya.sys','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','YTDownloader');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','YTDownloader');
DeleteFile('C:\Program Files (x86)\YTDownloader\YTDownloader.exe','32');
DeleteFile('C:\Program Files\groover300820151711\Lotbi.exe','32');
DeleteFile('C:\Program Files\groover300820151711\Lotbi64.exe','32');
DeleteFile('C:\Program Files\groover300820151711\dr_inst.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','prtstart');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','groover30082015171164');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','groover300820151711');
DeleteFile('C:\Users\Alexander\AppData\Roaming\cpuminer\sgminer\start.cmd','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gpuminer');
DeleteFile('C:\Program Files\groover300820151711\Colmugt.dll','32');
DeleteFile('C:\Windows\Tasks\AmiUpdXp.job','32');
DeleteFile('C:\Windows\system32\Tasks\AmiUpdXp','64');
DeleteFile('C:\Windows\system32\Tasks\Pesdyhme','64');
DeleteFile('C:\Program Files\groover300820151711\Euineis.bat','32');
DeleteFile('C:\Windows\system32\Zoegceato.dll','32');
ExecuteSysClean;
Executerepair(15);
RebootWindows(true);
end.