Код:
begin
TerminateProcessByName('C:\Users\user\AppData\Roaming\463437\164150.exe');
TerminateProcessByName('C:\Users\user\AppData\Roaming\440947\167031.exe');
TerminateProcessByName('C:\Users\user\AppData\Roaming\178047\237277.exe');
TerminateProcessByName('C:\Program Files\2DJDCC0AAA\2DJDCC0AA.exe');
TerminateProcessByName('C:\Program Files\35DQ6YZ9XO\35DQ6YZ9X.exe');
TerminateProcessByName('C:\Program Files\3JKMDE0CF1\3JKMDE0CF.exe');
TerminateProcessByName('C:\Program Files\491UQ9ZVOJ\491UQ9ZVO.exe');
TerminateProcessByName('C:\Program Files\5APFXRMF3X\5APFXRMF3.exe');
TerminateProcessByName('C:\Program Files\5TRRDBB0VD\5TRRDBB0V.exe');
TerminateProcessByName('C:\Users\user\AppData\Roaming\727292\617770.exe');
TerminateProcessByName('C:\Users\user\AppData\Roaming\234726\637527.exe');
TerminateProcessByName('C:\Users\user\AppData\Roaming\740388\670994.exe');
TerminateProcessByName('C:\Users\user\AppData\Roaming\518397\686708.exe');
TerminateProcessByName('C:\Program Files\ICFQ8EJIQP\6Q0UWMP86.exe');
TerminateProcessByName('C:\Users\user\AppData\Roaming\272391\747174.exe');
TerminateProcessByName('C:\Users\user\AppData\Roaming\838634\772117.exe');
TerminateProcessByName('C:\Program Files\8HJG2J4DQO\7JG860ATM.exe');
TerminateProcessByName('C:\Users\user\AppData\Roaming\452352\835412.exe');
TerminateProcessByName('C:\Program Files\8PL0PZ1C8N\8PL0PZ1C8.exe');
TerminateProcessByName('C:\Program Files\9ZVVAFVQWT\9ZVVAFVQW.exe');
TerminateProcessByName('C:\Program Files\XBISLYDP1H\A0P7TYJQ0.exe');
TerminateProcessByName('C:\Program Files\5OWC6WH42Z\PGQDEZKPV.exe');
TerminateProcessByName('C:\Program Files\PQCARGEVAA\PQCARGEVA.exe');
TerminateProcessByName('C:\Program Files\SFM9X9RBEQ\SFM9X9RBE.exe');
TerminateProcessByName('C:\Program Files\TI1PSCGILW\TI1PSCGIL.exe');
TerminateProcessByName('C:\Program Files\TU4Y29BKIZ\TU4Y29BKI.exe');
TerminateProcessByName('C:\Program Files\XIZXZ1P0KC\XIZXZ1P0K.exe');
QuarantineFileF('c:\program files (x86)\firefox', '*.exe', true, '', 0 , 0);
QuarantineFile('C:\Users\user\AppData\Roaming\463437\164150.exe', '');
QuarantineFile('C:\Users\user\AppData\Roaming\440947\167031.exe', '');
QuarantineFile('C:\Users\user\AppData\Roaming\178047\237277.exe', '');
QuarantineFile('C:\Program Files\2DJDCC0AAA\2DJDCC0AA.exe', '');
QuarantineFile('C:\Program Files\35DQ6YZ9XO\35DQ6YZ9X.exe', '');
QuarantineFile('C:\Program Files\3JKMDE0CF1\3JKMDE0CF.exe', '');
QuarantineFile('C:\Program Files\491UQ9ZVOJ\491UQ9ZVO.exe', '');
QuarantineFile('C:\Program Files\5APFXRMF3X\5APFXRMF3.exe', '');
QuarantineFile('C:\Program Files\5TRRDBB0VD\5TRRDBB0V.exe', '');
QuarantineFile('C:\Users\user\AppData\Roaming\727292\617770.exe', '');
QuarantineFile('C:\Users\user\AppData\Roaming\234726\637527.exe', '');
QuarantineFile('C:\Users\user\AppData\Roaming\740388\670994.exe', '');
QuarantineFile('C:\Users\user\AppData\Roaming\518397\686708.exe', '');
QuarantineFile('C:\Program Files\ICFQ8EJIQP\6Q0UWMP86.exe', '');
QuarantineFile('C:\Users\user\AppData\Roaming\272391\747174.exe', '');
QuarantineFile('C:\Users\user\AppData\Roaming\838634\772117.exe', '');
QuarantineFile('C:\Program Files\8HJG2J4DQO\7JG860ATM.exe', '');
QuarantineFile('C:\Users\user\AppData\Roaming\452352\835412.exe', '');
QuarantineFile('C:\Program Files\8PL0PZ1C8N\8PL0PZ1C8.exe', '');
QuarantineFile('C:\Program Files\9ZVVAFVQWT\9ZVVAFVQW.exe', '');
QuarantineFile('C:\Program Files\XBISLYDP1H\A0P7TYJQ0.exe', '');
QuarantineFile('C:\Program Files\5OWC6WH42Z\PGQDEZKPV.exe', '');
QuarantineFile('C:\Program Files\PQCARGEVAA\PQCARGEVA.exe', '');
QuarantineFile('C:\Program Files\SFM9X9RBEQ\SFM9X9RBE.exe', '');
QuarantineFile('C:\Program Files\TI1PSCGILW\TI1PSCGIL.exe', '');
QuarantineFile('C:\Program Files\TU4Y29BKIZ\TU4Y29BKI.exe', '');
QuarantineFile('C:\Program Files\XIZXZ1P0KC\XIZXZ1P0K.exe', '');
QuarantineFile('C:\Users\user\AppData\Local\background_fault\bf.dll', '');
QuarantineFile('C:\Users\user\AppData\Local\background_fault\libcef.dll', '');
QuarantineFile('C:\Users\user\AppData\Local\background_fault\chrome_elf.dll', '');
QuarantineFile('C:\Users\user\AppData\Local\background_fault\libglesv2.dll', '');
QuarantineFile('C:\Users\user\AppData\Local\background_fault\libegl.dll', '');
QuarantineFile('c:\programdata\bit\bit.dll', '');
QuarantineFile('c:\programdata\microsoft\apps\common\helper.dll', '');
QuarantineFile('c:\users\user\appdata\roaming\winsapsvc\winsap.dll', '');
QuarantineFile('C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe', '');
QuarantineFile('C:\Users\user\AppData\Local\ANSARE\Snare.dll', '');
QuarantineFile('C:\Users\user\AppData\Local\WANARE\Snare.dll', '');
QuarantineFile('C:\Program Files (x86)\Wumertnujoent Provider\local64spl.dll', '');
QuarantineFile('C:\Users\user\AppData\Roaming\DCleaner\dcc.exe', '');
QuarantineFile('C:\Program Files (x86)\Soficult\reuverry.exe', '');
QuarantineFile('C:\Users\user\AppData\Roaming\Afcdc\Aaace.exe', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Services\Acaec\Afacb.exe', '');
QuarantineFile('C:\Program Files (x86)\Hersitionthokock\aredock.exe', '');
QuarantineFile('C:\windows\psgo\psgo.ps1', '');
QuarantineFile('C:\Program Files (x86)\Hersitionthokock\bibecult.exe', '');
DeleteFile('C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk', '32');
DeleteFile('C:\Users\user\AppData\Roaming\463437\164150.exe', '32');
DeleteFile('C:\Users\user\AppData\Roaming\440947\167031.exe', '32');
DeleteFile('C:\Users\user\AppData\Roaming\178047\237277.exe', '32');
DeleteFile('C:\Program Files\2DJDCC0AAA\2DJDCC0AA.exe', '32');
DeleteFile('C:\Program Files\35DQ6YZ9XO\35DQ6YZ9X.exe', '32');
DeleteFile('C:\Program Files\3JKMDE0CF1\3JKMDE0CF.exe', '32');
DeleteFile('C:\Program Files\491UQ9ZVOJ\491UQ9ZVO.exe', '32');
DeleteFile('C:\Program Files\5APFXRMF3X\5APFXRMF3.exe', '32');
DeleteFile('C:\Program Files\5TRRDBB0VD\5TRRDBB0V.exe', '32');
DeleteFile('C:\Users\user\AppData\Roaming\727292\617770.exe', '32');
DeleteFile('C:\Users\user\AppData\Roaming\234726\637527.exe', '32');
DeleteFile('C:\Users\user\AppData\Roaming\740388\670994.exe', '32');
DeleteFile('C:\Users\user\AppData\Roaming\518397\686708.exe', '32');
DeleteFile('C:\Program Files\ICFQ8EJIQP\6Q0UWMP86.exe', '32');
DeleteFile('C:\Users\user\AppData\Roaming\272391\747174.exe', '32');
DeleteFile('C:\Users\user\AppData\Roaming\838634\772117.exe', '32');
DeleteFile('C:\Program Files\8HJG2J4DQO\7JG860ATM.exe', '32');
DeleteFile('C:\Users\user\AppData\Roaming\452352\835412.exe', '32');
DeleteFile('C:\Program Files\8PL0PZ1C8N\8PL0PZ1C8.exe', '32');
DeleteFile('C:\Program Files\9ZVVAFVQWT\9ZVVAFVQW.exe', '32');
DeleteFile('C:\Program Files\XBISLYDP1H\A0P7TYJQ0.exe', '32');
DeleteFile('C:\Program Files\5OWC6WH42Z\PGQDEZKPV.exe', '32');
DeleteFile('C:\Program Files\PQCARGEVAA\PQCARGEVA.exe', '32');
DeleteFile('C:\Program Files\SFM9X9RBEQ\SFM9X9RBE.exe', '32');
DeleteFile('C:\Program Files\TI1PSCGILW\TI1PSCGIL.exe', '32');
DeleteFile('C:\Program Files\TU4Y29BKIZ\TU4Y29BKI.exe', '32');
DeleteFile('C:\Program Files\XIZXZ1P0KC\XIZXZ1P0K.exe', '32');
DeleteFile('C:\Users\user\AppData\Local\background_fault\bf.dll', '32');
DeleteFile('C:\Users\user\AppData\Local\background_fault\libcef.dll', '32');
DeleteFile('C:\Users\user\AppData\Local\background_fault\chrome_elf.dll', '32');
DeleteFile('C:\Users\user\AppData\Local\background_fault\libglesv2.dll', '32');
DeleteFile('C:\Users\user\AppData\Local\background_fault\libegl.dll', '32');
DeleteFile('c:\programdata\bit\bit.dll', '32');
DeleteFile('c:\programdata\microsoft\apps\common\helper.dll', '32');
DeleteFile('c:\users\user\appdata\roaming\winsapsvc\winsap.dll', '32');
DeleteFile('C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe', '32');
DeleteFile('C:\Users\user\AppData\Local\ANSARE\Snare.dll', '32');
DeleteFile('C:\Users\user\AppData\Local\WANARE\Snare.dll', '32');
DeleteFile('C:\Program Files (x86)\Wumertnujoent Provider\local64spl.dll', '32');
DeleteFile('C:\Users\user\AppData\Roaming\DCleaner\dcc.exe', '32');
DeleteFile('C:\Program Files (x86)\Soficult\reuverry.exe', '32');
DeleteFile('C:\Users\user\AppData\Roaming\Afcdc\Aaace.exe', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Services\Acaec\Afacb.exe', '32');
DeleteFile('C:\Program Files (x86)\Hersitionthokock\aredock.exe', '32');
DeleteFile('C:\windows\psgo\psgo.ps1', '32');
DeleteFile('C:\Program Files (x86)\Hersitionthokock\bibecult.exe', '32');
DeleteService('FirefoxU');
DeleteFileMask('c:\users\user\appdata\local\background_fault', '*', true);
DeleteFileMask('c:\programdata\bit', '*', true);
DeleteFileMask('c:\program files (x86)\firefox', '*', true);
DeleteFileMask('c:\users\user\appdata\local\ansare', '*', true);
DeleteFileMask('c:\users\user\appdata\local\wanare', '*', true);
DeleteFileMask('c:\program files (x86)\wumertnujoent provider', '*', true);
DeleteFileMask('c:\users\user\appdata\roaming\dcleaner', '*', true);
DeleteFileMask('c:\program files (x86)\soficult', '*', true);
DeleteFileMask('c:\users\user\appdata\roaming\afcdc', '*', true);
DeleteFileMask('c:\program files (x86)\common files\services', '*', true);
DeleteFileMask('"c:\program files (x86)\mio', '*', true);
DeleteFileMask('c:\program files (x86)\hersitionthokock', '*', true);
DeleteFileMask('c:\windows\psgo', '*', true);
DeleteDirectory('c:\users\user\appdata\local\background_fault');
DeleteDirectory('c:\programdata\bit');
DeleteDirectory('c:\program files (x86)\firefox');
DeleteDirectory('c:\users\user\appdata\local\ansare');
DeleteDirectory('c:\users\user\appdata\local\wanare');
DeleteDirectory('c:\program files (x86)\wumertnujoent provider');
DeleteDirectory('c:\users\user\appdata\roaming\dcleaner');
DeleteDirectory('c:\program files (x86)\soficult');
DeleteDirectory('c:\users\user\appdata\roaming\afcdc');
DeleteDirectory('c:\program files (x86)\common files\services');
DeleteDirectory('"c:\program files (x86)\mio');
DeleteDirectory('c:\program files (x86)\hersitionthokock');
DeleteDirectory('c:\windows\psgo');
ExecuteFile('schtasks.exe', '/delete /TN "DirAnalizator" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Fderward Provider" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Cecdb" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Bdcae" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Defrag\Cceea" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Diagnosis\Edaed" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Maintenance\Cecdb" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Media Center\Fbadd" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\MUI\Aabab" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Shell\Bdcae" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Shell\Cecdb" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\SideShow\Fbadd" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Windows Error Reporting\Afdda" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Milimili" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Nohswocerther Provider" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ScanMe" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Sherweck" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Windows-PG" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Wumertnujoent Provider" /F', 0, 15000, true);
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'DQPF4OZ665ET9DD');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '953PWOF7TMOPNXF');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '687379');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '504463');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'HZVJN3467FC6PW0');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '192396');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'SGT82XHK84GO6LM');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'S0WUXL93U5B9NW0');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '299913');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'N2AQA7AMXKAQVA6');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'WQUOXO41VUOFQ0Z');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '492790');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '7NXKS8Y0BH2TFQ0');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '414430');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '4G3LXRY0684IT2L');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'FY4UTT7A7C4NXT8');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '162559');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'H0XKWF24VUOFZMZ');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'OAK8P6FOLEEN7I8');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '616173');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '1AQ63B6D9U1SG9R');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '260942');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '0KZQVFTLL658C4Y');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'QNCUSKV0S1ZJQEF');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '82475');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '8MCKYJNDUQCMADM');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'KDGR9Z0UQP3S530');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'background_fault');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\ANSARE\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\BIT\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\WANARE\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\WindowsAppSvc\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\WinSAPSvc\Parameters', 'ServiceDll');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.