Код:
begin
TerminateProcessByName('c:\users\Магазин\appdata\local\amd\amd.exe');
StopService('AMD');
StopService('clean');
QuarantineFileF('c:\program files (x86)\firefox', '*.exe', true, '', 0 , 0);
QuarantineFile('C:\Users\Магазин\AppData\Local\background_fault\bf.dll', '');
QuarantineFile('c:\programdata\microsoft\phone tools\corecon\12.0\addons\sdkfilesver.dll', '');
QuarantineFile('c:\users\магазин\appdata\local\3dm\kitty.dll', '');
QuarantineFile('c:\users\магазин\appdata\roaming\winsapsvc\winsap.dll', '');
QuarantineFile('c:\programdata\bit\bit.dll', '');
QuarantineFile('c:\programdata\microsoft\identitycrl\production\ppcrlconfig617.dll', '');
QuarantineFile('c:\programdata\common\apple\apps\azuretools.dll', '');
QuarantineFile('c:\program files (x86)\iis\microsoft web deploy v3\te\msdeploy.resources.dll', '');
QuarantineFile('c:\users\магазин\appdata\local\kitty\kitty.dll', '');
QuarantineFile('c:\programdata\package cache\{2a002f88-fd5d-379b-a350-a25d84af128b}v14.0.25420\packages\visualc_d14\vc_ide.base\vc_ide_base.dll', '');
QuarantineFile('C:\Users\Магазин\AppData\Local\AMD\amd.exe', '');
QuarantineFile('C:\Users\Магазин\AppData\Local\clean\Kyubey.exe', '');
QuarantineFile('C:\Program Files (x86)\Ultimate-Discounter Browser\udservice.exe', '');
QuarantineFile('C:\Program Files (x86)\amuleCexx\ed2k.exe', '');
QuarantineFile('C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe', '');
QuarantineFile('C:\Users\Магазин\AppData\Roaming\gastproffite\ml.py', '');
QuarantineFile('C:\Users\Магазин\AppData\Local\CWASRE\Snare.dll', '');
QuarantineFile('C:\Users\Магазин\AppData\Local\NPASRE\Snare.dll', '');
QuarantineFile('C:\Windows\svchost.exe', '');
QuarantineFile('C:\Users\Магазин\AppData\Local\SNARE\Snare.dll', '');
QuarantineFile('C:\Users\Магазин\AppData\Local\SNARER\Snarer.dll', '');
QuarantineFile('C:\Users\Магазин\AppData\Local\VNASRE\Snare.dll', '');
QuarantineFile('C:\Users\Магазин\AppData\Local\WANARE\Snare.dll', '');
QuarantineFile('C:\Users\Магазин\AppData\Roaming\WINSNARE\WinSnare.dll', '');
QuarantineFile('C:\Users\Магазин\AppData\Local\Mail.Ru\Sputnik\IESearchPlugin.dll', '');
QuarantineFile('C:\ProgramData\1132R39T32B3106\1132R39T32B3106.dll', '');
QuarantineFile('C:\Program Files (x86)\Antanna\Application\chrome.exe', '');
QuarantineFile('C:\Users\Магазин\AppData\Roaming\gastproffite\app.py', '');
QuarantineFile('C:\ProgramData\vCore\VCore.exe', '');
QuarantineFile('C:\windows\psgo\psgo.ps1', '');
DeleteFile('C:\Windows\Tasks\1132R39T32B3106.job', '64');
DeleteFile('C:\Users\Магазин\AppData\Local\background_fault\bf.dll', '32');
DeleteFile('C:\Program Files (x86)\Dayglad\Application\chrome_child.dll', '32');
DeleteFile('C:\Program Files (x86)\Dayglad\Application\chrome.dll', '32');
DeleteFile('c:\programdata\microsoft\phone tools\corecon\12.0\addons\sdkfilesver.dll', '32');
DeleteFile('c:\users\магазин\appdata\local\3dm\kitty.dll', '32');
DeleteFile('c:\users\магазин\appdata\roaming\winsapsvc\winsap.dll', '32');
DeleteFile('c:\programdata\bit\bit.dll', '32');
DeleteFile('c:\programdata\microsoft\identitycrl\production\ppcrlconfig617.dll', '32');
DeleteFile('c:\programdata\common\apple\apps\azuretools.dll', '32');
DeleteFile('c:\program files (x86)\iis\microsoft web deploy v3\te\msdeploy.resources.dll', '32');
DeleteFile('c:\users\магазин\appdata\local\kitty\kitty.dll', '32');
DeleteFile('c:\programdata\package cache\{2a002f88-fd5d-379b-a350-a25d84af128b}v14.0.25420\packages\visualc_d14\vc_ide.base\vc_ide_base.dll', '32');
DeleteFile('C:\Users\Магазин\AppData\Local\AMD\amd.exe', '32');
DeleteFile('C:\Users\Магазин\AppData\Local\clean\Kyubey.exe', '32');
DeleteFile('C:\Program Files (x86)\Ultimate-Discounter Browser\udservice.exe', '32');
DeleteFile('C:\Program Files (x86)\amuleCexx\ed2k.exe', '32');
DeleteFile('C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe', '32');
DeleteFile('C:\Users\Магазин\AppData\Roaming\gastproffite\ml.py', '32');
DeleteFile('C:\Users\Магазин\AppData\Local\CWASRE\Snare.dll', '32');
DeleteFile('C:\Users\Магазин\AppData\Local\NPASRE\Snare.dll', '32');
DeleteFile('C:\Windows\svchost.exe', '32');
DeleteFile('C:\Users\Магазин\AppData\Local\SNARE\Snare.dll', '32');
DeleteFile('C:\Users\Магазин\AppData\Local\SNARER\Snarer.dll', '32');
DeleteFile('C:\Users\Магазин\AppData\Local\VNASRE\Snare.dll', '32');
DeleteFile('C:\Users\Магазин\AppData\Local\WANARE\Snare.dll', '32');
DeleteFile('C:\Users\Магазин\AppData\Roaming\WINSNARE\WinSnare.dll', '32');
DeleteFile('C:\Users\Магазин\AppData\Local\Mail.Ru\Sputnik\IESearchPlugin.dll', '32');
DeleteFile('C:\ProgramData\1132R39T32B3106\1132R39T32B3106.dll', '32');
DeleteFile('C:\Program Files (x86)\Antanna\Application\chrome.exe', '32');
DeleteFile('C:\Users\Магазин\AppData\Roaming\gastproffite\app.py', '32');
DeleteFile('C:\ProgramData\vCore\VCore.exe', '32');
DeleteFile('C:\windows\psgo\psgo.ps1', '32');
DeleteService('AMD');
DeleteService('clean');
DeleteService('Coupons Browser Update Service');
DeleteService('ed2kidle');
DeleteService('FirefoxU');
DeleteFileMask('c:\users\магазин\appdata\local\background_fault', '*', true);
DeleteFileMask('c:\program files (x86)\dayglad', '*', true);
DeleteFileMask('c:\programdata\microsoft\phone tools\corecon', '*', false);
DeleteFileMask('c:\users\магазин\appdata\local\3dm', '*', true);
DeleteFileMask('c:\programdata\bit', '*', true);
DeleteFileMask('c:\users\магазин\appdata\local\kitty', '*', true);
DeleteFileMask('c:\programdata\package cache\{2a002f88-fd5d-379b-a350-a25d84af128b}v14.0.25420', '*', true);
DeleteFileMask('c:\users\магазин\appdata\local\clean', '*', true);
DeleteFileMask('c:\program files (x86)\ultimate-discounter browser', '*', true);
DeleteFileMask('c:\program files (x86)\amulecexx', '*', true);
DeleteFileMask('c:\program files (x86)\firefox', '*', true);
DeleteFileMask('c:\users\магазин\appdata\roaming\gastproffite', '*', true);
DeleteFileMask('c:\users\магазин\appdata\local\cwasre', '*', true);
DeleteFileMask('c:\users\магазин\appdata\local\npasre', '*', true);
DeleteFileMask('c:\users\магазин\appdata\local\snare', '*', true);
DeleteFileMask('c:\users\магазин\appdata\local\snarer', '*', true);
DeleteFileMask('c:\users\магазин\appdata\local\vnasre', '*', true);
DeleteFileMask('c:\users\магазин\appdata\local\wanare', '*', true);
DeleteFileMask('c:\users\магазин\appdata\roaming\winsnare', '*', true);
DeleteFileMask('c:\users\магазин\appdata\local\mail.ru', '*', true);
DeleteFileMask('c:\programdata\1132r39t32b3106', '*', true);
DeleteFileMask('c:\program files (x86)\antanna', '*', true);
DeleteFileMask('c:\program files (x86)\iobit', '*', true);
DeleteFileMask('c:\programdata\vcore', '*', true);
DeleteFileMask('"c:\program files (x86)\mio', '*', true);
DeleteFileMask('c:\windows\psgo', '*', true);
DeleteDirectory('c:\users\магазин\appdata\local\background_fault');
DeleteDirectory('c:\program files (x86)\dayglad');
DeleteDirectory('c:\programdata\microsoft\phone tools\corecon');
DeleteDirectory('c:\users\магазин\appdata\local\3dm');
DeleteDirectory('c:\programdata\bit');
DeleteDirectory('c:\users\магазин\appdata\local\kitty');
DeleteDirectory('c:\programdata\package cache\{2a002f88-fd5d-379b-a350-a25d84af128b}v14.0.25420');
DeleteDirectory('c:\users\магазин\appdata\local\clean');
DeleteDirectory('c:\program files (x86)\ultimate-discounter browser');
DeleteDirectory('c:\program files (x86)\amulecexx');
DeleteDirectory('c:\program files (x86)\firefox');
DeleteDirectory('c:\users\магазин\appdata\roaming\gastproffite');
DeleteDirectory('c:\users\магазин\appdata\local\cwasre');
DeleteDirectory('c:\users\магазин\appdata\local\npasre');
DeleteDirectory('c:\users\магазин\appdata\local\snare');
DeleteDirectory('c:\users\магазин\appdata\local\snarer');
DeleteDirectory('c:\users\магазин\appdata\local\vnasre');
DeleteDirectory('c:\users\магазин\appdata\local\wanare');
DeleteDirectory('c:\users\магазин\appdata\roaming\winsnare');
DeleteDirectory('c:\users\магазин\appdata\local\mail.ru');
DeleteDirectory('c:\programdata\1132r39t32b3106');
DeleteDirectory('c:\program files (x86)\antanna');
DeleteDirectory('c:\program files (x86)\iobit');
DeleteDirectory('c:\programdata\vcore');
DeleteDirectory('"c:\program files (x86)\mio');
DeleteDirectory('c:\windows\psgo');
DelBHO('{8E8F97CD-60B5-456F-A201-73065652D099}');
ExecuteFile('schtasks.exe', '/delete /TN "1132R39T32B3106-dll" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ACC" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "browser-netnetrnor" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Driver Booster SkipUAC (Магазин)" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "FUB" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "gastproffite" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "gastproffite2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "hda\ravcpl64" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Media Center\VCore" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Milimili" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Windows-PG" /F', 0, 15000, true);
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'gastproffite');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'background_fault');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\ MicrosoftCRLSrv\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\3DM\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\AppleAzureSrv\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\BIT\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\CWASRE\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\IISvr\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\Kitty\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\MVCSrv\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\WinSAPSvc\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\WPDTSrv\Parameters', 'ServiceDll');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteRepair(9);
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
Компьютер перезагрузится.