Код:
begin
QuarantineFile('C:\Users\Олег Уваров\AppData\Local\background_fault\bf.dll', '');
QuarantineFile('c:\programdata\bit\bit.dll', '');
QuarantineFile('c:\users\олег уваров\appdata\roaming\winsapsvc\winsap.dll', '');
QuarantineFile('C:\Users\Олег Уваров\AppData\Roaming\539113\812005.exe', '');
QuarantineFile('C:\Users\Олег Уваров\AppData\Roaming\521636\751277.exe', '');
QuarantineFile('C:\Users\Олег Уваров\AppData\Roaming\247578\538390.exe', '');
QuarantineFile('C:\Users\Олег Уваров\AppData\Roaming\380574\472767.exe', '');
QuarantineFile('C:\Users\Олег Уваров\AppData\Roaming\616790\150866.exe', '');
QuarantineFile('C:\Users\Олег Уваров\AppData\Roaming\207308\59775.exe', '');
QuarantineFile('C:\Users\Олег Уваров\AppData\Roaming\515847\363897.exe', '');
QuarantineFile('C:\Users\Олег Уваров\AppData\Roaming\885219\363053.exe', '');
QuarantineFile('C:\Users\Олег Уваров\AppData\Roaming\595237\92013.exe', '');
QuarantineFile('C:\Users\Олег Уваров\AppData\Roaming\gplyra\gplyra\start.cmd', '');
QuarantineFile('C:\WINDOWS\TEMP\gB1BD.tmp.exe', '');
QuarantineFile('C:\Program Files (x86)\Lerfopervather Host\local64spl.dll', '');
QuarantineFile('C:\Program Files (x86)\IObit\Driver', '');
QuarantineFile('C:\Program Files (x86)\Jiricultclerroly\nahit.exe', '');
QuarantineFile('C:\Windows\Manager.exe', '');
DeleteFile('C:\Users\Олег Уваров\AppData\Local\background_fault\bf.dll', '32');
DeleteFile('c:\programdata\bit\bit.dll', '32');
DeleteFile('c:\users\олег уваров\appdata\roaming\winsapsvc\winsap.dll', '32');
DeleteFile('C:\Users\Олег Уваров\AppData\Roaming\539113\812005.exe', '32');
DeleteFile('C:\Users\Олег Уваров\AppData\Roaming\521636\751277.exe', '32');
DeleteFile('C:\Users\Олег Уваров\AppData\Roaming\247578\538390.exe', '32');
DeleteFile('C:\Users\Олег Уваров\AppData\Roaming\380574\472767.exe', '32');
DeleteFile('C:\Users\Олег Уваров\AppData\Roaming\616790\150866.exe', '32');
DeleteFile('C:\Users\Олег Уваров\AppData\Roaming\207308\59775.exe', '32');
DeleteFile('C:\Users\Олег Уваров\AppData\Roaming\515847\363897.exe', '32');
DeleteFile('C:\Users\Олег Уваров\AppData\Roaming\885219\363053.exe', '32');
DeleteFile('C:\Users\Олег Уваров\AppData\Roaming\595237\92013.exe', '32');
DeleteFile('C:\Users\Олег Уваров\AppData\Roaming\gplyra\gplyra\start.cmd', '32');
DeleteFile('C:\WINDOWS\TEMP\gB1BD.tmp.exe', '32');
DeleteFile('C:\Program Files (x86)\Lerfopervather Host\local64spl.dll', '32');
DeleteFile('C:\Program Files (x86)\IObit\Driver', '32');
DeleteFile('C:\Program Files (x86)\Jiricultclerroly\nahit.exe', '32');
DeleteFile('C:\Windows\Manager.exe', '32');
DeleteFileMask('c:\users\олег уваров\appdata\local\background_fault', '*', true);
DeleteFileMask('c:\programdata\bit', '*', true);
DeleteFileMask('c:\users\олег уваров\appdata\roaming\gplyra', '*', true);
DeleteFileMask('c:\program files (x86)\jiricultclerroly', '*', true);
DeleteFileMask('"c:\program files (x86)\mio', '*', true);
DeleteDirectory('c:\users\олег уваров\appdata\local\background_fault');
DeleteDirectory('c:\programdata\bit');
DeleteDirectory('c:\users\олег уваров\appdata\roaming\gplyra');
DeleteDirectory('c:\program files (x86)\jiricultclerroly');
DeleteDirectory('"c:\program files (x86)\mio');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Ckuqdom" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Driver Booster SkipUAC (Олег Уваров)" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Lerfopervather Host" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Multimedia\Manager" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Milimili" /F', 0, 15000, true);
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '903954');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '884698');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '208459');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '840770');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '460199');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '672494');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '928927');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '644441');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '979520');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'background_fault');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\BIT\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\WinSAPSvc\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'gplyra');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'DESKTOP-U9AG4Q5');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.