Код:
begin
QuarantineFile('C:\Applications\Service.exe', '');
QuarantineFile('C:\Browse\Browse.exe', '');
QuarantineFile('C:\PROGRA~2\FASTDA~1\FASTDA~1.EXE', '');
QuarantineFile('C:\Program Files\0E34D21ZZS\XV4KT49LR.exe', '');
QuarantineFile('C:\Program Files\21L1LZVBGT\21L1LZVBG.exe', '');
QuarantineFile('C:\ProgramData\MicrosoftCorporation\Windows\System32\Isass.exe', '');
QuarantineFile('C:\ProgramData\Quoteex\Goldenwarm.dll', '');
QuarantineFile('C:\ProgramData\Quoteex\Joyflex.reg', '');
QuarantineFile('C:\ProgramData\Quoteex\LightNimstring.reg', '');
QuarantineFile('C:\ProgramData\Quoteex\OpenJoyplus.dll', '');
QuarantineFile('C:\ProgramData\WindowsAppCertification\checker.vbs', '');
QuarantineFile('C:\ProgramData\winhost.exe', '');
QuarantineFile('C:\Users\Slava\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TYDMMA2D\JavaSetup8u161.exe', '');
QuarantineFile('C:\Users\Slava\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe', '');
QuarantineFile('C:\Users\Slava\appdata\roaming\gplyra\gplyra.exe', '');
QuarantineFile('C:\Users\Slava\AppData\Roaming\qbwqvxhcxwu\aee3p3mwuhb.exe', '');
QuarantineFile('C:\Users\Slava\AppData\Roaming\qvavicaz4ie\ro5pwihruwz.exe', '');
QuarantineFile('C:\Users\Slava\AppData\Roaming\wget\wget.exe', '');
QuarantineFile('C:\Users\Slava\AppData\Roaming\wget\wget_1_19_4.exe', '');
QuarantineFile('C:\Windows\rss\csrss.exe', '');
QuarantineFile('C:\Windows\windefender.exe', '');
QuarantineFile('J:\autorun.exe', '');
QuarantineFile('J:\autorun.inf', '');
QuarantineFileF('c:\applications', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', false, '', 0 , 0);
QuarantineFileF('c:\programdata\windowsappcertification', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', false, '', 0 , 0);
QuarantineFileF('c:\users\slava\appdata\roaming\wget', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', false, '', 0 , 0);
QuarantineFileF('c:\windows\rss', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', false, '', 0 , 0);
DeleteFile('C:\Applications\Service.exe', '32');
DeleteFile('C:\Browse\Browse.exe', '32');
DeleteFile('C:\PROGRA~2\FASTDA~1\FASTDA~1.EXE', '32');
DeleteFile('C:\Program Files\0E34D21ZZS\XV4KT49LR.exe', '32');
DeleteFile('C:\Program Files\21L1LZVBGT\21L1LZVBG.exe', '32');
DeleteFile('C:\ProgramData\MicrosoftCorporation\Windows\System32\Isass.exe', '32');
DeleteFile('C:\ProgramData\Quoteex\Goldenwarm.dll', '32');
DeleteFile('C:\ProgramData\Quoteex\Joyflex.reg', '32');
DeleteFile('C:\ProgramData\Quoteex\LightNimstring.reg', '32');
DeleteFile('C:\ProgramData\Quoteex\OpenJoyplus.dll', '32');
DeleteFile('C:\ProgramData\WindowsAppCertification\checker.vbs', '32');
DeleteFile('C:\ProgramData\winhost.exe', '32');
DeleteFile('C:\Users\Slava\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TYDMMA2D\JavaSetup8u161.exe', '32');
DeleteFile('C:\Users\Slava\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe', '32');
DeleteFile('C:\Users\Slava\appdata\roaming\gplyra\gplyra.exe', '32');
DeleteFile('C:\Users\Slava\AppData\Roaming\qbwqvxhcxwu\aee3p3mwuhb.exe', '32');
DeleteFile('C:\Users\Slava\AppData\Roaming\qvavicaz4ie\ro5pwihruwz.exe', '32');
DeleteFile('C:\Users\Slava\AppData\Roaming\wget\wget.exe', '32');
DeleteFile('C:\Users\Slava\AppData\Roaming\wget\wget_1_19_4.exe', '32');
DeleteFile('C:\Windows\rss\csrss.exe', '32');
DeleteFile('C:\Windows\windefender.exe', '32');
DeleteFile('http:\kharesti.ru\f.exe', '32');
ExecuteFile('schtasks.exe', '/delete /TN "{C0068F3D-2398-482E-B39F-5C394BFD6DDA}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Browse" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "FastDataX Task" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "psv_Duofind" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "psv_Zim-Flex" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ShadowsocksS" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "wget" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "wgets" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Windows_Antimalware_Host" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Windows_Antimalware_Host_Systm" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "WinHostStartForMachine" /F', 0, 15000, true);
DeleteService('WinDefender');
DeleteFileMask('c:\applications', '*', false);
DeleteFileMask('c:\browse', '*', true);
DeleteFileMask('c:\progra~2\fastda~1', '*', true);
DeleteFileMask('c:\program files\0e34d21zzs', '*', true);
DeleteFileMask('c:\program files\21l1lzvbgt', '*', true);
DeleteFileMask('c:\programdata\microsoftcorporation', '*', true);
DeleteFileMask('c:\programdata\quoteex', '*', true);
DeleteFileMask('c:\programdata\windowsappcertification', '*', false);
DeleteFileMask('c:\users\slava\appdata\roaming\epicnet inc', '*', true);
DeleteFileMask('c:\users\slava\appdata\roaming\gplyra', '*', true);
DeleteFileMask('c:\users\slava\appdata\roaming\qvavicaz4ie', '*', true);
DeleteFileMask('c:\users\slava\appdata\roaming\wget', '*', false);
DeleteFileMask('c:\windows\rss', '*', true);
DeleteDirectory('c:\applications');
DeleteDirectory('c:\browse');
DeleteDirectory('c:\progra~2\fastda~1');
DeleteDirectory('c:\program files\0e34d21zzs');
DeleteDirectory('c:\program files\21l1lzvbgt');
DeleteDirectory('c:\programdata\microsoftcorporation');
DeleteDirectory('c:\programdata\quoteex');
DeleteDirectory('c:\programdata\windowsappcertification');
DeleteDirectory('c:\users\slava\appdata\roaming\epicnet inc');
DeleteDirectory('c:\users\slava\appdata\roaming\gplyra');
DeleteDirectory('c:\users\slava\appdata\roaming\qvavicaz4ie');
DeleteDirectory('c:\users\slava\appdata\roaming\wget');
DeleteDirectory('c:\windows\rss');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '8969905');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '9650289');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'CloudNet');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'CWUONNRP514Z5MU');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'MHPVE1BG2A3IQVF');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'PolishedLake');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Windows_Antimalware_Host_Syst');
ExecuteRepair(21);
ExecuteFile('ipconfig.exe', '/flushdns', 0, 15000, true);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.