Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
TerminateProcessByName('c:\users\ara\appdata\local\temp\csrss\ww24.exe');
TerminateProcessByName('c:\users\ara\appdata\roaming\b9d10b433b6e\b9d10b433b6e.exe');
TerminateProcessByName('c:\windows\rss\csrss.exe');
TerminateProcessByName('c:\windows\windefender.exe');
StopService('WinDefender');
StopService('Winmon');
StopService('WinmonFS');
StopService('WinmonProcessMonitor');
QuarantineFile('C:\Program Files (x86)\afc\452366990.exe', '');
QuarantineFile('C:\Users\Ara\AppData\Local\Temp\csrss\scheduled.exe', '');
QuarantineFile('C:\Users\Ara\appdata\local\temp\csrss\wup\xarch\wup.exe', '');
QuarantineFile('c:\users\ara\appdata\local\temp\csrss\ww24.exe', '');
QuarantineFile('c:\users\ara\appdata\roaming\b9d10b433b6e\b9d10b433b6e.exe', '');
QuarantineFile('c:\windows\rss\csrss.exe', '');
QuarantineFile('C:\Windows\System32\drivers\Winmon.sys', '');
QuarantineFile('C:\Windows\System32\drivers\WinmonFS.sys', '');
QuarantineFile('C:\Windows\System32\drivers\WinmonProcessMonitor.sys', '');
QuarantineFile('c:\windows\windefender.exe', '');
QuarantineFileF('c:\users\ara\appdata\roaming\b9d10b433b6e', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', false, '', 0 , 0);
QuarantineFileF('c:\windows\rss', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', false, '', 0 , 0);
DeleteFile('C:\Program Files (x86)\afc\452366990.exe', '64');
DeleteFile('C:\Users\Ara\appdata\local\temp\csrss\scheduled.exe', '');
DeleteFile('C:\Users\Ara\AppData\Local\Temp\csrss\scheduled.exe', '64');
DeleteFile('C:\Users\Ara\appdata\local\temp\csrss\wup\xarch\wup.exe', '');
DeleteFile('c:\users\ara\appdata\local\temp\csrss\ww24.exe', '');
DeleteFile('c:\users\ara\appdata\roaming\b9d10b433b6e\b9d10b433b6e.exe', '');
DeleteFile('C:\Users\Ara\AppData\Roaming\b9d10b433b6e\b9d10b433b6e.exe', '32');
DeleteFile('C:\Users\Ara\AppData\Roaming\b9d10b433b6e\b9d10b433b6e.exe', '64');
DeleteFile('c:\windows\rss\csrss.exe', '');
DeleteFile('C:\Windows\rss\csrss.exe', '32');
DeleteFile('C:\Windows\rss\csrss.exe', '64');
DeleteFile('C:\Windows\System32\drivers\Winmon.sys', '64');
DeleteFile('C:\Windows\System32\drivers\WinmonFS.sys', '64');
DeleteFile('C:\Windows\System32\drivers\WinmonProcessMonitor.sys', '64');
DeleteFile('c:\windows\windefender.exe', '');
DeleteFile('C:\Windows\windefender.exe', '64');
DeleteService('WinDefender');
DeleteService('Winmon');
DeleteService('WinmonFS');
DeleteService('WinmonProcessMonitor');
DeleteFileMask('c:\users\ara\appdata\local\temp\csrss', '*', true);
DeleteFileMask('c:\users\ara\appdata\roaming\b9d10b433b6e', '*', true);
DeleteFileMask('c:\windows\rss', '*', true);
DeleteDirectory('c:\users\ara\appdata\local\temp\csrss');
DeleteDirectory('c:\users\ara\appdata\roaming\b9d10b433b6e');
DeleteDirectory('c:\windows\rss');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'CloudNet', '32');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'CloudNet', '64');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'DampMorning', '32');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'DampMorning', '64');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', '2v1nsqjrvgb', '64');
DeleteSchedulerTask('{3AED78F3-021B-41CE-873D-992538100C5B}');
DeleteSchedulerTask('{82930025-2F49-4CD8-B02A-8B67EE66F6CF}');
DeleteSchedulerTask('{92CE26CB-DC9C-4E2E-8788-E0481241AC73}');
DeleteSchedulerTask('{998D0D6D-50EA-4478-9466-760D07398869}');
DeleteSchedulerTask('{F7AFA1C3-D60D-4568-98E5-E88E90E60A06}');
DeleteSchedulerTask('csrss');
DeleteSchedulerTask('ScheduledUpdate');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 3, 3, true);
RebootWindows(true);
end.
Компьютер перезагрузится.