Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
QuarantineFileF('c:\programdata\microsoft\macromed\flash player\c850f184-e5fe-4872-8750-c603cb9c99ed', '*', true, '', 0 , 0);
QuarantineFile('C:\Windows\winstart.bat', '');
QuarantineFileF('C:\Users\ksheeire\AppData\Local\Microsoft\0F070D42FAEAB4884BB61E9E5B16C20C\', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFile('C:\Users\ksheeire\AppData\Local\Microsoft\0F070D42FAEAB4884BB61E9E5B16C20C\58EADDAA91895238D54062D96DA7A2F7.exe', '');
QuarantineFile('C:\ProgramData\Microsoft\Macromed\Flash Player\C850F184-E5FE-4872-8750-C603CB9C99ED\B8C011B1-8399-43E0-B0BC-C0DF74FBB0AE.exe', '');
DeleteFile('C:\Users\ksheeire\AppData\Local\Microsoft\0F070D42FAEAB4884BB61E9E5B16C20C\58EADDAA91895238D54062D96DA7A2F7.exe');
DeleteFile('C:\Windows\winstart.bat', '32');
DeleteFile('C:\Users\ksheeire\AppData\Local\Microsoft\0F070D42FAEAB4884BB61E9E5B16C20C\58EADDAA91895238D54062D96DA7A2F7.exe', '32');
DeleteFile('C:\ProgramData\Microsoft\Macromed\Flash Player\C850F184-E5FE-4872-8750-C603CB9C99ED\B8C011B1-8399-43E0-B0BC-C0DF74FBB0AE.exe', '32');
ExecuteFile('schtasks.exe', '/delete /TN "{28AACC7A-DF7D-4DCD-9C01-755A24D15214}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "InputPersonalization" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\A7A2F7D69D26045D83259819AA58EADD" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\A7A2F7D69D26045D83259819AA58EADDSB" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\A7A2F7D69D26045D83259819AA58EADD" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\A7A2F7D69D26045D83259819AA58EADDSB" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\AC850F184-E5FE-4872-8750-C603CB9C99ED" /F', 0, 15000, true);
DeleteFileMask('C:\Users\ksheeire\AppData\Local\Microsoft\0F070D42FAEAB4884BB61E9E5B16C20C\', '*', true);
DeleteDirectory('C:\Users\ksheeire\AppData\Local\Microsoft\0F070D42FAEAB4884BB61E9E5B16C20C\');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'A7A2F7D69D26045D83259819AA58EADDSB');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteRepair(13);
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.