Код:
begin
TerminateProcessByName('C:\Windows\Temp\gFAA1.tmp.exe');
QuarantineFileF('c:\users\fedor\appdata\local\filesystemoptions', '*.exe', true, '', 0 , 0);
QuarantineFileF('c:\users\fedor\appdata\local\testmenu', '*.exe', true, '', 0 , 0);
QuarantineFileF('c:\users\fedor\appdata\local\immediatehelp', '*.exe', true, '', 0 , 0);
QuarantineFileF('c:\users\fedor\appdata\local\lastnews', '*.exe', true, '', 0 , 0);
QuarantineFileF('c:\users\fedor\appdata\local\validatelife', '*.exe', true, '', 0 , 0);
QuarantineFile('C:\Windows\Temp\gFAA1.tmp.exe', '');
QuarantineFile('C:\Windows\TEMP\gFA9F.tmp', '');
QuarantineFile('C:\Users\Fedor\AppData\Local\FilterOptions\regCheck.vbs', '');
QuarantineFile('C:\Users\Fedor\AppData\Local\FileSystemOptions\regCheck.vbs', '');
QuarantineFile('C:\Users\Fedor\AppData\Local\TestMenu\regCheck.vbs', '');
QuarantineFile('C:\Users\Fedor\AppData\Local\ImmediateHelp\regCheck.vbs', '');
QuarantineFile('C:\Users\Fedor\AppData\Local\LastNews\regCheck.vbs', '');
QuarantineFile('C:\Users\Fedor\AppData\Local\ValidateLife\regCheck.vbs', '');
QuarantineFile('C:\Users\Fedor\AppData\Local\DateOption\regCheck.vbs', '');
QuarantineFile('C:\Users\Fedor\AppData\Local\rightchose\regCheck.vbs', '');
QuarantineFile('C:\ProgramData\228z719z9P647\228z719z9P647.dll', '');
QuarantineFile('C:\Program Files (x86)\ScreenUp\future_helper.exe', '');
QuarantineFile('C:\Users\Fedor\AppData\Local\FilterStart\FilterStart.exe', '');
DeleteFile('C:\Windows\Temp\gFAA1.tmp.exe', '32');
DeleteFile('C:\Windows\TEMP\gFA9F.tmp', '32');
DeleteFile('C:\Users\Fedor\AppData\Local\FilterOptions\regCheck.vbs', '32');
DeleteFile('C:\Users\Fedor\AppData\Local\FileSystemOptions\regCheck.vbs', '32');
DeleteFile('C:\Users\Fedor\AppData\Local\TestMenu\regCheck.vbs', '32');
DeleteFile('C:\Users\Fedor\AppData\Local\ImmediateHelp\regCheck.vbs', '32');
DeleteFile('C:\Users\Fedor\AppData\Local\LastNews\regCheck.vbs', '32');
DeleteFile('C:\Users\Fedor\AppData\Local\ValidateLife\regCheck.vbs', '32');
DeleteFile('C:\Users\Fedor\AppData\Local\DateOption\regCheck.vbs', '32');
DeleteFile('C:\Users\Fedor\AppData\Local\rightchose\regCheck.vbs', '32');
DeleteFile('C:\ProgramData\228z719z9P647\228z719z9P647.dll', '32');
DeleteFile('C:\Program Files (x86)\ScreenUp\future_helper.exe', '32');
DeleteFile('C:\Users\Fedor\AppData\Local\FilterStart\FilterStart.exe', '32');
DeleteFileMask('c:\users\fedor\appdata\local\filesystemoptions', '*', true);
DeleteFileMask('c:\users\fedor\appdata\local\testmenu', '*', true);
DeleteFileMask('c:\users\fedor\appdata\local\immediatehelp', '*', true);
DeleteFileMask('c:\users\fedor\appdata\local\lastnews', '*', true);
DeleteFileMask('c:\users\fedor\appdata\local\validatelife', '*', true);
DeleteFileMask('c:\users\fedor\appdata\local\dateoption', '*', true);
DeleteFileMask('c:\users\fedor\appdata\local\rightchose', '*', true);
DeleteFileMask('c:\programdata\228z719z9p647', '*', false);
DeleteFileMask('c:\program files (x86)\screenup', '*', true);
DeleteFileMask('c:\users\fedor\appdata\local\filterstart', '*', true);
DeleteDirectory('c:\users\fedor\appdata\local\filesystemoptions');
DeleteDirectory('c:\users\fedor\appdata\local\testmenu');
DeleteDirectory('c:\users\fedor\appdata\local\immediatehelp');
DeleteDirectory('c:\users\fedor\appdata\local\lastnews');
DeleteDirectory('c:\users\fedor\appdata\local\validatelife');
DeleteDirectory('c:\users\fedor\appdata\local\dateoption');
DeleteDirectory('c:\users\fedor\appdata\local\rightchose');
DeleteDirectory('c:\programdata\228z719z9p647');
DeleteDirectory('c:\program files (x86)\screenup');
DeleteDirectory('c:\users\fedor\appdata\local\filterstart');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "228z719z9P647" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "228z719z9P647-dll" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "urlopener" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Request Account Helper" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Manifest Base Mgr" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Solution Language Mgr" /F', 0, 15000, true);
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'FilterOptions');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'FileSystemOptions');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'TestMenu');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'ImmediateHelp');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'LastNews');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'ValidateLife');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'DateOption');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'ELSID001');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.