Код:
begin
TerminateProcessByName('c:\programdata\windowssql\com surrogate.exe');
TerminateProcessByName('c:\users\alexa\appdata\roaming\windows_firewall.{4026492f-2f69-46b8-b9bf-5654fc07e423}\comhosts.exe');
TerminateProcessByName('c:\users\alexa\appdata\roaming\backup.{b98a2bea-7d42-4558-8bd1-832f41bac6fd}\backup\conserver_at.exe');
TerminateProcessByName('c:\program files (x86)\common files\microsoft shared\phone tools\corecon\11.0\bin\ipoverusbsvc.exe');
TerminateProcessByName('C:\ProgramData\WindowsTask\MicrosoftShellHost.exe');
TerminateProcessByName('c:\users\alexa\appdata\roaming\windows_firewall.{4026492f-2f69-46b8-b9bf-5654fc07e423}\runhosts.exe');
TerminateProcessByName('C:\ProgramData\System32\Logs\ShellExperienceHost.exe');
TerminateProcessByName('c:\users\alexa\appdata\roaming\memorycool\sysservices.exe');
TerminateProcessByName('c:\programdata\framework\windows driver.exe');
TerminateProcessByName('c:\programdata\winsxd.exe');
TerminateProcessByName('c:\program files (x86)\uumeftwnyie\yrrcuitcah.exe');
StopService('IpOverUsbSvc');
QuarantineFileF('c:\users\alexa\appdata\roaming\memorycool', '*.exe', false, '', 0 , 0);
QuarantineFile('c:\programdata\windowssql\com surrogate.exe', '');
QuarantineFile('c:\users\alexa\appdata\roaming\windows_firewall.{4026492f-2f69-46b8-b9bf-5654fc07e423}\comhosts.exe', '');
QuarantineFile('c:\users\alexa\appdata\roaming\backup.{b98a2bea-7d42-4558-8bd1-832f41bac6fd}\backup\conserver_at.exe', '');
QuarantineFile('C:\ProgramData\WindowsTask\MicrosoftShellHost.exe', '');
QuarantineFile('c:\users\alexa\appdata\roaming\windows_firewall.{4026492f-2f69-46b8-b9bf-5654fc07e423}\runhosts.exe', '');
QuarantineFile('C:\ProgramData\System32\Logs\ShellExperienceHost.exe', '');
QuarantineFile('c:\users\alexa\appdata\roaming\memorycool\sysservices.exe', '');
QuarantineFile('c:\programdata\framework\windows driver.exe', '');
QuarantineFile('c:\programdata\winsxd.exe', '');
QuarantineFile('c:\program files (x86)\uumeftwnyie\yrrcuitcah.exe', '');
QuarantineFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\Qt5Widgets.dll', '');
QuarantineFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\Qt5Gui.dll', '');
QuarantineFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\Qt5Core.dll', '');
QuarantineFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\Qt5WebSockets.dll', '');
QuarantineFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\Qt5Network.dll', '');
QuarantineFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\OpenCL.dll', '');
QuarantineFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\platforms\qwindows.dll', '');
QuarantineFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\ssleay32.dll', '');
QuarantineFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\LIBEAY32.dll', '');
QuarantineFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\imageformats\qico.dll', '');
QuarantineFile('C:\Program Files (x86)\UUMEfTWNyIE\kbYaKZWvA.dll', '');
QuarantineFile('C:\Program Files (x86)\UUMEfTWNyIE\iRhXP.dll', '');
QuarantineFile('C:\WINDOWS\system32\drivers\wfcre.sys', '');
QuarantineFile('C:\WINDOWS\System32\ihctrl32.dll', '');
QuarantineFile('C:\WINDOWS\System32\wsaudio.dll', '');
QuarantineFile('C:\Users\Alexa\AppData\Roaming\Microsoft\fairbvsa\dgjivcfd.exe', '');
QuarantineFile('C:\Program Files (x86)\PieSfXRZU\HDwtfe.dll', '');
QuarantineFile('C:\Users\Alexa\AppData\Roaming\Backup.{B98A2BEA-7D42-4558-8BD1-832F41BAC6FD}\Backup\conserver_at.sfx.exe', '');
QuarantineFile('C:\Users\Alexa\AppData\Roaming\Recovery\rmssys.exe', '');
QuarantineFile('C:\Program Files (x86)\JgBxoaZwmZRU2\pHGDGwDttfXeD.dll', '');
DeleteFile('C:\WINDOWS\Tasks\BYkucKAbLoZInYF.job', '64');
DeleteFile('c:\programdata\windowssql\com surrogate.exe', '32');
DeleteFile('c:\users\alexa\appdata\roaming\windows_firewall.{4026492f-2f69-46b8-b9bf-5654fc07e423}\comhosts.exe', '32');
DeleteFile('c:\users\alexa\appdata\roaming\backup.{b98a2bea-7d42-4558-8bd1-832f41bac6fd}\backup\conserver_at.exe', '32');
DeleteFile('C:\ProgramData\WindowsTask\MicrosoftShellHost.exe', '32');
DeleteFile('c:\users\alexa\appdata\roaming\windows_firewall.{4026492f-2f69-46b8-b9bf-5654fc07e423}\runhosts.exe', '32');
DeleteFile('C:\ProgramData\System32\Logs\ShellExperienceHost.exe', '32');
DeleteFile('c:\users\alexa\appdata\roaming\memorycool\sysservices.exe', '32');
DeleteFile('c:\programdata\framework\windows driver.exe', '32');
DeleteFile('c:\programdata\winsxd.exe', '32');
DeleteFile('c:\program files (x86)\uumeftwnyie\yrrcuitcah.exe', '32');
DeleteFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\Qt5Widgets.dll', '32');
DeleteFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\Qt5Gui.dll', '32');
DeleteFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\Qt5Core.dll', '32');
DeleteFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\Qt5WebSockets.dll', '32');
DeleteFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\Qt5Network.dll', '32');
DeleteFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\OpenCL.dll', '32');
DeleteFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\platforms\qwindows.dll', '32');
DeleteFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\ssleay32.dll', '32');
DeleteFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\LIBEAY32.dll', '32');
DeleteFile('C:\Users\Alexa\AppData\Roaming\Windows_Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}\imageformats\qico.dll', '32');
DeleteFile('C:\Program Files (x86)\UUMEfTWNyIE\kbYaKZWvA.dll', '32');
DeleteFile('C:\Users\Alexa\AppData\Roaming\memorycool\libmysql.dll', '32');
DeleteFile('C:\ProgramData\Framework\Qt5WebSockets.dll', '32');
DeleteFile('C:\ProgramData\Framework\Qt5Core.dll', '32');
DeleteFile('C:\ProgramData\Framework\Qt5Network.dll', '32');
DeleteFile('C:\ProgramData\Framework\ssleay32.dll', '32');
DeleteFile('C:\ProgramData\Framework\LIBEAY32.dll', '32');
DeleteFile('C:\Program Files (x86)\UUMEfTWNyIE\iRhXP.dll', '32');
DeleteFile('C:\WINDOWS\system32\drivers\wfcre.sys', '32');
DeleteFile('C:\WINDOWS\System32\ihctrl32.dll', '32');
DeleteFile('C:\WINDOWS\System32\wsaudio.dll', '32');
DeleteFile('C:\Users\Alexa\AppData\Roaming\Microsoft\fairbvsa\dgjivcfd.exe', '32');
DeleteFile('C:\Program Files (x86)\PieSfXRZU\HDwtfe.dll', '32');
DeleteFile('C:\Users\Alexa\AppData\Roaming\Backup.{B98A2BEA-7D42-4558-8BD1-832F41BAC6FD}\Backup\conserver_at.sfx.exe', '32');
DeleteFile('C:\Users\Alexa\AppData\Roaming\Recovery\rmssys.exe', '32');
DeleteFile('C:\Program Files (x86)\JgBxoaZwmZRU2\pHGDGwDttfXeD.dll', '32');
DeleteService('IpOverUsbSvc');
DeleteService('WinSxD');
DeleteService('wfcre');
DeleteFileMask('c:\programdata\windowssql', '*', true);
DeleteFileMask('c:\users\alexa\appdata\roaming\windows_firewall.{4026492f-2f69-46b8-b9bf-5654fc07e423}', '*', true);
DeleteFileMask('c:\users\alexa\appdata\roaming\backup.{b98a2bea-7d42-4558-8bd1-832f41bac6fd}', '*', true);
DeleteFileMask('c:\program files (x86)\common files\microsoft shared\phone tools', '*', true);
DeleteFileMask('c:\programdata\windowstask', '*', true);
DeleteFileMask('c:\programdata\system32\logs', '*', true);
DeleteFileMask('c:\users\alexa\appdata\roaming\memorycool', '*', true);
DeleteFileMask('c:\programdata\framework', '*', true);
DeleteFileMask('c:\program files (x86)\uumeftwnyie', '*', true);
DeleteFileMask('c:\users\alexa\appdata\roaming\microsoft\fairbvsa', '*', true);
DeleteFileMask('c:\program files (x86)\piesfxrzu', '*', true);
DeleteFileMask('c:\users\alexa\appdata\roaming\recovery', '*', true);
DeleteFileMask('c:\program files (x86)\jgbxoazwmzru2', '*', true);
DeleteDirectory('c:\programdata\windowssql');
DeleteDirectory('c:\users\alexa\appdata\roaming\windows_firewall.{4026492f-2f69-46b8-b9bf-5654fc07e423}');
DeleteDirectory('c:\users\alexa\appdata\roaming\backup.{b98a2bea-7d42-4558-8bd1-832f41bac6fd}');
DeleteDirectory('c:\program files (x86)\common files\microsoft shared\phone tools');
DeleteDirectory('c:\programdata\windowstask');
DeleteDirectory('c:\programdata\system32\logs');
DeleteDirectory('c:\users\alexa\appdata\roaming\memorycool');
DeleteDirectory('c:\programdata\framework');
DeleteDirectory('c:\program files (x86)\uumeftwnyie');
DeleteDirectory('c:\users\alexa\appdata\roaming\microsoft\fairbvsa');
DeleteDirectory('c:\program files (x86)\piesfxrzu');
DeleteDirectory('c:\users\alexa\appdata\roaming\recovery');
DeleteDirectory('c:\program files (x86)\jgbxoazwmzru2');
DelBHO('{C0D38E5A-7CF8-4105-8FE8-31B81443A114}');
ExecuteFile('schtasks.exe', '/delete /TN "BYkucKAbLoZInYF" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "BYkucKAbLoZInYF2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\comhosts\runco" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Memory\recovery" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\system\r" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\sytems\recovery" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Wininet\Systemmanedger" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "zXHETIgCcYWbiA" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{0D5F4463-D958-47B3-B5E0-5447E63083AF}" /F', 0, 15000, true);
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Google_updater');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\ihctrl32\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\wsaudio\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'THIS IS WIIIGET!');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.