Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
StopService('fratgpcf');
StopService('prifass');
QuarantineFile('C:\Program Files (x86)\SvnSzzIscGyUC\mmTcToB.dll', '');
QuarantineFile('C:\Program Files (x86)\SystemHealer\HealerConsole.exe', '');
QuarantineFile('C:\Program Files (x86)\SystemHealer\SystemHealer.exe', '');
QuarantineFile('C:\Program Files\SystemaRev\RevServicesX\updaterev.exe', '');
QuarantineFile('C:\ProgramData\a1128b39ba0441c7ae6c3fe76f48f07e\HandlerExecution.exe', '');
QuarantineFile('C:\ProgramData\AppriabuS\Unolab.dll', '');
QuarantineFile('C:\ProgramData\Subair\Free-Core.reg', '');
QuarantineFile('C:\Users\rini\AppData\Local\39bc555b0a2541f49ea3448e00b8df81\HandlerExecution.exe', '');
QuarantineFile('C:\Users\rini\AppData\Local\88d80c293a084afbb0e5bf7c1fc810d1\HandlerExecution.exe', '');
QuarantineFile('C:\Users\rini\AppData\Local\c10021975a434878b5d7420f93cc1ff8\HandlerExecution.exe', '');
QuarantineFile('C:\Users\rini\AppData\Roaming\5d49703c101e42a088b924dbc36478ad\HandlerExecution.exe', '');
QuarantineFile('C:\Users\rini\AppData\Roaming\wget 1.16\wget.exe', '');
QuarantineFile('C:\Users\rini\AppData\Roaming\wget 1.16\wget_1_19_4.exe', '');
QuarantineFile('C:\Windows\System32\drivers\prifass.sys', '');
QuarantineFile('C:\Windows\system32\drivers\ybvtxiwe.sys', '');
DeleteFile('C:\Program Files (x86)\SvnSzzIscGyUC\mmTcToB.dll', '');
DeleteFile('C:\Program Files (x86)\SystemHealer\HealerConsole.exe', '');
DeleteFile('C:\Program Files (x86)\SystemHealer\SystemHealer.exe', '');
DeleteFile('C:\Program Files\SystemaRev\RevServicesX\updaterev.exe', '');
DeleteFile('C:\ProgramData\a1128b39ba0441c7ae6c3fe76f48f07e\HandlerExecution.exe', '');
DeleteFile('C:\ProgramData\AppriabuS\Unolab.dll', '64');
DeleteFile('C:\ProgramData\Subair\Free-Core.reg', '');
DeleteFile('C:\Users\rini\AppData\Local\39bc555b0a2541f49ea3448e00b8df81\HandlerExecution.exe', '');
DeleteFile('C:\Users\rini\AppData\Local\88d80c293a084afbb0e5bf7c1fc810d1\HandlerExecution.exe', '');
DeleteFile('C:\Users\rini\AppData\Local\c10021975a434878b5d7420f93cc1ff8\HandlerExecution.exe', '');
DeleteFile('C:\Users\rini\AppData\Roaming\5d49703c101e42a088b924dbc36478ad\HandlerExecution.exe', '');
DeleteFile('C:\Users\rini\AppData\Roaming\wget 1.16\wget.exe', '');
DeleteFile('C:\Users\rini\AppData\Roaming\wget 1.16\wget_1_19_4.exe', '');
DeleteFile('C:\Windows\System32\drivers\prifass.sys', '');
DeleteFile('C:\Windows\system32\drivers\ybvtxiwe.sys', '');
ExecuteFile('schtasks.exe', '/delete /TN "GoogleUpdateSecurityTaskMachine_DB" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "GoogleUpdateSecurityTaskMachine_HA" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "GoogleUpdateSecurityTaskMachine_HM" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "GoogleUpdateSecurityTaskMachine_MX" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "GoogleUpdateSecurityTaskMachine_NF" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "MainPM" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "psv_Lamfax" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "System Healer Delayed" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "System Healer Monitor" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "TUZwhpCbnzWcBoUhWSI2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "update64" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "wget" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "wgets" /F', 0, 15000, true);
DeleteService('fratgpcf');
DeleteService('prifass');
DeleteService('update64');
DeleteFileMask('c:\program files (x86)\svnszziscgyuc', '*', true);
DeleteFileMask('c:\program files (x86)\systemhealer', '*', true);
DeleteFileMask('c:\program files\systemarev\revservicesx', '*', true);
DeleteFileMask('c:\programdata\a1128b39ba0441c7ae6c3fe76f48f07e', '*', true);
DeleteFileMask('c:\programdata\appriabus', '*', true);
DeleteFileMask('c:\users\rini\appdata\local\39bc555b0a2541f49ea3448e00b8df81', '*', true);
DeleteFileMask('c:\users\rini\appdata\local\88d80c293a084afbb0e5bf7c1fc810d1', '*', true);
DeleteFileMask('c:\users\rini\appdata\local\c10021975a434878b5d7420f93cc1ff8', '*', true);
DeleteFileMask('c:\users\rini\appdata\roaming\5d49703c101e42a088b924dbc36478ad', '*', true);
DeleteFileMask('c:\users\rini\appdata\roaming\wget 1.16', '*', true);
DeleteDirectory('c:\program files (x86)\svnszziscgyuc');
DeleteDirectory('c:\program files (x86)\systemhealer');
DeleteDirectory('c:\program files\systemarev\revservicesx');
DeleteDirectory('c:\programdata\a1128b39ba0441c7ae6c3fe76f48f07e');
DeleteDirectory('c:\programdata\appriabus');
DeleteDirectory('c:\users\rini\appdata\local\39bc555b0a2541f49ea3448e00b8df81');
DeleteDirectory('c:\users\rini\appdata\local\88d80c293a084afbb0e5bf7c1fc810d1');
DeleteDirectory('c:\users\rini\appdata\local\c10021975a434878b5d7420f93cc1ff8');
DeleteDirectory('c:\users\rini\appdata\roaming\5d49703c101e42a088b924dbc36478ad');
DeleteDirectory('c:\users\rini\appdata\roaming\wget 1.16');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.