Код:
begin
StopService('46e76a0915f5079e');
StopService('46e76a70b0a331b7');
QuarantineFile('C:\Program Files (x86)\AFgCFPkotwsU2\XMBOsgPCPdRus.dll', '');
QuarantineFile('C:\Program Files (x86)\iHxowcMbEquvyaXNgMR\HBoPrtK.dll', '');
QuarantineFile('C:\Program Files (x86)\jWvePDzmFuLuC\wSIXEKE.dll', '');
QuarantineFile('C:\Program Files (x86)\WeatherInspect\KUCRH.exe', '');
QuarantineFile('C:\ProgramData\WindowsMenu\enplus.exe', '');
QuarantineFile('C:\ProgramData\WindowsMenu\westat.exe', '');
QuarantineFile('c:\users\studia_pc\appdata\local\xservice\xservice.dll', '');
QuarantineFile('C:\Windows\TEMP\820e994.sys', '');
QuarantineFile('C:\Windows\TEMP\9356a30.sys', '');
QuarantineFile('C:\Windows\TEMP\inyCucqamxVJrgXA\sriWRDSdfralRPkv.exe', '');
DeleteFile('C:\Program Files (x86)\AFgCFPkotwsU2\XMBOsgPCPdRus.dll', '');
DeleteFile('C:\Program Files (x86)\iHxowcMbEquvyaXNgMR\HBoPrtK.dll', '');
DeleteFile('C:\Program Files (x86)\jWvePDzmFuLuC\wSIXEKE.dll', '');
DeleteFile('C:\Program Files (x86)\WeatherInspect\KUCRH.exe', '32');
DeleteFile('C:\ProgramData\WindowsMenu\enplus.exe', '');
DeleteFile('C:\ProgramData\WindowsMenu\westat.exe', '');
DeleteFile('c:\users\studia_pc\appdata\local\xservice\xservice.dll', '');
DeleteFile('C:\Users\Studia_PC\AppData\Local\XService\XService.dll', '32');
DeleteFile('C:\Windows\Tasks\bkuWEPKvAynruffMrNJ.job', '64');
DeleteFile('C:\Windows\TEMP\820e994.sys', '');
DeleteFile('C:\Windows\TEMP\9356a30.sys', '');
DeleteFile('C:\Windows\TEMP\inyCucqamxVJrgXA\sriWRDSdfralRPkv.exe', '');
ExecuteFile('schtasks.exe', '/delete /TN "bkuWEPKvAynruffMrNJ" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "HCFlKJlLNXMilIycGmi2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ksFqmuWlgDqlfq" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "MGnDKqpyxWdiicJlI2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\QuickLaunch" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Starter" /F', 0, 15000, true);
DeleteService('46e76a0915f5079e');
DeleteService('46e76a70b0a331b7');
DeleteService('Starter Check');
DeleteFileMask('c:\program files (x86)\afgcfpkotwsu2', '*', true);
DeleteFileMask('c:\program files (x86)\ihxowcmbequvyaxngmr', '*', true);
DeleteFileMask('c:\program files (x86)\jwvepdzmfuluc', '*', true);
DeleteFileMask('c:\program files (x86)\weatherinspect', '*', true);
DeleteFileMask('c:\programdata\windowsmenu', '*', true);
DeleteFileMask('c:\users\studia_pc\appdata\local\xservice', '*', true);
DeleteFileMask('c:\windows\temp\inycucqamxvjrgxa', '*', true);
DeleteDirectory('c:\program files (x86)\afgcfpkotwsu2');
DeleteDirectory('c:\program files (x86)\ihxowcmbequvyaxngmr');
DeleteDirectory('c:\program files (x86)\jwvepdzmfuluc');
DeleteDirectory('c:\program files (x86)\weatherinspect');
DeleteDirectory('c:\programdata\windowsmenu');
DeleteDirectory('c:\users\studia_pc\appdata\local\xservice');
DeleteDirectory('c:\windows\temp\inycucqamxvjrgxa');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'H1DIEDJDZGX7YY2');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\MicroService\Parameters', 'ServiceDll');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.
Код:
>>> "C:\Users\Studia_PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk" -> ["C:\Program Files\Internet Explorer\iexplore.exe" =>> %SNP%]
>>> "C:\Users\Studia_PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk" -> ["C:\Program Files\Internet Explorer\iexplore.exe" =>> %SNP%]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PostgreSQL 8.4\SQL Shell (psql).lnk" -> ["C:\postgreSQL\scripts\runpsql.bat"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK\Удалить - TL-WN725N_WN723N Драйвер.lnk" -> ["C:\Program Files (x86)\InstallShield Installation Information\{3C3F9CEB-2C5A-4A47-8EAA-DA76037546BA}\setup.exe" =>> -runfromtemp -removeonly DriverOnly]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google\Backup and Sync from Google.lnk" -> ["C:\Program Files\Google\Drive\googledrivesync.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google\Google Sheets.lnk" -> ["C:\Program Files\Google\Drive\googledrivesync.exe" =>> --new_spreadsheet]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google\Google Slides.lnk" -> ["C:\Program Files\Google\Drive\googledrivesync.exe" =>> --new_presentation]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google\Google Docs.lnk" -> ["C:\Program Files\Google\Drive\googledrivesync.exe" =>> --new_document]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\partypoker.lnk" -> ["C:\Programs\PartyGaming\PartyGaming.exe" =>> -P=PartyPoker]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\partypoker\partypoker.lnk" -> ["C:\Programs\PartyGaming\PartyGaming.exe" =>> -P=PartyPoker]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmarThru Office\SmarThru Office.lnk" -> ["C:\Program Files (x86)\SmarThru Office\STONavigator.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmarThru Office\SmarThru Office Launcher.lnk" -> ["C:\Program Files (x86)\SmarThru Office\x64\LegacyLauncher.exe"]
>>> "C:\Users\Studia_PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Starbound.lnk" -> ["E:\Game\Starbound\win32\launcher\launcher.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDjView\WinDjView.lnk" -> ["C:\Program Files\WinDjView\WinDjView.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDjView\Удалить WinDjView.lnk" -> ["C:\Program Files\WinDjView\uninstall.exe"]
>>> "C:\Users\Studia_PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CodeBlocks.lnk" -> ["C:\Users\Studia_PC\CodeBlocks\codeblocks.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kerbal Space Program\Kerbal Space Program.lnk" -> ["E:\Game\Kerbal Space Program\KSP_x64.exe"]
>>> "C:\Users\Studia_PC\AppData\Roaming\Microsoft\Excel\Прайс%20Сайт%20(70,80,100,%20Хаски)%20от%2001,08,2306816500852470998\Прайс%20Сайт%20(70,80,100,%20Хаски)%20от%2001,08,2018%20розница.xlsx.lnk" -> ["C:\Users\Studia_PC\Desktop\Прайс Сайт (70,80,100, Хаски) от 01,08,2018 розница.xlsx" =>> 50]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Русская рыбалка (Одиночная)\Редактор водоемов.lnk" -> ["E:\Game\Game\RF3.Offline\RF2MapEditor.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Русская рыбалка (Одиночная)\Руководство по игре.lnk" -> ["E:\Game\Game\RF3.Offline\Help\help.html"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerStars\PokerStars.lnk" -> ["C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerStars\Network Status.lnk" -> ["C:\Program Files (x86)\PokerStars\Tracer.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerStars\Uninstall PokerStars.lnk" -> ["C:\Program Files (x86)\PokerStars\PokerStarsUninstall.exe" =>> /u:PokerStars]
>>> "C:\Users\Studia_PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Twitch.lnk" -> ["C:\Users\Studia_PC\AppData\Roaming\Twitch\Bin\Twitch.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam.lnk" -> ["C:\Program Files (x86)\Steam\Steam.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PostgreSQL 8.4\Application Stack Builder.lnk" -> ["C:\postgreSQL\bin\stackbuilder.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan\SpeedFan.lnk" -> ["C:\Program Files (x86)\SpeedFan\speedfan.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan\Help and HOW-TO.lnk" -> ["C:\Program Files (x86)\SpeedFan\speedfan.chm"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan\Release info.lnk" -> ["C:\Program Files (x86)\SpeedFan\speedfan.txt"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan\Uninstall SpeedFan.lnk" -> ["C:\Program Files (x86)\SpeedFan\uninstall.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PostgreSQL 8.4\Documentation\pgAdmin documentation (French).lnk" -> ["C:\postgreSQL\pgAdmin III\docs\fr_FR\pgadmin3.chm"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PostgreSQL 8.4\Documentation\pgAdmin documentation (Czech).lnk" -> ["C:\postgreSQL\pgAdmin III\docs\cs_CZ\pgadmin3.chm"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PostgreSQL 8.4\Documentation\pgAdmin documentation (English).lnk" -> ["C:\postgreSQL\pgAdmin III\docs\en_US\pgadmin3.chm"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PostgreSQL 8.4\pgAdmin III.lnk" -> ["C:\postgreSQL\bin\pgAdmin3.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\partypoker.lnk" -> ["C:\Programs\PartyGaming\PartyGaming.exe" =>> -P=PartyPoker]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\partypoker\Uninstall partypoker.lnk" -> ["C:\programs\partygaming\PartyPoker\Uninstall\Setup.exe" =>> App_Type=U]
>>> "C:\Users\postgres\Desktop\888casino.lnk" -> ["C:\Program Files (x86)\CasinoOnNet\bin\casino.exe"]
Отчёт о работе прикрепите.