Код:
begin
TerminateProcessByName('C:\Windows\svchost.exe');
QuarantineFile('C:\Windows\svchost.exe', '');
QuarantineFile('C:\Users\ALB\AppData\Local\Microsoft\7D47C0EBF0964151C2CAC8D0839F3CE6\CF32297B133FB26365125433CA8CE58E.exe', '');
QuarantineFile('C:\Windows\winstart.bat', '');
QuarantineFile('C:\Users\ALB\AppData\Local\Adobe\PPAPI\395C6E5B-5682-4D26-ADCC-FA96CE34DFBB\6B359E0B-D9FE-4108-8612-29BA3B283143.exe', '');
QuarantineFile('C:\Users\ALB\AppData\Roaming\Adobe\Manager.exe', '');
QuarantineFile('C:\Windows\csrss.exe', '');
DeleteFile('C:\Windows\svchost.exe', '32');
DeleteFile('C:\Users\ALB\AppData\Local\Microsoft\7D47C0EBF0964151C2CAC8D0839F3CE6\CF32297B133FB26365125433CA8CE58E.exe', '32');
DeleteFile('C:\Windows\winstart.bat', '32');
DeleteFile('C:\Users\ALB\AppData\Local\Adobe\PPAPI\395C6E5B-5682-4D26-ADCC-FA96CE34DFBB\6B359E0B-D9FE-4108-8612-29BA3B283143.exe', '32');
DeleteFile('C:\Users\ALB\AppData\Roaming\Adobe\Manager.exe', '32');
DeleteFile('C:\Windows\csrss.exe', '32');
DeleteService('Windows');
DeleteFileMask('c:\users\alb\appdata\local\microsoft\7d47c0ebf0964151c2cac8d0839f3ce6', '*', true);
DeleteFileMask('c:\users\alb\appdata\local\adobe\ppapi', '*', true);
DeleteDirectory('c:\users\alb\appdata\local\microsoft\7d47c0ebf0964151c2cac8d0839f3ce6');
DeleteDirectory('c:\users\alb\appdata\local\adobe\ppapi');
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\8CE58EAC33452156362BF331B7CF3229" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\8CE58EAC33452156362BF331B7CF3229SB" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\8CE58EAC33452156362BF331B7CF3229" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\8CE58EAC33452156362BF331B7CF3229SB" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\A395C6E5B-5682-4D26-ADCC-FA96CE34DFBB" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Multimedia\Manager" /F', 0, 15000, true);
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', '8CE58EAC33452156362BF331B7CF3229SB');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
RebootWindows(true);
end.
Компьютер перезагрузится.