Код:
begin
TerminateProcessByName('c:\users\dima\appdata\roaming\7f064c\c692e8.exe');
QuarantineFileF('c:\users\dima\appdata\roaming\7f064c', '*.exe', false, '', 0 , 0);
QuarantineFile('c:\users\dima\appdata\roaming\7f064c\c692e8.exe', '');
QuarantineFile('C:\Users\Dima\AppData\Roaming\iVWxXh6.exe', '');
QuarantineFile('C:\ProgramData\TimeTasks\TimeTasksSetup.exe', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe', '');
QuarantineFile('C:\ProgramData\Yellow AdBlocker\Yellow AdBlocker.exe', '');
QuarantineFile('C:\ProgramData\Mini - Adblocker\Mini - Adblocker.exe', '');
QuarantineFile('C:\ProgramData\Supreme AdBlocker\Supreme AdBlocker.exe', '');
QuarantineFile('C:\ProgramData\Extreme Blocker\Extreme Blocker.exe', '');
DeleteFile('c:\users\dima\appdata\roaming\7f064c\c692e8.exe', '32');
DeleteFile('C:\Users\Dima\AppData\Local\Temp\65A4728.sys', '32');
DeleteFile('C:\Users\Dima\AppData\Local\Temp\7C281BC.sys', '32');
DeleteFile('C:\Users\Dima\AppData\Local\Temp\55B0CC1.sys', '32');
DeleteFile('C:\Users\Dima\AppData\Local\Temp\967EF29.sys', '32');
DeleteFile('C:\Users\Dima\AppData\Roaming\iVWxXh6.exe', '32');
DeleteFile('C:\ProgramData\TimeTasks\TimeTasksSetup.exe', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe', '32');
DeleteFile('C:\ProgramData\Yellow AdBlocker\Yellow AdBlocker.exe', '32');
DeleteFile('C:\ProgramData\Mini - Adblocker\Mini - Adblocker.exe', '32');
DeleteFile('C:\ProgramData\Supreme AdBlocker\Supreme AdBlocker.exe', '32');
DeleteFile('C:\ProgramData\Extreme Blocker\Extreme Blocker.exe', '32');
DeleteFile('C:\Users\Dima\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk');
DeleteService('4F95399518B46EF9');
DeleteService('4F95F4CF1D78C3F9');
DeleteService('4F95F4CF6F833099');
DeleteService('4F95F4CFC135A279');
DeleteFileMask('c:\users\dima\appdata\roaming\7f064c', '*', true);
DeleteFileMask('c:\programdata\timetasks', '*', true);
DeleteFileMask('c:\program files (x86)\zaxar', '*', true);
DeleteFileMask('c:\programdata\yellow adblocker', '*', true);
DeleteFileMask('c:\programdata\mini - adblocker', '*', true);
DeleteFileMask('c:\programdata\supreme adblocker', '*', true);
DeleteFileMask('c:\programdata\extreme blocker', '*', true);
DeleteDirectory('c:\users\dima\appdata\roaming\7f064c');
DeleteDirectory('c:\programdata\timetasks');
DeleteDirectory('c:\program files (x86)\zaxar');
DeleteDirectory('c:\programdata\yellow adblocker');
DeleteDirectory('c:\programdata\mini - adblocker');
DeleteDirectory('c:\programdata\supreme adblocker');
DeleteDirectory('c:\programdata\extreme blocker');
ExecuteFile('schtasks.exe', '/delete /TN "{3D593A11-0595-402B-8269-D95D56535385}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{50896A8A-AF8A-4285-B838-5B9C1FD15684}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{6BF69235-2B0A-4399-85D6-82CFC684D9BE}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{89E8E136-3238-4013-9A0E-E36D76856098}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{E5E07D91-4F13-492E-9BDD-C3664B663AC0}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{EEEF4D0D-0034-4931-88AA-239D8FA05CFF}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ASP" /F', 0, 15000, true);
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '7F064C');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MediaVerifyer', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Timestasks', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ZaxarLoader', 'command');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.