Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
TerminateProcessByName('C:\ProgramData\673f351eba5b4862995435981ee77770\bqJiFLiHKz1.exe');
TerminateProcessByName('C:\Windows\Temp\g868.tmp.exe');
TerminateProcessByName('C:\Program Files\Samsung\783P65OWZS7QNK2AR2STVOTDKXX\H56Wv21uIP.exe');
StopService('wfcre');
QuarantineFile('C:\ProgramData\673f351eba5b4862995435981ee77770\bqJiFLiHKz1.exe', '');
QuarantineFile('C:\Windows\Temp\g868.tmp.exe', '');
QuarantineFile('C:\Program Files\Samsung\783P65OWZS7QNK2AR2STVOTDKXX\H56Wv21uIP.exe', '');
QuarantineFile('C:\WINDOWS\system32\drivers\wfcre.sys', '');
QuarantineFile('C:\Program Files\CCleaner\MOBBAFM33V\zJdamwzQA0.exe', '');
QuarantineFileF('C:\Windows\Temp', '*.tmp.exe', false, '', 0, 0);
QuarantineFile('C:\Users\Ника\AppData\Local\30c512ef474549938a746af4941d665a\7i3mNU8zRMZnc.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Roaming\d0fbbc9aaa1a402b9ed8e9c968608a23\hBHN8hfj6II.exe', '');
QuarantineFile('C:\ProgramData\f48467b556974691916dca7c83ad9c88\11WGsMLt6RxVP.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Local\01d0fef1786e4154b425e92f8558940b\qCfRvJOooDTL.exe', '');
QuarantineFile('C:\ProgramData\bdfadd877e724bafa30df9c2cbdab539\tpvjugh6NAtFH.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Local\8d469451b704497d84fcbaee6c255e18\ABh46amvf.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Roaming\e34799bc5a1143e4b4461ac845e91834\r7vSvVxyJDe.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Local\b19ad9a68b4148198ec10a378807245f\hRj5GZNPG.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Roaming\64cd3ea34148410fb95651eafa51d426\Yv0EIPuRK.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Local\Temp\3aa871f0f4dc4c1eac53626d99e3006b\amHsfqmgVSsYq.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Local\Temp\2ce18946783a42bbbaf946e307f64119\bm5KfsRu.exe', '');
QuarantineFile('C:\ProgramData\43c63d60fb1748048bd63f1b873aac18\NnIYSN4WXI5.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Local\073d7fbba9204d62b8e6d5ef5dc81e23\yJILLdsR7.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Local\bfe45c913dee4896a4c49cf9ef0cdaf8\ppuLFBsQvHjU.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Local\Temp\6d4bb921070b4dd0bc7af7a38cbe0a11\UmrqpNx.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Local\e41d64d6c4da4be7ab2d8b8061d22115\0sWDvCmOGFPk6.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Local\76324486e17e41fd87a0f44b4f5c9cbf\qGUEM3SCxKbyf.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Roaming\1203acfb67574ba8b49c369f32a1129f\dvRDwYqr.exe', '');
QuarantineFile('C:\ProgramData\7c9f8639cf75482cbd63179d18851b5b\HZ5CYs7chtEc.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Roaming\6a0003cb6b454675843db1f1f4db552d\RFxyguILh.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Local\e3dc2cb6f393499cac804e797f505519\lGINXFGa.exe', '');
QuarantineFile('C:\ProgramData\5af6371eee474e84afbcf9f2af4e397b\C7P9Ifbaj.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Roaming\092935287e824c29836704390dbb776c\ejTg8Rv3RC.exe', '');
QuarantineFile('C:\ProgramData\2ee22d68c7df48708d6c859fd9adafff\I8IpMrYv4gHU.exe', '');
QuarantineFile('C:\Program Files\DOH4A4WX3U\DY46F55XYYDLH9Q\Jm+' + Chr(39) + '3qM9pD.exe', '');
QuarantineFile('C:\WINDOWS\TEMP\g867.tmp.exe', '');
QuarantineFile('C:\Program Files (x86)\Microleaves\Online Application\Online', '');
QuarantineFile('C:\Users\AB31~1\AppData\Roaming\BESTSA~1\ml.py', '');
QuarantineFile('C:\Users\AB31~1\AppData\Roaming\BESTSA~1\app.py', '');
QuarantineFile('C:\Users\Ника\AppData\Roaming\Eeffa\Dfcea.exe', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Services\Dcdaa\Dbbaf.exe', '');
QuarantineFile('C:\ProgramData\WindowsReporting\wermgr.exe', '');
QuarantineFile('C:\Program Files (x86)\PC Clean Plus\PCCleanPlus.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Roaming\Event Monitor\em.exe', '');
QuarantineFile('C:\Users\AB31~1\AppData\Roaming\setupsk\ml.py', '');
QuarantineFile('C:\Users\AB31~1\AppData\Roaming\setupsk\python\pythonw.exe', '');
QuarantineFile('C:\Users\AB31~1\AppData\Roaming\SETUPS~1\ml.py', '');
QuarantineFile('C:\Users\AB31~1\AppData\Roaming\SETUPS~1\python\pythonw.exe', '');
QuarantineFile('C:\Users\Ника\AppData\Local\Microsoft\TaskPlay\caches.dat', '');
QuarantineFile('C:\Program Files (x86)\iWebar\Uninstall.exe', '');
QuarantineFile('C:\Users\Ника\appdata\roaming\event monitor\isxdl.dll', '');
QuarantineFile('C:\Users\Ника\appdata\roaming\gplyra\gplyra.exe', '');
DeleteFile('C:\WINDOWS\Tasks\Updater_Online_Application.job', '64');
DeleteFile('C:\ProgramData\673f351eba5b4862995435981ee77770\bqJiFLiHKz1.exe', '32');
DeleteFile('C:\Windows\Temp\g868.tmp.exe', '32');
DeleteFile('C:\Program Files\Samsung\783P65OWZS7QNK2AR2STVOTDKXX\H56Wv21uIP.exe', '32');
DeleteFile('C:\WINDOWS\system32\drivers\wfcre.sys', '32');
DeleteFile('C:\Program Files\CCleaner\MOBBAFM33V\zJdamwzQA0.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Local\30c512ef474549938a746af4941d665a\7i3mNU8zRMZnc.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Roaming\d0fbbc9aaa1a402b9ed8e9c968608a23\hBHN8hfj6II.exe', '32');
DeleteFile('C:\ProgramData\f48467b556974691916dca7c83ad9c88\11WGsMLt6RxVP.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Local\01d0fef1786e4154b425e92f8558940b\qCfRvJOooDTL.exe', '32');
DeleteFile('C:\ProgramData\bdfadd877e724bafa30df9c2cbdab539\tpvjugh6NAtFH.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Local\8d469451b704497d84fcbaee6c255e18\ABh46amvf.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Roaming\e34799bc5a1143e4b4461ac845e91834\r7vSvVxyJDe.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Local\b19ad9a68b4148198ec10a378807245f\hRj5GZNPG.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Roaming\64cd3ea34148410fb95651eafa51d426\Yv0EIPuRK.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Local\Temp\3aa871f0f4dc4c1eac53626d99e3006b\amHsfqmgVSsYq.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Local\Temp\2ce18946783a42bbbaf946e307f64119\bm5KfsRu.exe', '32');
DeleteFile('C:\ProgramData\43c63d60fb1748048bd63f1b873aac18\NnIYSN4WXI5.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Local\073d7fbba9204d62b8e6d5ef5dc81e23\yJILLdsR7.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Local\bfe45c913dee4896a4c49cf9ef0cdaf8\ppuLFBsQvHjU.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Local\Temp\6d4bb921070b4dd0bc7af7a38cbe0a11\UmrqpNx.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Local\e41d64d6c4da4be7ab2d8b8061d22115\0sWDvCmOGFPk6.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Local\76324486e17e41fd87a0f44b4f5c9cbf\qGUEM3SCxKbyf.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Roaming\1203acfb67574ba8b49c369f32a1129f\dvRDwYqr.exe', '32');
DeleteFile('C:\ProgramData\7c9f8639cf75482cbd63179d18851b5b\HZ5CYs7chtEc.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Roaming\6a0003cb6b454675843db1f1f4db552d\RFxyguILh.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Local\e3dc2cb6f393499cac804e797f505519\lGINXFGa.exe', '32');
DeleteFile('C:\ProgramData\5af6371eee474e84afbcf9f2af4e397b\C7P9Ifbaj.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Roaming\092935287e824c29836704390dbb776c\ejTg8Rv3RC.exe', '32');
DeleteFile('C:\ProgramData\2ee22d68c7df48708d6c859fd9adafff\I8IpMrYv4gHU.exe', '32');
DeleteFile('C:\Program Files\DOH4A4WX3U\DY46F55XYYDLH9Q\Jm+' + Chr(39) + '3qM9pD.exe', '32');
DeleteFile('C:\WINDOWS\TEMP\g867.tmp.exe', '32');
DeleteFile('C:\Program Files (x86)\Microleaves\Online Application\Online', '32');
DeleteFile('C:\Users\AB31~1\AppData\Roaming\BESTSA~1\ml.py', '32');
DeleteFile('C:\Users\AB31~1\AppData\Roaming\BESTSA~1\app.py', '32');
DeleteFile('C:\Users\Ника\AppData\Roaming\Eeffa\Dfcea.exe', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Services\Dcdaa\Dbbaf.exe', '32');
DeleteFile('C:\ProgramData\WindowsReporting\wermgr.exe', '32');
DeleteFile('C:\Program Files (x86)\PC Clean Plus\PCCleanPlus.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Roaming\Event Monitor\em.exe', '32');
DeleteFile('C:\Users\AB31~1\AppData\Roaming\setupsk\ml.py', '32');
DeleteFile('C:\Users\AB31~1\AppData\Roaming\setupsk\python\pythonw.exe', '32');
DeleteFile('C:\Users\AB31~1\AppData\Roaming\SETUPS~1\ml.py', '32');
DeleteFile('C:\Users\AB31~1\AppData\Roaming\SETUPS~1\python\pythonw.exe', '32');
DeleteFile('C:\Users\Ника\AppData\Local\Microsoft\TaskPlay\caches.dat', '32');
DeleteFile('C:\Program Files (x86)\iWebar\Uninstall.exe', '32');
DeleteFile('C:\Users\Ника\appdata\roaming\event monitor\isxdl.dll', '32');
DeleteFile('C:\Users\Ника\appdata\roaming\gplyra\gplyra.exe', '32');
DeleteService('wfcre');
DeleteFileMask('C:\Windows\Temp', '*.tmp.exe', true);
DeleteFileMask('c:\programdata\673f351eba5b4862995435981ee77770', '*', true);
DeleteFileMask('c:\program files (x86)\microleaves', '*', true);
DeleteFileMask('c:\users\ab31~1\appdata\roaming\bestsa~1', '*', true);
DeleteFileMask('c:\users\ника\appdata\roaming\eeffa', '*', true);
DeleteFileMask('c:\program files (x86)\common files\services', '*', true);
DeleteFileMask('c:\programdata\windowsreporting', '*', true);
DeleteFileMask('c:\program files (x86)\pc clean plus', '*', true);
DeleteFileMask('c:\users\ника\appdata\roaming\event monitor', '*', true);
DeleteFileMask('c:\users\ab31~1\appdata\roaming\setupsk', '*', true);
DeleteFileMask('c:\users\ab31~1\appdata\roaming\setups~1', '*', true);
DeleteFileMask('c:\users\ника\appdata\local\microsoft\taskplay', '*', true);
DeleteFileMask('c:\program files (x86)\iwebar', '*', true);
DeleteFileMask('c:\users\ника\appdata\roaming\gplyra', '*', true);
DeleteDirectory('c:\programdata\673f351eba5b4862995435981ee77770');
DeleteDirectory('c:\program files (x86)\microleaves');
DeleteDirectory('c:\users\ab31~1\appdata\roaming\bestsa~1');
DeleteDirectory('c:\users\ника\appdata\roaming\eeffa');
DeleteDirectory('c:\program files (x86)\common files\services');
DeleteDirectory('c:\programdata\windowsreporting');
DeleteDirectory('c:\program files (x86)\pc clean plus');
DeleteDirectory('c:\users\ника\appdata\roaming\event monitor');
DeleteDirectory('c:\users\ab31~1\appdata\roaming\setupsk');
DeleteDirectory('c:\users\ab31~1\appdata\roaming\setups~1');
DeleteDirectory('c:\users\ника\appdata\local\microsoft\taskplay');
DeleteDirectory('c:\program files (x86)\iwebar');
DeleteDirectory('c:\users\ника\appdata\roaming\gplyra');
DelBHO('{DBC80044-A445-435b-BC74-9C25C1C588A9}');
ExecuteFile('schtasks.exe', '/delete /TN "bestsalesprofit" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "bestsalesprofit2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Feafd" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Bdbfc" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Defrag\Ccebf" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Diagnosis\Dcbfd" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Maintenance\Feafd" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Media Center\Fabaa" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\MUI\Ebeef" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Shell\Bdbfc" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Shell\Feafd" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\SideShow\Fabaa" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Windows Error Reporting\Beede" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Windows Error Reporting\ErrorReporting" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "pc clean plus_updates" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "RunAtStartup" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "setupsk" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "setupsk_upd" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Updater_Online_Application" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{C8226825-BD66-4069-87C5-C53C19D0A5FA}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{CF564732-9ECC-4E49-B24C-28FF7C278A39}" /F', 0, 15000, true);
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'zJdamwzQA0.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '7i3mNU8zRMZnc.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'hBHN8hfj6II.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '11WGsMLt6RxVP.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'qCfRvJOooDTL.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'tpvjugh6NAtFH.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'ABh46amvf.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'r7vSvVxyJDe.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'hRj5GZNPG.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Yv0EIPuRK.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'amHsfqmgVSsYq.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'bm5KfsRu.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'NnIYSN4WXI5.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'yJILLdsR7.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'ppuLFBsQvHjU.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'UmrqpNx.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '0sWDvCmOGFPk6.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'qGUEM3SCxKbyf.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'dvRDwYqr.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'HZ5CYs7chtEc.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'RFxyguILh.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'lGINXFGa.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'C7P9Ifbaj.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'ejTg8Rv3RC.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'I8IpMrYv4gHU.exe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'bqJiFLiHKz1.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'Lahin_Raw_barra_al3eb_b3id_Jm+'3qM9pD.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'Lahin_Raw_barra_al3eb_b3id_H56Wv21uIP.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'NIKA');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteRepair(13);
ExecuteRepair(4);
ExecuteRepair(3);
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.