Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
QuarantineFile('C:\ProgramData\Windows\System32\x64\isaa.exe', '');
QuarantineFile('C:\Users\Nik\AppData\Local\Temp\isaa.exe', '');
QuarantineFile('C:\Users\Nik\AppData\Roaming\iuoauk.exe', '');
QuarantineFile('C:\Users\Nik\AppData\Roaming\YTKNfCo.exe', '');
QuarantineFile('C:\Windows\System32\drivers\mracdrv.sys', '');
QuarantineFile('C:\Windows\System32\mracsvc.exe', '');
DeleteFile('C:\ProgramData\Windows\System32\x64\isaa.exe', '32');
DeleteFile('C:\Users\Nik\AppData\Local\Temp\isaa.exe', '32');
DeleteFile('C:\Users\Nik\AppData\Roaming\iuoauk.exe', '32');
DeleteFile('C:\Users\Nik\AppData\Roaming\YTKNfCo.exe', '32');
DeleteFile('C:\Windows\System32\drivers\mracdrv.sys', '32');
DeleteFile('C:\Windows\System32\mracsvc.exe', '32');
ExecuteFile('schtasks.exe', '/delete /TN "{3754F209-2B3B-4EC3-800D-75C094A4CDFB}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{FCB86346-93C4-43F4-B2CD-6CEC6C679EE8}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Windows\CampaignManager" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Windows\ServiceRun" /F', 0, 15000, true);
DeleteService('mracdrv');
DeleteService('mracsvc');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
Компьютер перезагрузится.