Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
TerminateProcessByName('c:\users\admin\appdata\local\temp\vobufbtaztrqzihs.exe');
TerminateProcessByName('c:\users\admin\appdata\local\temp\wgkuwjs.exe');
QuarantineFile('C:\autorun.inf', '');
QuarantineFile('C:\Users\Admin\AppData\Local\Temp\cwkeqngoojiisccoi.exe', '');
QuarantineFile('C:\Users\Admin\AppData\Local\Temp\vobufbtaztrqzihs.exe .', '');
QuarantineFile('c:\users\admin\appdata\local\temp\vobufbtaztrqzihs.exe', '');
QuarantineFile('c:\users\admin\appdata\local\temp\wgkuwjs.exe', '');
QuarantineFile('C:\Users\Admin\AppData\Local\Temp\ywomcdamqpswkycsqtmkc.exe .', '');
QuarantineFile('C:\wgkuwjs.bat', '');
QuarantineFile('C:\Windows\system32\jgxujjfqtrtwjwzolnfc.exe', '');
QuarantineFile('C:\Windows\system32\lgvqdbvefbbcnyzmhh.exe', '');
QuarantineFile('C:\Windows\system32\vobufbtaztrqzihs.exe', '');
QuarantineFile('C:\Windows\system32\wsiesrmwyvwykwymija.exe', '');
QuarantineFile('D:\autorun.inf', '');
QuarantineFile('D:\wgkuwjs.bat', '');
QuarantineFile('E:\autorun.inf', '');
QuarantineFile('E:\wgkuwjs.bat', '');
DeleteFile('C:\autorun.inf', '');
DeleteFile('C:\Users\Admin\AppData\Local\Temp\cwkeqngoojiisccoi.exe', '');
DeleteFile('C:\Users\Admin\AppData\Local\Temp\cwkeqngoojiisccoi.exe', '32');
DeleteFile('C:\Users\Admin\AppData\Local\Temp\cwkeqngoojiisccoi.exe', '64');
DeleteFile('C:\Users\Admin\AppData\Local\Temp\vobufbtaztrqzihs.exe .', '32');
DeleteFile('c:\users\admin\appdata\local\temp\vobufbtaztrqzihs.exe', '');
DeleteFile('C:\Users\Admin\AppData\Local\Temp\vobufbtaztrqzihs.exe', '32');
DeleteFile('c:\users\admin\appdata\local\temp\wgkuwjs.exe', '');
DeleteFile('C:\Users\Admin\AppData\Local\Temp\ywomcdamqpswkycsqtmkc.exe .', '32');
DeleteFile('C:\wgkuwjs.bat', '');
DeleteFile('C:\Windows\system32\jgxujjfqtrtwjwzolnfc.exe', '32');
DeleteFile('C:\Windows\system32\jgxujjfqtrtwjwzolnfc.exe', '64');
DeleteFile('C:\Windows\system32\lgvqdbvefbbcnyzmhh.exe', '32');
DeleteFile('C:\Windows\system32\vobufbtaztrqzihs.exe', '');
DeleteFile('C:\Windows\system32\vobufbtaztrqzihs.exe', '32');
DeleteFile('C:\Windows\system32\wsiesrmwyvwykwymija.exe', '32');
DeleteFile('C:\Windows\system32\wsiesrmwyvwykwymija.exe', '64');
DeleteFile('D:\autorun.inf', '');
DeleteFile('D:\wgkuwjs.bat', '');
DeleteFile('E:\autorun.inf', '');
DeleteFile('E:\wgkuwjs.bat', '');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'cougkzkkc');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'nclahznqlbvq');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'mcmckdswsjeag');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'vipchxjkdr');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\cougkzkkc', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\nclahznqlbvq', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\qiumwriomfcaiqo', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'lwbmpdnm');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'qemagxkmgvo');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'cougkzkkc');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'qiumwriomfcaiqo');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'nepgpjzebtpmta');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'vipchxjkdr');
ExecuteSysClean;
ExecuteRepair(8);
ExecuteRepair(10);
ExecuteRepair(17);
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.