Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
QuarantineFile('C:\ProgramData\Windows\svchost.vbs', '');
QuarantineFile('C:\ProgramData\Windows\svchot.exe', '');
QuarantineFile('C:\Users\Андрей\AppData\Local\Temp\csrss\scheduled.exe', '');
QuarantineFile('C:\Users\Андрей\appdata\local\temp\csrss\wup\xarch\wup.exe', '');
QuarantineFile('C:\Windows\rss\csrss.exe', '');
QuarantineFile('C:\Windows\System32\drivers\Winmon.sys', '');
QuarantineFileF('c:\windows\rss', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', false, '', 0 , 0);
DeleteFile('C:\ProgramData\Windows\svchost.vbs', '');
DeleteFile('C:\ProgramData\Windows\svchot.exe', '64');
DeleteFile('C:\Users\Андрей\appdata\local\temp\csrss\scheduled.exe', '');
DeleteFile('C:\Users\Андрей\AppData\Local\Temp\csrss\scheduled.exe', '64');
DeleteFile('C:\Users\Андрей\appdata\local\temp\csrss\wup\xarch\wup.exe', '');
DeleteFile('C:\Windows\rss\csrss.exe', '');
DeleteFile('C:\Windows\rss\csrss.exe', '32');
DeleteFile('C:\Windows\rss\csrss.exe', '64');
DeleteFile('C:\Windows\System32\drivers\Winmon.sys', '64');
DeleteService('Winmon');
DeleteFileMask('C:\ProgramData\Windows', '*', true);
DeleteFileMask('c:\users\андрей\appdata\local\temp\csrss', '*', true);
DeleteFileMask('c:\windows\rss', '*', true);
DeleteDirectory('C:\ProgramData\Windows');
DeleteDirectory('c:\users\андрей\appdata\local\temp\csrss');
DeleteDirectory('c:\windows\rss');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'PurplePaper', '32');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'PurplePaper', '64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Андрей^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^explorer.lnk', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QHSafeTray', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ScrewDrivers RDP Plugin', 'x64');
DeleteSchedulerTask('{D5DCF572-B893-4C30-807F-EAB60EEF352D}');
DeleteSchedulerTask('csrss');
DeleteSchedulerTask('ScheduledUpdate');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 3, 3, true);
RebootWindows(true);
end.
Компьютер перезагрузится.