Код:
begin
TerminateProcessByName('C:\Program Files\Content Defender\cd.exe');
TerminateProcessByName('c:\users\likvidator\appdata\roaming\daemon2.exe');
TerminateProcessByName('c:\windows\syswow64\searchprotectservice.exe');
StopService('cd');
StopService('SPS');
StopService('condef');
QuarantineFileF('C:\Users\Likvidator\AppData\Local\epohbbbfeldaodfhfljalhiilifmneie', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js', true, '', 0 , 0);
QuarantineFile('C:\Program Files\Content Defender\cd.exe', '');
QuarantineFile('c:\users\likvidator\appdata\roaming\daemon2.exe', '');
QuarantineFile('c:\windows\syswow64\searchprotectservice.exe', '');
QuarantineFile('C:\Windows\system32\drivers\condef.sys', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QMUdisk64.sys', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\softaal64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\tsskx64.sys', '');
QuarantineFile('C:\Windows\system32\GroupPolicy\Machine\Registry.pol', '');
QuarantineFile('C:\Windows\system32\GroupPolicy\Machine\R', '');
QuarantineFile('C:\Users\Likvidator\AppData\Local\epohbbbfeldaodfhfljalhiilifmneie\stub.exe', '');
QuarantineFile('D:\Mail.Ru\DwarChrome\dwarclient.exe', '');
QuarantineFile('C:\Program Files (x86)\Sense\d8b5485b-d489-4c81-9042-bba41162ccb9-5.exe', '');
QuarantineFile('C:\PROGRA~1\COMMON~1\System\SysMenu.dll', '');
QuarantineFile('C:\Program Files (x86)\ShopperPro\JSDriver\1.42.1.2000\jsdrv.exe', '');
QuarantineFile('C:\Users\Likvidator\AppData\Roaming\istartsurf\UninstallManager.exe', '');
QuarantineFile('C:\Windows\system32\searchprotectservice.exe', '');
QuarantineFile('C:\Program Files\content defender\condefsetup.exe', '');
QuarantineFile('C:\Program Files\content defender\libeay32.dll', '');
QuarantineFile('C:\Program Files\content defender\ssleay32.dll', '');
DeleteFile('C:\Windows\Tasks\d8b5485b-d489-4c81-9042-bba41162ccb9-5.job', '64');
DeleteFile('C:\Windows\Tasks\d8b5485b-d489-4c81-9042-bba41162ccb9-5_user.job', '64');
DeleteFile('C:\Program Files\Content Defender\cd.exe', '32');
DeleteFile('c:\users\likvidator\appdata\roaming\daemon2.exe', '32');
DeleteFile('c:\windows\syswow64\searchprotectservice.exe', '32');
DeleteFile('C:\Windows\system32\drivers\condef.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QMUdisk64.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\softaal64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\tsskx64.sys', '32');
DeleteFile('C:\Windows\system32\GroupPolicy\Machine\Registry.pol', '32');
DeleteFile('C:\Windows\system32\GroupPolicy\Machine\R', '32');
DeleteFile('C:\Users\Likvidator\AppData\Local\epohbbbfeldaodfhfljalhiilifmneie\stub.exe', '32');
DeleteFile('C:\Users\Likvidator\AppData\Local\epohbbbfeldaodfhfljalhiilifmneie\config.json', '32');
DeleteFile('C:\Users\Likvidator\AppData\Local\Mail.Ru\Sputnik\ptls\mailruhomesearch.exe', '32');
DeleteFile('C:\ProgramData\qoPqEmuwQe\KGnmkNoEY5.bat', '32');
DeleteFile('D:\Mail.Ru\DwarChrome\dwarclient.exe', '32');
DeleteFile('C:\Program Files (x86)\Sense\d8b5485b-d489-4c81-9042-bba41162ccb9-5.exe', '32');
DeleteFile('C:\PROGRA~1\COMMON~1\System\SysMenu.dll', '32');
DeleteFile('C:\Program Files (x86)\ShopperPro\JSDriver\1.42.1.2000\jsdrv.exe', '32');
DeleteFile('C:\Users\Likvidator\AppData\Roaming\istartsurf\UninstallManager.exe', '32');
DeleteFile('C:\Windows\system32\searchprotectservice.exe', '32');
DeleteFile('C:\Program Files\content defender\condefsetup.exe', '32');
DeleteFile('C:\Program Files\content defender\libeay32.dll', '32');
DeleteFile('C:\Program Files\content defender\ssleay32.dll', '32');
DeleteService('cd');
DeleteService('SPS');
DeleteService('condef');
DeleteService('QMUdisk');
DeleteService('softaal');
DeleteService('TSSKX64');
DeleteFileMask('C:\Program Files\Content Defender', '*', true);
DeleteFileMask('C:\Program Files (x86)\Tencent', '*', true);
DeleteFileMask('C:\Users\Likvidator\AppData\Local\epohbbbfeldaodfhfljalhiilifmneie', '*', true);
DeleteFileMask('C:\Users\Likvidator\AppData\Local\Mail.Ru', '*', true);
DeleteFileMask('D:\Mail.Ru', '*', true);
DeleteFileMask('C:\Program Files (x86)\Sense', '*', true);
DeleteFileMask('C:\Program Files (x86)\ShopperPro', '*', true);
DeleteFileMask('C:\Users\Likvidator\AppData\Roaming\istartsurf', '*', true);
DeleteDirectory('C:\Program Files\Content Defender');
DeleteDirectory('C:\Program Files (x86)\Tencent');
DeleteDirectory('C:\Users\Likvidator\AppData\Local\epohbbbfeldaodfhfljalhiilifmneie');
DeleteDirectory('C:\Users\Likvidator\AppData\Local\Mail.Ru');
DeleteDirectory('D:\Mail.Ru');
DeleteDirectory('C:\Program Files (x86)\Sense');
DeleteDirectory('C:\Program Files (x86)\ShopperPro');
DeleteDirectory('C:\Users\Likvidator\AppData\Roaming\istartsurf');
ExecuteFile('schtasks.exe', '/delete /TN "d8b5485b-d489-4c81-9042-bba41162ccb9-5" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "d8b5485b-d489-4c81-9042-bba41162ccb9-5_user" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SMupdate2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SMupdate3" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "UNELEVATE_25398" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{5035EB6C-CEE1-4922-B9D4-9D20E3E45414}" /F', 0, 15000, true);
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'C');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Daemon');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\epohbbbfeldaodfhfljalhiilifmneie', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mailruhomesearch', 'command');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
Компьютер перезагрузится.