Код:
begin
QuarantineFile('C:\Program Files (x86)\Microsoft Data\InstallAddons.exe','');
QuarantineFile('C:\Users\anders\AppData\Roaming\FHIGIC.exe','');
QuarantineFile('C:\Users\anders\AppData\Local\03DE0294-1426628399-0575-8806-440700080009\bnsq4991.exe','');
QuarantineFile('C:\Users\anders\AppData\Local\03DE0294-1426628411-0575-8806-440700080009\cnsv77B3.tmp','');
StopService('tigozoce');
DeleteService('tigozoce');
StopService('serveras');
DeleteService('serveras');
StopService('IHProtect Service');
DeleteService('IHProtect Service');
TerminateProcessByName('c:\users\anders\appdata\local\mbot_ru_86\upmbot_ru_86.exe');
QuarantineFile('c:\users\anders\appdata\local\mbot_ru_86\upmbot_ru_86.exe','');
TerminateProcessByName('c:\program files (x86)\xtab\protectservice.exe');
QuarantineFile('c:\program files (x86)\xtab\protectservice.exe','');
TerminateProcessByName('c:\users\anders\appdata\local\03de0294-1426628411-0575-8806-440700080009\cnsv77b3.tmp');
QuarantineFile('c:\users\anders\appdata\local\03de0294-1426628411-0575-8806-440700080009\cnsv77b3.tmp','');
TerminateProcessByName('c:\users\anders\appdata\roaming\aspackage\assrv.exe');
QuarantineFile('c:\users\anders\appdata\roaming\aspackage\assrv.exe','');
TerminateProcessByName('c:\users\anders\appdata\local\03de0294-1426628411-0575-8806-440700080009\ansq75bf.exe');
QuarantineFile('c:\users\anders\appdata\local\03de0294-1426628411-0575-8806-440700080009\ansq75bf.exe','');
TerminateProcessByName('c:\program files (x86)\cinemap-1.9cv05.03\2300726e-d013-4e97-93b8-82cdb2191e24-10.exe');
QuarantineFile('c:\program files (x86)\cinemap-1.9cv05.03\2300726e-d013-4e97-93b8-82cdb2191e24-10.exe','');
TerminateProcessByName('c:\program files (x86)\cinemap-1.9cv05.03\2300726e-d013-4e97-93b8-82cdb2191e24-1-6.exe');
QuarantineFile('c:\program files (x86)\cinemap-1.9cv05.03\2300726e-d013-4e97-93b8-82cdb2191e24-1-6.exe','');
DeleteFile('c:\program files (x86)\cinemap-1.9cv05.03\2300726e-d013-4e97-93b8-82cdb2191e24-1-6.exe','32');
DeleteFile('c:\program files (x86)\cinemap-1.9cv05.03\2300726e-d013-4e97-93b8-82cdb2191e24-10.exe','32');
DeleteFile('c:\users\anders\appdata\local\03de0294-1426628411-0575-8806-440700080009\ansq75bf.exe','32');
DeleteFile('c:\users\anders\appdata\roaming\aspackage\assrv.exe','32');
DeleteFile('c:\users\anders\appdata\local\03de0294-1426628411-0575-8806-440700080009\cnsv77b3.tmp','32');
DeleteFile('c:\program files (x86)\xtab\protectservice.exe','32');
DeleteFile('c:\users\anders\appdata\local\mbot_ru_86\upmbot_ru_86.exe','32');
DeleteFile('C:\Users\anders\AppData\Local\03DE0294-1426628411-0575-8806-440700080009\cnsv77B3.tmp','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','upmbot_ru_86.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','WinCheck');
DeleteFile('C:\Users\anders\AppData\Local\03DE0294-1426628399-0575-8806-440700080009\bnsq4991.exe','32');
DeleteFile('C:\Windows\Tasks\2300726e-d013-4e97-93b8-82cdb2191e24-1-6.job','64');
DeleteFile('C:\Windows\Tasks\2300726e-d013-4e97-93b8-82cdb2191e24-1-7.job','64');
DeleteFile('C:\Windows\Tasks\2300726e-d013-4e97-93b8-82cdb2191e24-10_user.job','64');
DeleteFile('C:\Windows\Tasks\2300726e-d013-4e97-93b8-82cdb2191e24-3.job','64');
DeleteFile('C:\Windows\Tasks\2300726e-d013-4e97-93b8-82cdb2191e24-5.job','64');
DeleteFile('C:\Windows\Tasks\2300726e-d013-4e97-93b8-82cdb2191e24-5_user.job','64');
DeleteFile('C:\Windows\Tasks\2300726e-d013-4e97-93b8-82cdb2191e24-6.job','64');
DeleteFile('C:\Windows\Tasks\2300726e-d013-4e97-93b8-82cdb2191e24-7.job','64');
DeleteFile('C:\Windows\Tasks\FHIGIC.job','64');
DeleteFile('C:\Users\anders\AppData\Roaming\FHIGIC.exe','32');
DeleteFile('C:\Windows\system32\Tasks\2300726e-d013-4e97-93b8-82cdb2191e24-1-6','64');
DeleteFile('C:\Windows\system32\Tasks\2300726e-d013-4e97-93b8-82cdb2191e24-1-7','64');
DeleteFile('C:\Windows\system32\Tasks\2300726e-d013-4e97-93b8-82cdb2191e24-10_user','64');
DeleteFile('C:\Windows\system32\Tasks\2300726e-d013-4e97-93b8-82cdb2191e24-5_user','64');
DeleteFile('C:\Windows\system32\Tasks\chrome5','64');
DeleteFile('C:\Windows\system32\Tasks\chrome5_logon','64');
DeleteFile('C:\Program Files (x86)\Microsoft Data\InstallAddons.exe','32');
ExecuteSysClean;
RebootWindows(true);
end.