Код:
begin
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
QuarantineFile('C:\Windows\syswow64\hfnapi.dll','');
QuarantineFile('C:\Windows\system32\hfnapi.dll','');
QuarantineFile('C:\Users\Radio Silence\AppData\Roaming\QMMNRLWT4Kh.exe','');
QuarantineFile('C:\Users\Radio Silence\AppData\Roaming\5SjU9mEPdjiGu.exe','');
QuarantineFile('C:\Users\Radio Silence\AppData\Local\1E003E40-1430589631-0400-907F-001E8C26980E\bnshB8D6.exe','');
DeleteService('BAPIDRV');
StopService('webTinstMKTN84');
DeleteService('webTinstMKTN84');
StopService('innfd_1_10_0_14');
DeleteService('innfd_1_10_0_14');
DeleteService('zikosito');
DeleteService('WindowsMangerProtect');
DeleteService('mijifyhu');
DeleteService('lusotocu');
DeleteService('jedyhusi');
TerminateProcessByName('c:\users\radios~1\appdata\local\temp\isafe_00000000\uninstall.exe');
QuarantineFile('c:\users\radios~1\appdata\local\temp\isafe_00000000\uninstall.exe','');
DeleteFile('c:\users\radios~1\appdata\local\temp\isafe_00000000\uninstall.exe','32');
DeleteFile('C:\Users\Radio Silence\AppData\Local\1E003E40-1430589769-0400-907F-001E8C26980E\cnsdD405.tmp','32');
DeleteFile('C:\Users\Radio Silence\AppData\Roaming\1E003E40-1430578743-0400-907F-001E8C26980E\jnshBD36.tmp','32');
DeleteFile('C:\Users\Radio Silence\AppData\Roaming\1E003E40-1430578743-0400-907F-001E8C26980E\nsb81A6.tmpfs','32');
DeleteFile('C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe','32');
DeleteFile('C:\Users\Radio Silence\AppData\Local\1E003E40-1430589783-0400-907F-001E8C26980E\snsd2A1.tmp','32');
DeleteFile('C:\Windows\system32\drivers\innfd_1_10_0_14.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\BAPIDRV64.sys','32');
DeleteFile('C:\Windows\system32\Drivers\webTinstMKTN84.sys','32');
DeleteFile('C:\Users\Radio Silence\AppData\Local\1E003E40-1430589631-0400-907F-001E8C26980E\bnshB8D6.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','WinCheck');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','SmartWeb');
DeleteFile('C:\Users\Radio Silence\AppData\Local\SmartWeb\SmartWebHelper.exe','32');
DeleteFile('C:\Windows\Tasks\5SjU9mEPdjiGu.job','64');
DeleteFile('C:\Users\Radio Silence\AppData\Roaming\5SjU9mEPdjiGu.exe','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP1.job','64');
DeleteFile('C:\Windows\Tasks\APSnotifierPP2.job','64');
DeleteFile('C:\Windows\Tasks\APSnotifierPP3.job','64');
DeleteFile('C:\Windows\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-1-6.job','64');
DeleteFile('C:\Windows\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-1-7.job','64');
DeleteFile('C:\Windows\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-10_user.job','64');
DeleteFile('C:\Windows\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-3.job','64');
DeleteFile('C:\Windows\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-4.job','64');
DeleteFile('C:\Windows\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-5.job','64');
DeleteFile('C:\Windows\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-5_user.job','64');
DeleteFile('C:\Windows\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-6.job','64');
DeleteFile('C:\Windows\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-7.job','64');
DeleteFile('C:\Windows\Tasks\QMMNRLWT4Kh.job','64');
DeleteFile('C:\Users\Radio Silence\AppData\Roaming\QMMNRLWT4Kh.exe','32');
DeleteFile('C:\Windows\system32\Tasks\5SjU9mEPdjiGu','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP1','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP2','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP3','64');
DeleteFile('C:\Windows\system32\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-1-6','64');
DeleteFile('C:\Windows\system32\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-1-7','64');
DeleteFile('C:\Windows\system32\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-10_user','64');
DeleteFile('C:\Windows\system32\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-3','64');
DeleteFile('C:\Windows\system32\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-4','64');
DeleteFile('C:\Windows\system32\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-5','64');
DeleteFile('C:\Windows\system32\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-5_user','64');
DeleteFile('C:\Windows\system32\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-6','64');
DeleteFile('C:\Windows\system32\Tasks\b890375d-86d6-4ec7-b355-ca0e392e5336-7','64');
DeleteFile('C:\Windows\system32\Tasks\QMMNRLWT4Kh','64');
DeleteFile('C:\Windows\system32\Tasks\SmartWeb Upgrade Trigger Task','64');
DeleteFile('C:\Windows\system32\Tasks\Soft installer','64');
DeleteFile('C:\Windows\system32\Tasks\{B5D33D40-D63D-4724-90F8-4DCF533F427D}','64');
DeleteFile('C:\Windows\system32\Tasks\{C332676C-9DCD-4EDE-B280-EC57B727C69A}','64');
DeleteFile('C:\Windows\system32\Tasks\{C45F4872-1CDF-4C9F-9F28-B9F7DD9442FA}','64');
DeleteFile('C:\Windows\system32\hfnapi.dll','32');
DeleteFile('C:\Windows\syswow64\hfnapi.dll','32');
ExecuteSysClean;
ExecuteRepair(2);
RebootWindows(true);
end.