Код:
begin
QuarantineFile('C:\Users\Andrew\AppData\Local\Microsoft\Macromed\Flash Player\Updater Startup Utility\B2D03AE7-55A1-4256-A2AA-632246C839D2.exe', '');
QuarantineFile('C:\Users\Andrew\AppData\Local\Microsoft\Extensions\extsetup.exe', '');
QuarantineFile('C:\ProgramData\service.exe', '');
QuarantineFile('C:\Users\Andrew\AppData\Roaming\svrupg.exe', '');
QuarantineFile('C:\Program Files\NewExt\nssm.exe', '');
QuarantineFile('C:\Program Files\Windows Screen Manager\Windows screen manage updater.exe', '');
QuarantineFile('C:\Users\Andrew\AppData\LocalLow\SearchGo\searchgo.dll', '');
QuarantineFile('C:\PROGRA~1\AFAMVY~1\Xagdalt.bat', '');
QuarantineFile('C:\ProgramData\KRB Updater Utility\krbupdater.exe', '');
QuarantineFile('C:\Program Files (x86)\Kinoroom Browser\krbrowser.exe', '');
DeleteFile('C:\Users\Andrew\AppData\Local\Microsoft\Macromed\Flash Player\Updater Startup Utility\B2D03AE7-55A1-4256-A2AA-632246C839D2.exe', '32');
DeleteFile('C:\Users\Andrew\AppData\Local\Microsoft\Extensions\extsetup.exe', '32');
DeleteFile('C:\ProgramData\service.exe', '32');
DeleteFile('C:\Users\Andrew\AppData\Roaming\svrupg.exe', '32');
DeleteFile('C:\Program Files\NewExt\nssm.exe', '32');
DeleteFile('C:\Program Files\Windows Screen Manager\Windows screen manage updater.exe', '32');
DeleteFile('C:\Users\Andrew\AppData\LocalLow\SearchGo\searchgo.dll', '32');
DeleteFile('C:\PROGRA~1\AFAMVY~1\Xagdalt.bat', '32');
DeleteFile('C:\ProgramData\KRB Updater Utility\krbupdater.exe', '32');
DeleteFile('C:\Program Files (x86)\Kinoroom Browser\krbrowser.exe', '32');
DeleteFileMask('c:\users\andrew\appdata\local\microsoft\macromed', '*', true);
DeleteFileMask('c:\users\andrew\appdata\local\microsoft\extensions', '*', true);
DeleteFileMask('c:\program files\windows screen manager', '*', true);
DeleteFileMask('c:\users\andrew\appdata\locallow\searchgo', '*', true);
DeleteFileMask('c:\progra~1\afamvy~1', '*', true);
DeleteFileMask('c:\programdata\krb updater utility', '*', true);
DeleteFileMask('c:\program files (x86)\kinoroom browser', '*', true);
DeleteDirectory('c:\users\andrew\appdata\local\microsoft\macromed');
DeleteDirectory('c:\program files\windows screen manager');
DeleteDirectory('c:\users\andrew\appdata\locallow\searchgo');
DeleteDirectory('c:\progra~1\afamvy~1');
DeleteDirectory('c:\programdata\krb updater utility');
DeleteDirectory('c:\program files (x86)\kinoroom browser');
DelBHO('{598AEFC6-DD3C-4A63-9AC3-53FCF6155931}');
DelBHO('{2BC46CFA-4B00-4193-A7BD-6AD1D0BCB5BC}');
ExecuteFile('schtasks.exe', '/delete /TN "Lhkawrec" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "extsetup" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "KRB Updater Utility Service" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "KRBLNKRUN" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SafeBrowser" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "AF4C2EF7D-0226-4400-B50C-97E05CF260C9" /F', 0, 15000, true);
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'F4C2EF7D-0226-4400-B50C-97E05CF260C9');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'SafeBrowser');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\Eventlog\Application\GoogleChromeUpService', 'EventMessageFile');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\Eventlog\Application\GoogleChromeUpSvc', 'EventMessageFile');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'WINDOWS_SCREEN_MANAGER_UPDATER_1');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.