Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
TerminateProcessByName('C:\Users\Obanas\AppData\Local\Microsoft\Macromed\Flash Player\Updater Startup Utility\C34C06FC-54D3-4BA8-A26A-04A3DEDFCFFF.exe');
QuarantineFile('C:\Users\Obanas\AppData\Local\Microsoft\Macromed\Flash Player\Updater Startup Utility\C34C06FC-54D3-4BA8-A26A-04A3DEDFCFFF.exe', '');
QuarantineFile('C:\Users\Obanas\appdata\locallow\searchgo\searchgo.dll', '');
QuarantineFileF('C:\Users\Obanas\appdata\locallow\searchgo', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFile('C:\Users\Obanas\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт.lnk', '');
QuarantineFile('C:\Users\Obanas\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk', '');
QuarantineFile('C:\Users\Public\Desktop\Aliexpress.lnk', '');
QuarantineFile('C:\Users\Public\Desktop\Black Desert.lnk', '');
QuarantineFile('C:\Users\Public\Desktop\Booking.com.lnk', '');
QuarantineFile('C:\Users\Public\Desktop\Forge of Empires.lnk', '');
QuarantineFile('C:\Users\Public\Desktop\Star Conflict.lnk', '');
QuarantineFile('C:\Users\Public\Desktop\War Thunder.lnk', '');
QuarantineFile('C:\Users\Public\Desktop\Новости.lnk', '');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Aliexpress.lnk', '');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Black Desert.lnk', '');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Booking.com.lnk', '');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Forge of Empires.lnk', '');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Star Conflict.lnk', '');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\War Thunder.lnk', '');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Новости.lnk', '');
QuarantineFileF('c:\programdata\krb updater utility', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\program files (x86)\kinoroom browser', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFile('C:\ProgramData\KRB Updater Utility\krbupdater.exe', '');
QuarantineFile('C:\Program Files (x86)\Kinoroom Browser\krbrowser.exe', '');
QuarantineFile('C:\Users\Obanas\AppData\Local\Microsoft\E0E0CB4D37B54A71311CF580B7A9ED55\BEC271FD5EFC9D83522D90DEA26367D1.exe', '');
DeleteFile('C:\Users\Obanas\AppData\Local\Microsoft\E0E0CB4D37B54A71311CF580B7A9ED55\BEC271FD5EFC9D83522D90DEA26367D1.exe');
DeleteFile('C:\Users\Obanas\AppData\Local\Microsoft\Macromed\Flash Player\Updater Startup Utility\C34C06FC-54D3-4BA8-A26A-04A3DEDFCFFF.exe');
DeleteFile('C:\Users\Obanas\appdata\locallow\searchgo\searchgo.dll');
DeleteFile('C:\ProgramData\KRB Updater Utility\krbupdater.exe', '32');
DeleteFile('C:\Program Files (x86)\Kinoroom Browser\krbrowser.exe', '32');
DeleteFile('C:\Users\Obanas\AppData\Local\Microsoft\E0E0CB4D37B54A71311CF580B7A9ED55\BEC271FD5EFC9D83522D90DEA26367D1.exe', '32');
ExecuteFile('schtasks.exe', '/delete /TN "Kinoroom Browser" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\6367D12AED09D22538D9CFE5DFBEC271" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\6367D12AED09D22538D9CFE5DFBEC271SB" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\KRBUUS\KRB Updater Utility Service" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\KRBUUS\KRBLNKRUN" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\6367D12AED09D22538D9CFE5DFBEC271" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\6367D12AED09D22538D9CFE5DFBEC271SB" /F', 0, 15000, true);
DeleteFileMask('C:\Users\Obanas\appdata\locallow\searchgo', '*', true);
DeleteFileMask('c:\programdata\krb updater utility', '*', true);
DeleteFileMask('c:\program files (x86)\kinoroom browser', '*', true);
DeleteDirectory('C:\Users\Obanas\appdata\locallow\searchgo');
DeleteDirectory('c:\programdata\krb updater utility');
DeleteDirectory('c:\program files (x86)\kinoroom browser');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'C93AB876-3A7C-4DCF-BA14-A8383D5DFE8D');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', '6367D12AED09D22538D9CFE5DFBEC271SB');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run-', 'fzjwdjfcil');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run-', 'KRB Updater Utility');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.