Код:
begin
ClearQuarantine;
QuarantineFile('C:\ProgramData\TimeTasks\timetasks.exe', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\ZaxarGameBrowser.exe', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe', '');
QuarantineFile('C:\Users\keni1\AppData\Local\Mail.Ru\Sputnik\ptls\mailruhomesearch.exe', '');
QuarantineFile('C:\Users\keni1\AppData\Local\Amigo\Application\amigo.exe', '');
QuarantineFile('C:\Users\keni1\AppData\Roaming\LoadLeader\Updater.exe', '');
QuarantineFile('C:\Users\keni1\AppData\Roaming\taskmgr\taskmgr.exe', '');
QuarantineFile('C:\Users\keni1\AppData\Roaming\cpuminer\cpm.exe', '');
QuarantineFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe', '');
QuarantineFile('C:\Users\keni1\AppData\Local\Hostinstaller\710347742_monster.exe', '');
QuarantineFile('C:\Users\keni1\AppData\Local\SystemMonitor2016\710347742.exe', '');
QuarantineFile('C:\Users\keni1\appdata\roaming\aspackage\aspackage.exe', '');
QuarantineFile('C:\Program Files\contentprotector\condefclean.exe', '');
QuarantineFile('C:\Program Files\contentprotector\conprotsetup.exe', '');
QuarantineFile('C:\Program Files\contentprotector\contentprotectorconrol.exe', '');
QuarantineFile('C:\Program Files\contentprotector\contentprotector.exe', '');
QuarantineFile('C:\Program Files\contentprotector\contentprotectorupdate.exe', '');
QuarantineFile('C:\Program Files\contentprotector\import_root_cert.exe', '');
QuarantineFile('C:\Program Files\contentprotector\nfregdrv.exe', '');
QuarantineFile('C:\Program Files\contentprotector\nss\certutil.exe', '');
DeleteFile('C:\WINDOWS\Tasks\Uninstaller_SkipUac_keni1.job', '64');
DeleteFile('C:\Program Files (x86)\03000200-1458597806-0500-0006-000700080009\jnsh1C03.tmp', '32');
DeleteFile('C:\Program Files (x86)\03000200-1458597806-0500-0006-000700080009\knslFFF9.tmpfs', '32');
DeleteFile('C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe', '32');
DeleteFile('C:\Program Files (x86)\SFK\SSFK.exe', '32');
DeleteFile('C:\ProgramData\iWdMi\WdMan.exe', '32');
DeleteFile('C:\Program Files (x86)\03000200-1458597806-0500-0006-000700080009\hnsq3384.tmp', '32');
DeleteFile('C:\ProgramData\TimeTasks\timetasks.exe', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\ZaxarGameBrowser.exe', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe', '32');
DeleteFile('C:\Users\keni1\AppData\Local\Mail.Ru\Sputnik\ptls\mailruhomesearch.exe', '32');
DeleteFile('C:\Users\keni1\AppData\Local\Amigo\Application\amigo.exe', '32');
DeleteFile('C:\Users\keni1\AppData\Roaming\LoadLeader\Updater.exe', '32');
DeleteFile('C:\Users\keni1\AppData\Roaming\taskmgr\taskmgr.exe', '32');
DeleteFile('C:\Users\keni1\AppData\Roaming\cpuminer\cpm.exe', '32');
DeleteFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe', '32');
DeleteFile('C:\Users\keni1\AppData\Local\Mail.Ru\Sputnik\IESearchPlugin.dll', '32');
DeleteFile('C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL', '32');
DeleteFile('C:\Program Files (x86)\IObit\IObit', '32');
DeleteFile('C:\Users\keni1\AppData\Local\Hostinstaller\710347742_monster.exe', '32');
DeleteFile('C:\Users\keni1\AppData\Local\SystemMonitor2016\710347742.exe', '32');
DeleteFile('C:\Users\keni1\appdata\roaming\aspackage\aspackage.exe', '32');
DeleteFile('C:\Users\keni1\appdata\roaming\aspackage\uninstall.exe', '32');
DeleteFile('C:\Program Files\contentprotector\condefclean.exe', '32');
DeleteFile('C:\Program Files\contentprotector\conprotsetup.exe', '32');
DeleteFile('C:\Program Files\contentprotector\contentprotectorconrol.exe', '32');
DeleteFile('C:\Program Files\contentprotector\contentprotector.exe', '32');
DeleteFile('C:\Program Files\contentprotector\contentprotectorupdate.exe', '32');
DeleteFile('C:\Program Files\contentprotector\import_root_cert.exe', '32');
DeleteFile('C:\Program Files\contentprotector\libeay32.dll', '32');
DeleteFile('C:\Program Files\contentprotector\nfregdrv.exe', '32');
DeleteFile('C:\Program Files\contentprotector\nss\certutil.exe', '32');
DeleteService('gerocyni');
DeleteService('gorubezezbt');
DeleteService('LiveUpdateSvc');
DeleteService('SSFK');
DeleteService('WdMan');
DeleteService('wucotusy');
DeleteFileMask('c:\program files (x86)\iobit', '*', true);
DeleteFileMask('c:\program files (x86)\sfk', '*', true);
DeleteFileMask('c:\programdata\iwdmi', '*', true);
DeleteFileMask('c:\programdata\timetasks', '*', true);
DeleteFileMask('c:\program files (x86)\zaxar', '*', true);
DeleteFileMask('c:\users\keni1\appdata\local\mail.ru', '*', true);
DeleteFileMask('c:\users\keni1\appdata\roaming\loadleader', '*', true);
DeleteFileMask('c:\users\keni1\appdata\roaming\cpuminer', '*', true);
DeleteFileMask('c:\program files\spacesoundpro', '*', true);
DeleteFileMask('c:\progra~2\iobit', '*', true);
DeleteFileMask('c:\users\keni1\appdata\local\hostinstaller', '*', true);
DeleteFileMask('c:\users\keni1\appdata\roaming\aspackage', '*', true);
DeleteFileMask('c:\program files\contentprotector', '*', true);
DeleteDirectory('c:\program files (x86)\iobit');
DeleteDirectory('c:\program files (x86)\sfk');
DeleteDirectory('c:\programdata\iwdmi');
DeleteDirectory('c:\programdata\timetasks');
DeleteDirectory('c:\program files (x86)\zaxar');
DeleteDirectory('c:\users\keni1\appdata\local\mail.ru');
DeleteDirectory('c:\users\keni1\appdata\roaming\loadleader');
DeleteDirectory('c:\users\keni1\appdata\roaming\cpuminer');
DeleteDirectory('c:\program files\spacesoundpro');
DeleteDirectory('c:\progra~2\iobit');
DeleteDirectory('c:\users\keni1\appdata\local\hostinstaller');
DeleteDirectory('c:\users\keni1\appdata\roaming\aspackage');
DeleteDirectory('c:\program files\contentprotector');
DelBHO('{8E8F97CD-60B5-456F-A201-73065652D099}');
DelBHO('{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}');
DelBHO('{92780B25-18CC-41C8-B9BE-3C9C571A8263}');
DelBHO('{84BFE29A-8139-402a-B2A4-C23AE9E1A75F}');
ExecuteFile('schtasks.exe', '/delete /TN "Soft installer" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SystemMonitor2016" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Uninstaller_SkipUac_keni1" /F', 0, 15000, true);
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Timestasks');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'ZaxarGameBrowser');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'ZaxarLoader');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'mailruhomesearch');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'amigo');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'LoadLeader');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'cpuminer');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'SpaceSoundPro');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyParamWrite('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\Eventlog\System\ip100Avista', 'EventMessageFile', 'REG_EXPAND_SZ', '%SystemRoot%\System32\netevent.dll');
ExecuteSysClean;
ExecuteRepair(3);
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.