Код:
begin
ExecuteAVUpdate;
TerminateProcessByName('c:\users\Мариша\appdata\roaming\daemon2.exe');
TerminateProcessByName('c:\users\Мариша\appdata\roaming\gplyra\gplyra\gplyra.exe');
TerminateProcessByName('c:\users\Мариша\appdata\roaming\hpmonkey\hpmonkeysrv.exe');
StopService('HPMonkey Service');
QuarantineFile('c:\users\Мариша\appdata\roaming\daemon2.exe', '');
QuarantineFile('c:\users\Мариша\appdata\roaming\gplyra\gplyra\gplyra.exe', '');
QuarantineFile('C:\Users\Мариша\AppData\Roaming\HPMonkey\HPMonkeySrv.exe', '');
QuarantineFile('C:\Users\Мариша\AppData\Roaming\gplyra\gplyra\start.cmd', '');
QuarantineFile('C:\Users\Мариша\AppData\Local\SystemDir\nethost.exe', '');
QuarantineFile('C:\Users\Мариша\AppData\Local\svshost\svshost.exe', '');
DeleteFile('c:\users\Мариша\appdata\roaming\daemon2.exe', '32');
DeleteFile('c:\users\Мариша\appdata\roaming\gplyra\gplyra\gplyra.exe', '32');
DeleteFile('C:\Users\Мариша\AppData\Roaming\HPMonkey\HPMonkeySrv.exe', '32');
DeleteFile('C:\Users\Мариша\AppData\Roaming\gplyra\gplyra\start.cmd', '32');
DeleteFile('C:\Users\Мариша\AppData\Local\SystemDir\nethost.exe', '32');
DeleteFile('C:\Users\Мариша\AppData\Local\svshost\svshost.exe', '32');
DeleteService('HPMonkey Service');
DeleteFileMask('c:\users\мариша\appdata\roaming\gplyra', '*', true);
DeleteFileMask('c:\users\мариша\appdata\roaming\hpmonkey', '*', true);
DeleteFileMask('c:\users\мариша\appdata\local\systemdir', '*', true);
DeleteFileMask('c:\users\мариша\appdata\local\svshost', '*', true);
DeleteDirectory('c:\users\мариша\appdata\roaming\gplyra');
DeleteDirectory('c:\users\мариша\appdata\roaming\hpmonkey');
DeleteDirectory('c:\users\мариша\appdata\local\systemdir');
DeleteDirectory('c:\users\мариша\appdata\local\svshost');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "nethost task" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "svshost" /F', 0, 15000, true);
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Daemon');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'ixfynvpgnl');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'gplyra');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.