Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
TerminateProcessByName('c:\users\Толик\appdata\roaming\vnlgp\vnlgp\vnlgp.exe');
TerminateProcessByName('c:\users\Толик\appdata\local\temp\00018959\msiql.exe');
StopService('KuaiZipDrive');
StopService('Hayzumflex');
StopService('MailRuYandex');
StopService('iThemes5');
StopService('HewlettPackardGUMBDtmp');
StopService('ed2kidle');
QuarantineFile('C:\Users\Толик\appdata\roaming\gplyra\gplyra\gplyra.exe','');
QuarantineFile('C:\Users\Толик\appdata\roaming\gplyra\gplyra.exe','');
QuarantineFile('C:\Program Files (x86)\Common Files\Zimbam\uninstall.dat','');
QuarantineFile('C:\Program Files (x86)\Common Files\Zimbam\uninstall.exe','');
QuarantineFile('C:\Users\Толик\AppData\Local\SystemMonitor2016\2628703937.exe','');
QuarantineFile('C:\Users\Толик\AppData\Local\Hostinstaller\2628703937_installcube.exe','');
QuarantineFile('C:\ProgramData\SearchModule\smhe.js','');
QuarantineFile('C:\ProgramData\smp2.exe','');
QuarantineFile('C:\Users\Толик\AppData\Roaming\Event Monitor\em.exe','');
QuarantineFile('C:\ProgramData\Hayzumflex\QvoFinlight.reg','');
QuarantineFile('C:\Program Files (x86)\PC Clean Plus\PCCleanPlus.exe','');
QuarantineFile('C:\PROGRA~1\6A8C~1\X86\Update.exe','');
QuarantineFile('C:\Program Files (x86)\Giqiiedaneqoch\shizery.exe','');
QuarantineFile('C:\Program Files (x86)\Smart Application Controller\smappscontroller.exe','');
QuarantineFile('C:\Program Files (x86)\Clerbespdremerle\kogght.exe','');
QuarantineFile('C:\Program Files (x86)\Gradischiveght Cloud\local64spl.dll','');
QuarantineFile('C:\Users\Толик\AppData\Roaming\vnlgp\vnlgp\start.cmd','');
QuarantineFile('C:\Users\Толик\AppData\Roaming\WinSnare\WinSnare.dll','');
QuarantineFile('C:\Program Files\????\X86\kuaizipUpdateChecker.dll','');
QuarantineFile('C:\Program Files (x86)\Giqiiedaneqoch\arbHst.dll','');
QuarantineFile('C:\Program Files (x86)\WinArcher\Archer.dll','');
QuarantineFile('C:\ProgramData\Apple\Lockdown\InstallInfo.dll','');
QuarantineFile('C:\Users\Толик\AppData\Local\Temp\fd-27b43-1a7-d75a2-f56cbbe506476\ECFWCBVFGQ.exe','');
QuarantineFile('C:\Users\Толик\AppData\Local\Temp\fd-27b43-1a7-d75a2-f56cbbe506476\NUKHIBZGFN.exe','');
QuarantineFile('C:\WINDOWS\system32\drivers\heejmknn.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\hcszvtwq.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\ggfemfxc.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\gdmdmlwc.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\csetvjhp.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\azdqabzp.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\KuaiZipDrive.sys','');
QuarantineFile('C:\ProgramData\Hayzumflex\Hayzumflex.exe','');
QuarantineFile('C:\Program Files (x86)\Giqiiedaneqoch\GiqiiedaneqochDPower.dll','');
QuarantineFile('C:\Program Files (x86)\amuleCe\ed2k.exe','');
QuarantineFile('c:\programdata\winsapsvc\winsap.dll','');
QuarantineFile('C:\Program Files (x86)\Yandex\MailRuYandex.dll','');
QuarantineFile('C:\Program Files (x86)\Tooltony\Application\chrome_child.dll','');
QuarantineFile('C:\Program Files (x86)\Tooltony\Application\chrome.dll','');
QuarantineFile('C:\Program Files (x86)\GUMBD07.tmp\HewlettPackardGUMBDtmp.dll','');
QuarantineFile('c:\program files (x86)\gub\gubzl.dll','');
QuarantineFile('C:\Program Files (x86)\Common Files\Services\iThemes.dll','');
QuarantineFile('c:\users\Толик\appdata\roaming\vnlgp\vnlgp\vnlgp.exe','');
QuarantineFile('c:\users\Толик\appdata\local\temp\00018959\msiql.exe','');
DeleteFile('C:\Program Files (x86)\PC Clean Plus\PCCleanPlus.exe');
DeleteFile('c:\users\Толик\appdata\local\temp\00018959\msiql.exe','32');
DeleteFile('c:\users\Толик\appdata\roaming\vnlgp\vnlgp\vnlgp.exe','32');
DeleteFile('C:\Program Files (x86)\Common Files\Services\iThemes.dll','32');
DeleteFile('C:\Program Files (x86)\GUMBD07.tmp\HewlettPackardGUMBDtmp.dll','32');
DeleteFile('C:\Program Files (x86)\Yandex\MailRuYandex.dll','32');
DeleteFile('C:\Program Files (x86)\amuleCe\ed2k.exe','32');
DeleteFile('C:\Program Files (x86)\Giqiiedaneqoch\GiqiiedaneqochDPower.dll','32');
DeleteFile('C:\ProgramData\Hayzumflex\Hayzumflex.exe','32');
DeleteFile('C:\WINDOWS\system32\drivers\KuaiZipDrive.sys','32');
DeleteFile('C:\Users\Толик\AppData\Local\Temp\fd-27b43-1a7-d75a2-f56cbbe506476\NUKHIBZGFN.exe','32');
DeleteFile('C:\Users\Толик\AppData\Local\Temp\fd-27b43-1a7-d75a2-f56cbbe506476\ECFWCBVFGQ.exe','32');
DeleteFile('C:\ProgramData\Apple\Lockdown\InstallInfo.dll','32');
DeleteFile('C:\Program Files (x86)\WinArcher\Archer.dll','32');
DeleteFile('C:\Program Files (x86)\Giqiiedaneqoch\arbHst.dll','32');
DeleteFile('C:\Program Files (x86)\Gub\GubZL.dll','32');
DeleteFile('C:\ProgramData\WinSAPSvc\WinSAP.dll','32');
DeleteFile('C:\Users\Толик\AppData\Roaming\WinSnare\WinSnare.dll','32');
DeleteFile('C:\Program Files (x86)\Clerbespdremerle\kogght.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\Bozoty Agent','64');
DeleteFile('C:\Program Files (x86)\Smart Application Controller\smappscontroller.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\CheckControllerUpdatesUA','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Driqeghtnerwi','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Gradischiveght Cloud','64');
DeleteFile('C:\Program Files (x86)\Giqiiedaneqoch\shizery.exe','32');
DeleteFile('C:\PROGRA~1\6A8C~1\X86\Update.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\KuaiZip_Update','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Milimili','64');
DeleteFile('C:\WINDOWS\system32\Tasks\PC Clean Plus','64');
DeleteFile('C:\ProgramData\Hayzumflex\QvoFinlight.reg','32');
DeleteFile('C:\WINDOWS\system32\Tasks\psv_Cofphase','64');
DeleteFile('C:\Users\Толик\AppData\Roaming\Event Monitor\em.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\RunAtStartup','64');
DeleteFile('C:\ProgramData\smp2.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\SMW_P','64');
DeleteFile('C:\ProgramData\SearchModule\smhe.js','32');
DeleteFile('C:\WINDOWS\system32\Tasks\SMW_UpdateTask_Time_3131353033363430352d325b573423416c45555a2a6c','64');
DeleteFile('C:\Users\Толик\AppData\Local\Hostinstaller\2628703937_installcube.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\Soft installer','64');
DeleteFile('C:\Users\Толик\AppData\Local\SystemMonitor2016\2628703937.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\SystemMonitor2016','64');
DeleteFile('C:\Program Files (x86)\Common Files\Zimbam\uninstall.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\{5EDBA36C-8FDF-4B51-B9A8-A015BA9A851B}','64');
DeleteFile('C:\Program Files (x86)\Common Files\Zimbam\uninstall.dat','32');
DeleteFile('C:\Users\Толик\appdata\roaming\gplyra\gplyra.exe','32');
DeleteFile('C:\Users\Толик\appdata\roaming\gplyra\gplyra\gplyra.exe','32');
DeleteFile('C:\Program Files\????\x86\kuaizipupdatechecker.dll','32');
DelBHO('{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}');
DelBHO('{a6c63b7f-2171-47fa-ab34-e64c4737169d}');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','NUKHIBZGFN.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ECFWCBVFGQ.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\APPLEsvr\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Archer\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Bvertaindubsp\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\GubZL\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\KuaizipUpdateChecker\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\WinSAPSvc\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\WinSnare\Parameters','ServiceDll');
DeleteService('KuaiZipDrive');
DeleteService('Hayzumflex');
DeleteService('GiqiiedaneqochDPower');
DeleteService('FirefoxDL');
DeleteService('MailRuYandex');
DeleteService('iThemes5');
DeleteService('HewlettPackardGUMBDtmp');
DeleteService('ed2kidle');
ExecuteSysClean;
ExecuteRepair(3);
ExecuteRepair(4);
RebootWindows(true);
end.
После перезагрузки выполните скрипт: