Код:
begin
TerminateProcessByName('c:\program files (x86)\bikaqrssreader\bikaq.exe');
TerminateProcessByName('c:\program files (x86)\amulecexx\ed2k.exe');
TerminateProcessByName('c:\program files (x86)\firefox\bin\firefoxupdate.exe');
TerminateProcessByName('c:\programdata\hayzumflex\hayzumflex.exe');
TerminateProcessByName('c:\program files (x86)\elex-tech\yac\isafesvc.exe');
TerminateProcessByName('c:\program files (x86)\elex-tech\yac\isafesvc2.exe');
TerminateProcessByName('c:\program files (x86)\elex-tech\yac\isafetray.exe');
TerminateProcessByName('C:\Program Files\Common Files\Noobzo\GNUpdate\smu.exe');
TerminateProcessByName('c:\program files (x86)\system tools\systemtools.exe');
StopService('ed2kidle');
StopService('FirefoxU');
StopService('Hayzumflex');
StopService('iSafeService');
StopService('iThemes5');
StopService('SMUpd');
StopService('BirdjobSU');
StopService('iSafeKrnl');
StopService('iSafeKrnlMon');
StopService('iSafeKrnlR3');
StopService('SMUpdd');
QuarantineFileF('c:\program files (x86)\firefox', '*.exe', true, '', 0 , 0);
QuarantineFile('c:\program files (x86)\bikaqrssreader\bikaq.exe', '');
QuarantineFile('c:\program files (x86)\amulecexx\ed2k.exe', '');
QuarantineFile('c:\program files (x86)\firefox\bin\firefoxupdate.exe', '');
QuarantineFile('c:\programdata\hayzumflex\hayzumflex.exe', '');
QuarantineFile('c:\program files (x86)\elex-tech\yac\isafesvc.exe', '');
QuarantineFile('c:\program files (x86)\elex-tech\yac\isafesvc2.exe', '');
QuarantineFile('c:\program files (x86)\elex-tech\yac\isafetray.exe', '');
QuarantineFile('C:\Program Files\Common Files\Noobzo\GNUpdate\smu.exe', '');
QuarantineFile('c:\program files (x86)\system tools\systemtools.exe', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSvc.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\isafeupbiz.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iCommu.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iImportLib.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\isafepxy.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\isaferpt.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\sqlite3.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\libcurl.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\curlpp.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\LIBEAY32.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\SSLEAY32.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\ipcproxy.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSvc2.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafenpf.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafebs.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeAdless.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlCall.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMonCall.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeDisp.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeBase.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iCommon.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\isafemc.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\libpng.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iTPNodisturb.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iTPProtect.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iTPDesk.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iTPFloaty.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iTPPush.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iTPMsgCenter.dll', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iTPAutoClean.dll', '');
QuarantineFile('C:\Program Files\Common Files\Noobzo\GNUpdate\smci32.dll', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Services\iThemes.dll', '');
QuarantineFile('c:\users\olga\appdata\roaming\winsapsvc\winsap.dll', '');
QuarantineFile('c:\program files (x86)\winarcher\archer.dll', '');
QuarantineFile('c:\program files (x86)\rerkuy\anthost.dll', '');
QuarantineFile('C:\Users\Olga\AppData\Local\Temp\1\BaofengUpdate_U.exe', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys', '');
QuarantineFile('C:\Program Files\Common Files\Noobzo\GNUpdate\smw.sys', '');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\iSafeKrnlBoot.sys', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys', '');
QuarantineFile('C:\ProgramData\Hayzumflex\X-Rannix.dll', '');
QuarantineFile('C:\Users\Olga\AppData\Roaming\WinSnare\WinSnare.dll', '');
QuarantineFile('C:\Users\Olga\AppData\Roaming\vnlgp\vnlgp.exe', '');
QuarantineFile('C:\ProgramData\Hayzumflex\Hotsoft.dll', '');
QuarantineFile('C:\Program Files (x86)\Grotersp Mapper\local64spl.dll', '');
QuarantineFile('C:\ProgramData\SearchModule\smhe.js', '');
QuarantineFile('C:\Program Files (x86)\Rerkuy\rerjupy.exe', '');
QuarantineFile('C:\Users\Olga\AppData\Local\BrowserAir\48.0.0.0\updater.exe', '');
QuarantineFile('"C:\Program Files (x86)\MIO\MIO.exe" -bindurl http://api.mhttxtv.com/hitachixhts543232a7a384_e2034233dw98asdw98asx.exe cmd=', '');
QuarantineFile('C:\ProgramData\smp2.exe install1 "http://www%2dsearching.com/?prd=set_epf&s=h27zamobl20544bu, ab8da6c7-cf46-449a-8346-333b8b8fe59d, " Search', '');
QuarantineFile('C:\ProgramData\smp2.exe', '');
QuarantineFile('C:\ProgramData\wintools\WintoolUprI.exe', '');
QuarantineFile('C:\Program Files (x86)\Common Files\BioLa\uninstall.exe', '');
QuarantineFile('C:\Program Files (x86)\Common Files\BioLa\uninstall.dat', '');
DeleteFile('C:\WINDOWS\Tasks\SMW_UpdateTask_Time_3238333332343030392d5a556c6c4a5a575750414134.job', '64');
DeleteFile('c:\program files (x86)\bikaqrssreader\bikaq.exe', '32');
DeleteFile('c:\program files (x86)\amulecexx\ed2k.exe', '32');
DeleteFile('c:\program files (x86)\firefox\bin\firefoxupdate.exe', '32');
DeleteFile('c:\programdata\hayzumflex\hayzumflex.exe', '32');
DeleteFile('c:\program files (x86)\elex-tech\yac\isafesvc.exe', '32');
DeleteFile('c:\program files (x86)\elex-tech\yac\isafesvc2.exe', '32');
DeleteFile('c:\program files (x86)\elex-tech\yac\isafetray.exe', '32');
DeleteFile('C:\Program Files\Common Files\Noobzo\GNUpdate\smu.exe', '32');
DeleteFile('c:\program files (x86)\system tools\systemtools.exe', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSvc.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafeupbiz.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iCommu.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iImportLib.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafepxy.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isaferpt.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\sqlite3.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\libcurl.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\curlpp.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\LIBEAY32.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\SSLEAY32.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\ipcproxy.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSvc2.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafenpf.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafebs.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeAdless.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlCall.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMonCall.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeDisp.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeBase.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iCommon.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafemc.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\libpng.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPNodisturb.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPProtect.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPDesk.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPFloaty.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPPush.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPMsgCenter.dll', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPAutoClean.dll', '32');
DeleteFile('C:\Program Files\Common Files\Noobzo\GNUpdate\smci32.dll', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Services\iThemes.dll', '32');
DeleteFile('c:\users\olga\appdata\roaming\winsapsvc\winsap.dll', '32');
DeleteFile('c:\program files (x86)\winarcher\archer.dll', '32');
DeleteFile('c:\program files (x86)\rerkuy\anthost.dll', '32');
DeleteFile('C:\Users\Olga\AppData\Local\Temp\1\BaofengUpdate_U.exe', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys', '32');
DeleteFile('C:\Program Files\Common Files\Noobzo\GNUpdate\smw.sys', '32');
DeleteFile('C:\WINDOWS\system32\DRIVERS\iSafeKrnlBoot.sys', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys', '32');
DeleteFile('C:\ProgramData\Hayzumflex\X-Rannix.dll', '32');
DeleteFile('C:\Users\Olga\AppData\Roaming\WinSnare\WinSnare.dll', '32');
DeleteFile('C:\Users\Olga\AppData\Roaming\vnlgp\vnlgp.exe', '32');
DeleteFile('C:\ProgramData\Hayzumflex\Hotsoft.dll', '32');
DeleteFile('C:\Program Files (x86)\Grotersp Mapper\local64spl.dll', '32');
DeleteFile('C:\ProgramData\SearchModule\smhe.js', '32');
DeleteFile('C:\Program Files (x86)\Rerkuy\rerjupy.exe', '32');
DeleteFile('C:\Users\Olga\AppData\Local\BrowserAir\48.0.0.0\updater.exe', '32');
DeleteFile('C:\Users\Olga\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Search.lnk', '32');
DeleteFile('C:\ProgramData\smp2.exe', '32');
DeleteFile('C:\ProgramData\wintools\WintoolUprI.exe', '32');
DeleteFile('C:\Program Files (x86)\Common Files\BioLa\uninstall.exe', '32');
DeleteFile('C:\Program Files (x86)\Common Files\BioLa\uninstall.dat', '32');
DeleteFile('C:\Users\Olga\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk');
DeleteService('ed2kidle');
DeleteService('FirefoxU');
DeleteService('Hayzumflex');
DeleteService('iSafeService');
DeleteService('iThemes5');
DeleteService('SMUpd');
DeleteService('BirdjobSU');
DeleteService('iSafeKrnl');
DeleteService('iSafeKrnlMon');
DeleteService('iSafeKrnlR3');
DeleteService('SMUpdd');
DeleteService('iSafeKrnlBoot');
DeleteService('iSafeKrnlKit');
DeleteFileMask('c:\program files (x86)\bikaqrssreader', '*', true);
DeleteFileMask('c:\program files (x86)\amulecexx', '*', true);
DeleteFileMask('c:\program files (x86)\firefox', '*', true);
DeleteFileMask('c:\programdata\hayzumflex', '*', true);
DeleteFileMask('c:\program files (x86)\elex-tech', '*', true);
DeleteFileMask('c:\program files\common files\noobzo', '*', true);
DeleteFileMask('c:\program files (x86)\system tools', '*', true);
DeleteFileMask('c:\program files (x86)\common files\services', '*', true);
DeleteFileMask('c:\program files (x86)\winarcher', '*', true);
DeleteFileMask('c:\program files (x86)\rerkuy', '*', true);
DeleteFileMask('c:\users\olga\appdata\roaming\winsnare', '*', true);
DeleteFileMask('c:\users\olga\appdata\roaming\vnlgp', '*', true);
DeleteFileMask('c:\program files (x86)\grotersp mapper', '*', true);
DeleteFileMask('c:\programdata\searchmodule', '*', true);
DeleteFileMask('c:\users\olga\appdata\local\browserair', '*', true);
DeleteFileMask('"c:\program files (x86)\mio', '*', true);
DeleteFileMask('c:\programdata\wintools', '*', true);
DeleteFileMask('c:\program files (x86)\common files\biola', '*', true);
DeleteDirectory('c:\program files (x86)\bikaqrssreader');
DeleteDirectory('c:\program files (x86)\amulecexx');
DeleteDirectory('c:\program files (x86)\firefox');
DeleteDirectory('c:\programdata\hayzumflex');
DeleteDirectory('c:\program files (x86)\elex-tech');
DeleteDirectory('c:\program files\common files\noobzo');
DeleteDirectory('c:\program files (x86)\system tools');
DeleteDirectory('c:\program files (x86)\common files\services');
DeleteDirectory('c:\program files (x86)\winarcher');
DeleteDirectory('c:\program files (x86)\rerkuy');
DeleteDirectory('c:\users\olga\appdata\roaming\winsnare');
DeleteDirectory('c:\users\olga\appdata\roaming\vnlgp');
DeleteDirectory('c:\program files (x86)\grotersp mapper');
DeleteDirectory('c:\programdata\searchmodule');
DeleteDirectory('c:\users\olga\appdata\local\browserair');
DeleteDirectory('"c:\program files (x86)\mio');
DeleteDirectory('c:\programdata\wintools');
DeleteDirectory('c:\program files (x86)\common files\biola');
ExecuteFile('schtasks.exe', '/delete /TN "BikaQ_FetchAndUpgrade_CanBeDel" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Grotersp Mapper" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "IBUpd" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "IBUpd2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Milimili" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SMW_P" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SMW_UpdateTask_Time_3238333332343030392d5a556c6c4a5a575750414134" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "WinTOOL" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{0C46B663-3004-4DDC-A66F-890E0B9DF23B}" /F', 0, 15000, true);
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\Archer\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\Dwadom\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\WinSAPSvc\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\WinSnare\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'vnlgp');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteRepair(4);
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.