Код:
begin
TerminateProcessByName('c:\users\4880~1\appdata\roaming\setupsk\python\pythonw.exe');
TerminateProcessByName('c:\users\Полина\appdata\local\temp\qph7tm19aka5.exe');
TerminateProcessByName('c:\windows\microsoft\svchost.exe');
TerminateProcessByName('C:\Windows\Microsoft\svchost.exe.exe');
TerminateProcessByName('c:\users\Полина\appdata\local\temp\t09grybxvu0o.exe');
TerminateProcessByName('C:\Program Files\UBar\ubar.exe');
TerminateProcessByName('C:\Program Files\UBar\UbarService.exe');
StopService('icacl');
StopService('SvcHost Service Host');
StopService('UbarPolicyProvider');
QuarantineFile('c:\users\4880~1\appdata\roaming\setupsk\python\pythonw.exe', '');
QuarantineFile('c:\users\Полина\appdata\local\temp\qph7tm19aka5.exe', '');
QuarantineFile('c:\windows\microsoft\svchost.exe', '');
QuarantineFile('C:\Windows\Microsoft\svchost.exe.exe', '');
QuarantineFile('c:\users\Полина\appdata\local\temp\t09grybxvu0o.exe', '');
QuarantineFile('C:\Program Files\UBar\ubar.exe', '');
QuarantineFile('C:\Program Files\UBar\UbarService.exe', '');
QuarantineFile('C:\Users\4880~1\AppData\Roaming\setupsk\python\python34.dll', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\AppleVersions.dll', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\YSCrashDump.DLL', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CoreFoundation.dll', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\ASL.dll', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\objc.dll', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libdispatch.dll', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\Foundation.dll', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libtidy.dll', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CFNetwork.dll', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\SQLite3.dll', '');
QuarantineFile('C:\WINDOWS\system32\icacl.exe', '');
QuarantineFile('C:\Users\4880~1\AppData\Roaming\SETUPS~1\python\pythonw.exe', '');
QuarantineFile('C:\Users\4880~1\AppData\Roaming\SETUPS~1\ml.py', '');
QuarantineFile('C:\Users\4880~1\AppData\Roaming\setupsk\ml.py', '');
QuarantineFile('C:\Users\Полина\AppData\Roaming\lidnkghmpmbmkjalooojbaefceoolghb\ml.py', '');
QuarantineFile('C:\Users\Полина\AppData\Local\yc\Application\yc.exe', '');
QuarantineFile('C:\Users\4880~1\AppData\Local\Temp\AST4W4~1.EXE', '');
QuarantineFile('C:\Users\Полина\AppData\LocalLow\SearchGo\searchgo.dll', '');
QuarantineFile('C:\Program Files (x86)\YeuAskIE\kETWl4IUB.dll', '');
QuarantineFile('C:\Program Files (x86)\YueAckU\xsxXcpJ.dll', '');
QuarantineFile('C:\Program Files (x86)\YtuAskU2\WGR8ZBc.dll', '');
QuarantineFile('C:\Users\Полина\AppData\Roaming\Microsoft\msi.exe', '');
QuarantineFile('C:\Users\Полина\AppData\Local\SearchGo\searchgo.exe', '');
QuarantineFile('C:\Users\Полина\AppData\Local\svshost\svshost.exe', '');
QuarantineFile('C:\Users\Полина\AppData\Local\wupdate\wupdate.exe', '');
DeleteFile('C:\WINDOWS\Tasks\A0EECDFC-B485-47CA-8AE4-6DB2B0B2691F.job', '64');
DeleteFile('c:\users\4880~1\appdata\roaming\setupsk\python\pythonw.exe', '32');
DeleteFile('c:\users\Полина\appdata\local\temp\qph7tm19aka5.exe', '32');
DeleteFile('c:\windows\microsoft\svchost.exe', '32');
DeleteFile('C:\Windows\Microsoft\svchost.exe.exe', '32');
DeleteFile('c:\users\Полина\appdata\local\temp\t09grybxvu0o.exe', '32');
DeleteFile('C:\Program Files\UBar\ubar.exe', '32');
DeleteFile('C:\Program Files\UBar\UbarService.exe', '32');
DeleteFile('C:\Users\4880~1\AppData\Roaming\setupsk\python\python34.dll', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\AppleVersions.dll', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\YSCrashDump.DLL', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CoreFoundation.dll', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\ASL.dll', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\objc.dll', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libdispatch.dll', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\Foundation.dll', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libtidy.dll', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CFNetwork.dll', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Apple\Apple Application Support\SQLite3.dll', '32');
DeleteFile('C:\WINDOWS\system32\icacl.exe', '32');
DeleteFile('C:\Users\Полина\Favorites\Links\Интернет.url', '32');
DeleteFile('C:\Users\4880~1\AppData\Roaming\SETUPS~1\python\pythonw.exe', '32');
DeleteFile('C:\Users\4880~1\AppData\Roaming\SETUPS~1\ml.py', '32');
DeleteFile('C:\Users\4880~1\AppData\Roaming\setupsk\ml.py', '32');
DeleteFile('C:\Users\Полина\AppData\Roaming\lidnkghmpmbmkjalooojbaefceoolghb\ml.py', '32');
DeleteFile('C:\Users\Полина\AppData\Local\yc\Application\yc.exe', '32');
DeleteFile('C:\Users\4880~1\AppData\Local\Temp\AST4W4~1.EXE', '32');
DeleteFile('C:\Users\Полина\AppData\LocalLow\SearchGo\searchgo.dll', '32');
DeleteFile('C:\Program Files (x86)\YeuAskIE\kETWl4IUB.dll', '32');
DeleteFile('C:\Program Files (x86)\YueAckU\xsxXcpJ.dll', '32');
DeleteFile('C:\Program Files (x86)\YtuAskU2\WGR8ZBc.dll', '32');
DeleteFile('C:\Users\Полина\AppData\Roaming\Microsoft\msi.exe', '32');
DeleteFile('C:\Users\Полина\Desktop\Вoйти в Интeрнет.lnk', '32
DeleteFile('C:\Users\Полина\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk', '32
DeleteFile('C:\Users\Полина\AppData\Local\SearchGo\searchgo.exe', '32');
DeleteFile('C:\Users\Полина\AppData\Local\svshost\svshost.exe', '32');
DeleteFile('C:\Users\Полина\AppData\Local\wupdate\wupdate.exe', '32');
DeleteService('icacl');
DeleteService('SvcHost Service Host');
DeleteService('UbarPolicyProvider');
DeleteFileMask('c:\program files\ubar', '*', true);
DeleteFileMask('c:\program files (x86)\common files\apple\apple application support', '*', true);
DeleteFileMask('c:\users\4880~1\appdata\roaming\setups~1', '*', true);
DeleteFileMask('c:\users\4880~1\appdata\roaming\setupsk', '*', true);
DeleteFileMask('c:\users\полина\appdata\roaming\lidnkghmpmbmkjalooojbaefceoolghb', '*', true);
DeleteFileMask('c:\users\полина\appdata\local\yc', '*', true);
DeleteFileMask('c:\users\полина\appdata\locallow\searchgo', '*', true);
DeleteFileMask('c:\program files (x86)\yeuaskie', '*', true);
DeleteFileMask('c:\program files (x86)\yueacku', '*', true);
DeleteFileMask('c:\program files (x86)\ytuasku2', '*', true);
DeleteFileMask('c:\users\полина\appdata\local\searchgo', '*', true);
DeleteFileMask('c:\users\полина\appdata\local\svshost', '*', true);
DeleteFileMask('c:\users\полина\appdata\local\wupdate', '*', true);
DeleteDirectory('c:\program files\ubar');
DeleteDirectory('c:\program files (x86)\common files\apple\apple application support');
DeleteDirectory('c:\users\4880~1\appdata\roaming\setups~1');
DeleteDirectory('c:\users\4880~1\appdata\roaming\setupsk');
DeleteDirectory('c:\users\полина\appdata\roaming\lidnkghmpmbmkjalooojbaefceoolghb');
DeleteDirectory('c:\users\полина\appdata\local\yc');
DeleteDirectory('c:\users\полина\appdata\locallow\searchgo');
DeleteDirectory('c:\program files (x86)\yeuaskie');
DeleteDirectory('c:\program files (x86)\yueacku');
DeleteDirectory('c:\program files (x86)\ytuasku2');
DeleteDirectory('c:\users\полина\appdata\local\searchgo');
DeleteDirectory('c:\users\полина\appdata\local\svshost');
DeleteDirectory('c:\users\полина\appdata\local\wupdate');
DelBHO('{598AEFC6-DD3C-4A63-9AC3-53FCF6155931}');
DelBHO('{C0D38E5A-7CF8-4105-8FE8-31B81443A114}');
DelBHO('{2BC46CFA-4B00-4193-A7BD-6AD1D0BCB5BC}');
ExecuteFile('schtasks.exe', '/delete /TN "5A8163FE-2D41-4CE5-AD54-7FE95B266373" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "A0EECDFC-B485-47CA-8AE4-6DB2B0B2691F" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "A0EECDFC-B485-47CA-8AE4-6DB2B0B2691F2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "lidnkghmpmbmkjalooojbaefceoolghb" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "MSI" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SearchGo Task" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "setupsk" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "setupsk_upd" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "svshost" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "wupdate" /F', 0, 15000, true);
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'setupsk_upd');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'setupsk');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'lidnkghmpmbmkjalooojbaefceoolghb');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'ycAutoLaunch_36AAEDB51CF8FF82EABB76D63261D431');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'jkturddczk');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'wtksincnzl');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'xragkhuoll');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'speeddialmaker_delete_self');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(false);
end.
Компьютер перезагрузится.