Код:
begin
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys', '');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\iSafeKrnlBoot.sys', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys', '');
QuarantineFile('C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol', '');
QuarantineFile('C:\Users\wertuall113\AppData\Roaming\bestsalesprofit\ml.py', '');
QuarantineFile('C:\Program Files (x86)\Cosupy\GhrControls.dll', '');
QuarantineFile('C:\ProgramData\WinSAPSvc\WinSAP.dll', '');
QuarantineFile('C:\Users\wertuall113\AppData\Roaming\WinSnare\WinSnare.dll', '');
QuarantineFile('C:\Users\wertuall113\AppData\Roaming\bestsalesprofit\updater.py', '');
QuarantineFile('"C:\Program Files (x86)\MIO\MIO.exe" -bindurl http://api.mhttxtv.com/hgstxhts541010a9e680_ja1000101rrdxm1rrdxmx.exe cmd=', '');
QuarantineFile('C:\Program Files (x86)\MIO\MIO.exe', '');
QuarantineFile('C:\Program Files (x86)\Cosupy\phergagh.exe', '');
QuarantineFile('C:\ProgramData\wintools\WintoolUprI.exe', '');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\uninstall.exe', '');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys', '32');
DeleteFile('C:\WINDOWS\system32\DRIVERS\iSafeKrnlBoot.sys', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys', '32');
DeleteFile('C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol', '32');
DeleteFile('C:\Users\wertuall113\AppData\Roaming\bestsalesprofit\ml.py', '32');
DeleteFile('C:\Program Files (x86)\Cosupy\GhrControls.dll', '32');
DeleteFile('C:\ProgramData\WinSAPSvc\WinSAP.dll', '32');
DeleteFile('C:\Users\wertuall113\AppData\Roaming\WinSnare\WinSnare.dll', '32');
DeleteFile('C:\Users\wertuall113\AppData\Roaming\bestsalesprofit\updater.py', '32');
DeleteFile('"C:\Program Files (x86)\MIO\MIO.exe" -bindurl http://api.mhttxtv.com/hgstxhts541010a9e680_ja1000101rrdxm1rrdxmx.exe cmd=', '32');
DeleteFile('C:\Program Files (x86)\MIO\MIO.exe', '32');
DeleteFile('C:\Program Files (x86)\Cosupy\phergagh.exe', '32');
DeleteFile('C:\ProgramData\wintools\WintoolUprI.exe', '32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\uninstall.exe', '32');
DeleteService('iSafeService');
DeleteService('iSafeKrnl');
DeleteService('iSafeKrnlMon');
DeleteService('iSafeKrnlR3');
DeleteService('iSafeKrnlBoot');
DeleteService('iSafeKrnlKit');
DeleteFileMask('c:\program files (x86)\elex-tech', '*', true);
DeleteFileMask('c:\users\wertuall113\appdata\roaming\bestsalesprofit', '*', true);
DeleteFileMask('c:\program files (x86)\cosupy', '*', true);
DeleteFileMask('c:\users\wertuall113\appdata\roaming\winsnare', '*', true);
DeleteFileMask('"c:\program files (x86)\mio', '*', true);
DeleteFileMask('c:\program files (x86)\mio', '*', true);
DeleteFileMask('c:\programdata\wintools', '*', true);
DeleteDirectory('c:\program files (x86)\elex-tech');
DeleteDirectory('c:\users\wertuall113\appdata\roaming\bestsalesprofit');
DeleteDirectory('c:\program files (x86)\cosupy');
DeleteDirectory('c:\users\wertuall113\appdata\roaming\winsnare');
DeleteDirectory('"c:\program files (x86)\mio');
DeleteDirectory('c:\program files (x86)\mio');
DeleteDirectory('c:\programdata\wintools');
ExecuteFile('schtasks.exe', '/delete /TN "bestsalesprofit" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "bestsalesprofit2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Milimili" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Vohphstomt Cloud" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "WinTOOL" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{C08BD056-3557-455A-B027-0B35EED19C83}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{C2751620-E04E-47A5-A7F4-65A52322355B}" /F', 0, 15000, true);
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'C');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'bestsalesprofit');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\Atomily\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\WinSAPSvc\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\WinSnare\Parameters', 'ServiceDll');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteRepair(1);
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.