Код:
begin
StopService('KuaiZipDrive');
StopService('GoogleChromeUpService');
QuarantineFile('C:\Users\Марина\AppData\Roaming\setupsk\app.py', '');
QuarantineFile('C:\Users\Марина\AppData\Roaming\setupsk\python\pythonw.exe', '');
QuarantineFile('C:\Users\Марина\AppData\Roaming\setupsk\ml.py', '');
QuarantineFile('C:\Users\Марина\AppData\Roaming\Adobe\Manager.exe', '');
QuarantineFile('C:\ProgramData\vCore\VCore.exe', '');
QuarantineFile('C:\PROGRA~1\6A8C~1\X86\Update.exe', '');
QuarantineFile('C:\Program Files (x86)\Naqodomvohs\phierk.exe', '');
QuarantineFileF('C:\Program Files (x86)\Naqodomvohs', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('C:\Program Files (x86)\Jernercult Verfier', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('C:\Program Files\їмС№\X86', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFile('C:\Program Files (x86)\Jernercult Verfier\local64spl.dll', '');
QuarantineFile('C:\Program Files\їмС№\X86\kuaizipUpdateChecker.dll', '');
QuarantineFile('C:\ProgramData\WindowsMsg\Chrome.exe', '');
QuarantineFile('C:\Users\Марина\AppData\Local\Temp\00021734\msiql.exe', '');
QuarantineFile('C:\ProgramData\service.exe', '');
QuarantineFile('C:\WINDOWS\system32\drivers\KuaiZipDrive.sys', '');
DeleteFile('C:\WINDOWS\system32\drivers\KuaiZipDrive.sys', '32');
DeleteFile('C:\ProgramData\service.exe', '32');
DeleteFile('C:\Users\Марина\AppData\Local\Temp\00021734\msiql.exe', '32');
DeleteFile('C:\ProgramData\WindowsMsg\Chrome.exe', '32');
DeleteFile('C:\Program Files\їмС№\X86\kuaizipUpdateChecker.dll', '32');
DeleteFile('C:\Program Files (x86)\Jernercult Verfier\local64spl.dll', '32');
DeleteFile('C:\Program Files (x86)\Naqodomvohs\phierk.exe', '32');
DeleteFile('C:\PROGRA~1\6A8C~1\X86\Update.exe', '32');
DeleteFile('C:\ProgramData\vCore\VCore.exe', '32');
DeleteFile('C:\Users\Марина\AppData\Roaming\setupsk\ml.py', '32');
DeleteFile('C:\Users\Марина\AppData\Roaming\setupsk\python\pythonw.exe', '32');
DeleteFile('C:\Users\Марина\AppData\Roaming\setupsk\app.py', '32');
DeleteFile('C:\Users\Марина\appdata\roaming\adobe\manager.exe', '32');
DeleteService('KuaiZipDrive');
DeleteService('GoogleChromeUpService');
DeleteFileMask('C:\Program Files\їмС№', '*', true);
DeleteFileMask('C:\Program Files (x86)\Naqodomvohs', '*', true);
DeleteFileMask('C:\Program Files (x86)\Jernercult Verfier', '*', true);
DeleteDirectory('C:\Program Files\їмС№');
DeleteDirectory('C:\Program Files (x86)\Naqodomvohs');
DeleteDirectory('C:\Program Files (x86)\Jernercult Verfier');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'msiql');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'osmsg');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\KuaizipUpdateChecker\Parameters', 'ServiceDll');
ExecuteFile('schtasks.exe', '/delete /TN "Atowerpyplowat" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Jernercult Verfier" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "KuaiZip_Update" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "VCore" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Manager" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "osTip" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "setupsk" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "setupsk2" /F', 0, 15000, true);
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
RebootWindows(true);
end.
Компьютер будет перезагружен.