Код:
begin
TerminateProcessByName('c:\program files (x86)\zaxar\zaxarloader.exe');
TerminateProcessByName('c:\program files (x86)\zaxar\zaxargamebrowser.exe');
TerminateProcessByName('C:\Program Files\UBar\UbarService.exe');
TerminateProcessByName('C:\Program Files\UBar\ubar.exe');
TerminateProcessByName('c:\users\flash\appdata\local\yc\application\yc.exe');
TerminateProcessByName('C:\Windows\Microsoft\svchost.exe.exe');
TerminateProcessByName('c:\windows\microsoft\svchost.exe');
TerminateProcessByName('c:\program files (x86)\yiuaskie\mbujct5j.exe');
TerminateProcessByName('C:\Windows\System32\Ea3Host.exe');
TerminateProcessByName('C:\Users\Flash\AppData\Roaming\fiibkhokmfkkadmpaigijmgmlfenpchk\python\pythonw.exe');
DeleteService('BrYNSvc');
StopService('BrYNSvc');
DeleteService('UbarPolicyProvider');
StopService('UbarPolicyProvider');
DeleteService('SvcHost Service Host');
StopService('SvcHost Service Host');
DeleteService('Ea3Host');
StopService('Ea3Host');
QuarantineFile('C:\WINDOWS\system32\Ea3Host.exe','');
QuarantineFile('c:\program files (x86)\yiuaskie\mbujct5j.exe','');
QuarantineFile('C:\Program Files (x86)\YiuAskIE\zeLvyU.dll','');
QuarantineFile('C:\Program Files (x86)\YiuAskIE\kO5ATp9E.dll','');
QuarantineFileF('c:\program files (x86)\yiuaskie', '*', false, '', 0, 0);
QuarantineFile('c:\windows\microsoft\svchost.exe','');
QuarantineFile('C:\Windows\Microsoft\svchost.exe.exe','');
QuarantineFileF('C:\Windows\Microsoft', '*', false, '', 0, 0);
QuarantineFile('c:\users\flash\appdata\local\yc\application\yc.exe','');
QuarantineFile('C:\Users\Flash\AppData\Local\yc\Application\56.0.2924.76\libglesv2.dll','');
QuarantineFile('C:\Users\Flash\AppData\Local\yc\Application\56.0.2924.76\libegl.dll','');
QuarantineFile('C:\Users\Flash\AppData\Local\yc\Application\56.0.2924.76\chrome_elf.dll','');
QuarantineFile('C:\Users\Flash\AppData\Local\yc\Application\56.0.2924.76\chrome_child.dll','');
QuarantineFile('C:\Users\Flash\AppData\Local\yc\Application\56.0.2924.76\chrome.dll','');
QuarantineFile('C:\Users\Flash\appdata\roaming\microsoft\msi.exe','');
QuarantineFile('C:\Program Files (x86)\YiuAskU2\GZ91zHW.dll','');
QuarantineFile('C:\Users\Flash\AppData\Roaming\curl\curl_7_54.exe','');
QuarantineFile('C:\Users\Flash\AppData\Roaming\curl\curl.exe','');
QuarantineFile('C:\Program Files (x86)\YiuAskU\t6YgDcm.dll','');
DelBHO('{2C6A44CB-AD42-4731-A544-3FBD3D83AB5B}');
QuarantineFile('C:\Users\Flash\AppData\Roaming\fiibkhokmfkkadmpaigijmgmlfenpchk\ml.py','');
QuarantineFile('C:\Program Files (x86)\Browny02\BrYNSvc.exe','');
DeleteFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Zaxar Games Browser.lnk','32');
DeleteFile('C:\Users\Flash\Favorites\Links\Интернет.url','32');
DeleteFile('C:\Windows\System32\Ea3Host.exe','32');
DeleteFile('c:\program files (x86)\yiuaskie\mbujct5j.exe','32');
DeleteFile('C:\Program Files (x86)\YiuAskIE\kO5ATp9E.dll','32');
DeleteFile('C:\Program Files (x86)\YiuAskIE\zeLvyU.dll','32');
DeleteFileMask('C:\Program Files (x86)\YiuAskIE','*',true);
DeleteDirectory('C:\Program Files (x86)\YiuAskIE');
DeleteFile('c:\windows\microsoft\svchost.exe','32');
DeleteFile('C:\Windows\Microsoft\svchost.exe.exe','32');
DeleteFileMask('C:\Windows\Microsoft','*',true);
DeleteDirectory('C:\Windows\Microsoft');
DeleteFile('c:\users\flash\appdata\local\yc\application\yc.exe','32');
DeleteFile('C:\Users\Flash\AppData\Local\yc\Application\56.0.2924.76\chrome.dll','32');
DeleteFile('C:\Users\Flash\AppData\Local\yc\Application\56.0.2924.76\chrome_child.dll','32');
DeleteFile('C:\Users\Flash\AppData\Local\yc\Application\56.0.2924.76\chrome_elf.dll','32');
DeleteFile('C:\Users\Flash\AppData\Local\yc\Application\56.0.2924.76\libegl.dll','32');
DeleteFile('C:\Users\Flash\AppData\Local\yc\Application\56.0.2924.76\libglesv2.dll','32');
DeleteFileMask('C:\Users\Flash\AppData\Local\yc','*',true);
DeleteDirectory('C:\Users\Flash\AppData\Local\yc');
DeleteFile('c:\program files (x86)\zaxar\zaxargamebrowser.exe','32');
DeleteFile('c:\program files (x86)\zaxar\zaxarloader.exe','32');
DeleteFile('C:\Program Files (x86)\Zaxar\bearer\qgenericbearer.dll','32');
DeleteFile('C:\Program Files (x86)\Zaxar\bearer\qnativewifibearer.dll','32');
DeleteFile('C:\Program Files (x86)\Zaxar\icudt58.dll','32');
DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qgif.dll','32');
DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qicns.dll','32');
DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qico.dll','32');
DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qjpeg.dll','32');
DeleteFileMask('C:\Program Files (x86)\Zaxar','*',true);
DeleteDirectory('C:\Program Files (x86)\Zaxar');
DeleteFile('C:\Program Files\UBar\Ubar.exe','32');
DeleteFile('C:\Program Files\UBar\UbarService.exe','32');
DeleteFileMask('C:\Program Files\UBar','*',true);
DeleteDirectory('C:\Program Files\UBar');
DeleteFile('C:\Program Files (x86)\Browny02\BrYNSvc.exe','32');
DeleteFileMask('C:\Program Files (x86)\Browny02','*',true);
DeleteDirectory('C:\Program Files (x86)\Browny02');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','fiibkhokmfkkadmpaigijmgmlfenpchk');
DeleteFile('C:\Users\Flash\AppData\Roaming\fiibkhokmfkkadmpaigijmgmlfenpchk\ml.py','32');
DeleteFileMask('C:\Users\Flash\AppData\Roaming\fiibkhokmfkkadmpaigijmgmlfenpchk','*',true);
DeleteDirectory('C:\Users\Flash\AppData\Roaming\fiibkhokmfkkadmpaigijmgmlfenpchk');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ycAutoLaunch_0B3D62489B08E9D25D94C09DA1240112');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','swmvobplqt');
DeleteFile('C:\WINDOWS\Tasks\2C6A44CB-AD42-4731-A544-3FBD3D83AB5B.job','32');
DeleteFile('C:\Program Files (x86)\YiuAskU\t6YgDcm.dll','32');
DeleteFileMask('C:\Program Files (x86)\YiuAskU','*',true);
DeleteDirectory('C:\Program Files (x86)\YiuAskU');
DeleteFile('C:\WINDOWS\system32\Tasks\2C6A44CB-AD42-4731-A544-3FBD3D83AB5B','64');
DeleteFile('C:\WINDOWS\system32\Tasks\2C6A44CB-AD42-4731-A544-3FBD3D83AB5B2','64');
DeleteFile('C:\WINDOWS\system32\Tasks\curl','64');
DeleteFile('C:\Users\Flash\AppData\Roaming\curl\curl.exe','32');
DeleteFile('C:\Users\Flash\AppData\Roaming\curl\curl_7_54.exe','32');
DeleteFileMask('C:\Users\Flash\AppData\Roaming\curl','*',true);
DeleteDirectory('C:\Users\Flash\AppData\Roaming\curl');
DeleteFile('C:\WINDOWS\system32\Tasks\curls','64');
DeleteFile('C:\WINDOWS\system32\Tasks\fiibkhokmfkkadmpaigijmgmlfenpchk','64');
DeleteFile('C:\WINDOWS\system32\Tasks\MSI','64');
DeleteFile('C:\Users\Flash\AppData\Roaming\Microsoft\msi.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\U2_2C6A44CB-AD42-4731-A544-3FBD3D83AB5B','64');
DeleteFile('C:\Program Files (x86)\YiuAskU2\GZ91zHW.dll','32');
DeleteFileMask('C:\Program Files (x86)\YiuAskU2','*',true);
DeleteDirectory('C:\Program Files (x86)\YiuAskU2');
ExecuteSysClean;
ExecuteRepair(2);
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteRepair(21);
ExecuteWizard('TSW',2,3,true);
ExecuteWizard('SCU',2,2,true);
RebootWindows(true);
end.
Компьютер перезагрузится.