Код:
begin
TerminateProcessByName('C:\ProgramData\WindowsTask\MicrosoftShellHost.exe');
TerminateProcessByName('C:\ProgramData\System32\Logs\ShellExperienceHost.exe');
QuarantineFileF('c:\users\вжик\appdata\roaming\memorycool', '*.exe', false, '', 0 , 0);
QuarantineFile('C:\ProgramData\WindowsTask\MicrosoftShellHost.exe', '');
QuarantineFile('C:\ProgramData\System32\Logs\ShellExperienceHost.exe', '');
QuarantineFile('C:\Program Files\iMenu Provection Experta\iMenu Provection Experta.dll', '');
QuarantineFile('C:\Users\Вжик\AppData\Roaming\Recovery\rmssys.exe', '');
QuarantineFile('C:\Users\Вжик\AppData\Roaming\memorycool\SysServices.exe', '');
QuarantineFileF('C:\Windows\Temp', '*.tmp.exe', false, '', 0, 0);
DeleteFile('C:\ProgramData\WindowsTask\MicrosoftShellHost.exe', '32');
DeleteFile('C:\ProgramData\System32\Logs\ShellExperienceHost.exe', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe', '32');
DeleteFile('C:\Program Files\iMenu Provection Experta\iMenu Provection Experta.dll', '32');
DeleteFile('C:\Users\Вжик\AppData\Roaming\Recovery\rmssys.exe', '32');
DeleteFile('C:\Users\Вжик\AppData\Roaming\memorycool\SysServices.exe', '32');
DeleteFile(' C:\Users\Вжик\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk');
DeleteFileMask('c:\programdata\windowstask', '*', true);
DeleteFileMask('c:\programdata\system32\logs', '*', true);
DeleteFileMask('c:\program files (x86)\zaxar', '*', true);
DeleteFileMask('c:\program files\imenu provection experta', '*', true);
DeleteFileMask('c:\users\вжик\appdata\roaming\recovery', '*', true);
DeleteFileMask('c:\users\вжик\appdata\roaming\memorycool', '*', true);
DeleteFileMask('C:\Windows\Temp', '*.tmp.exe', true);
DeleteDirectory('c:\programdata\windowstask');
DeleteDirectory('c:\programdata\system32\logs');
DeleteDirectory('c:\program files (x86)\zaxar');
DeleteDirectory('c:\program files\imenu provection experta');
DeleteDirectory('c:\users\вжик\appdata\roaming\recovery');
DeleteDirectory('c:\users\вжик\appdata\roaming\memorycool');
ExecuteFile('schtasks.exe', '/delete /TN "iMenu Provection Experta" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\sytems\recovery" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Wininet\Systemmanedger" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{0D5F4463-D958-47B3-B5E0-5447E63083AF}" /F', 0, 15000, true);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteRepair(13);
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(false);
end.
Компьютер перезагрузится.