Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
QuarantineFile('C:\Program Files\RDP Wrapper\rdpwrap.dll', '');
QuarantineFile('C:\Programdata\ReaItekHD\taskhost.exe', '');
QuarantineFile('C:\Programdata\RealtekHD\taskhost.exe', '');
QuarantineFile('C:\Programdata\RealtekHD\taskhostw.exe', '');
QuarantineFile('C:\Programdata\Setup\sch.bat', '');
QuarantineFile('C:\ProgramData\Windows Tasks Service\winserv.exe', '');
QuarantineFile('C:\Users\Марина\AppData\Local\Programs\Ghostery\bd2529c508.msi', '');
QuarantineFileF('c:\programdata\realtekhd', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', false, '', 0 , 0);
QuarantineFileF('c:\programdata\windows tasks service', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
DeleteFile('"C:\WINDOWS\system32\msiexec.exe" /i "c:\users\марина\appdata\local\programs\ghostery\bd2529c508.msi" /quiet chrome=1', '64');
DeleteFile('C:\Program Files\RDP Wrapper\rdpwrap.dll', '64');
DeleteFile('C:\Programdata\ReaItekHD\taskhost.exe', '64');
DeleteFile('C:\Programdata\RealtekHD\taskhost.exe', '64');
DeleteFile('C:\Programdata\RealtekHD\taskhostw.exe', '64');
DeleteFile('C:\Programdata\Setup\sch.bat', '64');
DeleteFile('C:\ProgramData\Windows Tasks Service\winserv.exe', '64');
DeleteFile('C:\Users\Марина\AppData\Local\Programs\Ghostery\bd2529c508.msi', '64');
DeleteFileMask('"c:\windows\system32\msiexec.exe" /i "c:\users\марина\appdata\local\programs\ghostery', '*', true);
DeleteFileMask('c:\program files\rdp wrapper', '*', true);
DeleteFileMask('c:\programdata\reaitekhd', '*', true);
DeleteFileMask('c:\programdata\realtekhd', '*', true);
DeleteFileMask('c:\programdata\setup', '*', true);
DeleteFileMask('c:\programdata\windows tasks service', '*', true);
DeleteFileMask('c:\users\марина\appdata\local\programs\ghostery', '*', true);
DeleteDirectory('"c:\windows\system32\msiexec.exe" /i "c:\users\марина\appdata\local\programs\ghostery');
DeleteDirectory('c:\program files\rdp wrapper');
DeleteDirectory('c:\programdata\reaitekhd');
DeleteDirectory('c:\programdata\realtekhd');
DeleteDirectory('c:\programdata\setup');
DeleteDirectory('c:\programdata\windows tasks service');
DeleteDirectory('c:\users\марина\appdata\local\programs\ghostery');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\TermService\Parameters', 'ServiceDll', '64');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
DeleteSchedulerTask('Ghostery Update Task-S-1-5-21-4191766718-2159356183-1985812813-1001');
DeleteSchedulerTask('Microsoft\Windows\WindowsBackup\RecoveryHosts');
DeleteSchedulerTask('Microsoft\Windows\WindowsBackup\RecoveryStartUP');
DeleteSchedulerTask('Microsoft\Windows\Wininet\RealtekHDControl');
DeleteSchedulerTask('Microsoft\Windows\Wininet\RealtekHDStartUP');
DeleteSchedulerTask('Microsoft\Windows\Wininet\Taskhost');
DeleteSchedulerTask('Microsoft\Windows\Wininet\Taskhostw');
DeleteSchedulerTask('Microsoft\Windows\Wininet\winser');
DeleteSchedulerTask('Microsoft\Windows\Wininet\winsers');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
Компьютер перезагрузится.