Код:
begin
QuarantineFile('C:\Documents and Settings\Nail\Local Settings\Application Data\Host installer\1423376841_monster.exe','');
QuarantineFile('C:\iexplore.bat','');
QuarantineFile('C:\firefox.bat','');
StopService('qizefuqo');
StopService('hehopove');
StopService('byxylymi');
DeleteService('Util Edu App');
DeleteService('qizefuqo');
DeleteService('hehopove');
DeleteService('byxylymi');
TerminateProcessByName('c:\documents and settings\nail\application data\58435451-1431192368-3051-4532-3085a9788358\vnsfe7.tmp');
QuarantineFile('c:\documents and settings\nail\application data\58435451-1431192368-3051-4532-3085a9788358\vnsfe7.tmp','');
TerminateProcessByName('c:\documents and settings\nail\local settings\application data\gmsd_ru_235\upgmsd_ru_235.exe');
QuarantineFile('c:\documents and settings\nail\local settings\application data\gmsd_ru_235\upgmsd_ru_235.exe','');
TerminateProcessByName('c:\documents and settings\localservice\local settings\application data\smartweb\smartwebhelper.exe');
QuarantineFile('c:\documents and settings\localservice\local settings\application data\smartweb\smartwebhelper.exe','');
TerminateProcessByName('c:\documents and settings\localservice\local settings\application data\smartweb\smartwebapp.exe');
QuarantineFile('c:\documents and settings\localservice\local settings\application data\smartweb\smartwebapp.exe','');
TerminateProcessByName('c:\documents and settings\all users\application data\appmgr6.49.325397\1\plugin.exe');
QuarantineFile('c:\documents and settings\all users\application data\appmgr6.49.325397\1\plugin.exe','');
TerminateProcessByName('c:\windows\temp\nsl1e1.tmp');
QuarantineFile('c:\windows\temp\nsl1e1.tmp','');
TerminateProcessByName('c:\windows\temp\nsh22f.tmp');
QuarantineFile('c:\windows\temp\nsh22f.tmp','');
TerminateProcessByName('c:\windows\temp\nsf1b3.tmp');
QuarantineFile('c:\windows\temp\nsf1b3.tmp','');
TerminateProcessByName('c:\windows\temp\nse254.tmp');
QuarantineFile('c:\windows\temp\nse254.tmp','');
TerminateProcessByName('c:\documents and settings\nail\application data\58435451-1431192368-3051-4532-3085a9788358\nsa100.tmpfs');
QuarantineFile('c:\documents and settings\nail\application data\58435451-1431192368-3051-4532-3085a9788358\nsa100.tmpfs','');
TerminateProcessByName('c:\documents and settings\nail\application data\58435451-1431192368-3051-4532-3085a9788358\jnsn11a.tmp');
QuarantineFile('c:\documents and settings\nail\application data\58435451-1431192368-3051-4532-3085a9788358\jnsn11a.tmp','');
TerminateProcessByName('c:\program files\gmsd_ru_235\gmsd_ru_235.exe');
QuarantineFile('c:\program files\gmsd_ru_235\gmsd_ru_235.exe','');
TerminateProcessByName('c:\documents and settings\nail\local settings\application data\58435451-1431214460-3051-4532-3085a9788358\cnsd16d.tmp');
QuarantineFile('c:\documents and settings\nail\local settings\application data\58435451-1431214460-3051-4532-3085a9788358\cnsd16d.tmp','');
TerminateProcessByName('c:\documents and settings\all users\application data\appmgr6.49.325397\appmgr.exe');
QuarantineFile('c:\documents and settings\all users\application data\appmgr6.49.325397\appmgr.exe','');
TerminateProcessByName('c:\documents and settings\nail\application data\acewebextension\updater\ace_web_extension.exe');
QuarantineFile('c:\documents and settings\nail\application data\acewebextension\updater\ace_web_extension.exe','');
TerminateProcessByName('c:\windows\temp\906.exe');
QuarantineFile('c:\windows\temp\906.exe','');
DeleteFile('c:\windows\temp\906.exe','32');
DeleteFile('c:\documents and settings\nail\application data\acewebextension\updater\ace_web_extension.exe','32');
DeleteFile('c:\documents and settings\all users\application data\appmgr6.49.325397\appmgr.exe','32');
DeleteFile('c:\documents and settings\nail\local settings\application data\58435451-1431214460-3051-4532-3085a9788358\cnsd16d.tmp','32');
DeleteFile('c:\program files\gmsd_ru_235\gmsd_ru_235.exe','32');
DeleteFile('c:\documents and settings\nail\application data\58435451-1431192368-3051-4532-3085a9788358\jnsn11a.tmp','32');
DeleteFile('c:\documents and settings\nail\application data\58435451-1431192368-3051-4532-3085a9788358\nsa100.tmpfs','32');
DeleteFile('c:\windows\temp\nse254.tmp','32');
DeleteFile('c:\windows\temp\nsf1b3.tmp','32');
DeleteFile('c:\windows\temp\nsh22f.tmp','32');
DeleteFile('c:\windows\temp\nsl1e1.tmp','32');
DeleteFile('c:\documents and settings\all users\application data\appmgr6.49.325397\1\plugin.exe','32');
DeleteFile('c:\documents and settings\localservice\local settings\application data\smartweb\smartwebapp.exe','32');
DeleteFile('c:\documents and settings\localservice\local settings\application data\smartweb\smartwebhelper.exe','32');
DeleteFile('c:\documents and settings\nail\local settings\application data\gmsd_ru_235\upgmsd_ru_235.exe','32');
DeleteFile('c:\documents and settings\nail\application data\58435451-1431192368-3051-4532-3085a9788358\vnsfe7.tmp','32');
DeleteFile('C:\Documents and Settings\Nail\Local Settings\Application Data\58435451-1431214460-3051-4532-3085A9788358\cnsd16D.tmp','32');
DeleteFile('C:\Documents and Settings\Nail\Application Data\58435451-1431192368-3051-4532-3085A9788358\jnsn11A.tmp','32');
DeleteFile('C:\Documents and Settings\Nail\Application Data\58435451-1431192368-3051-4532-3085A9788358\nsa100.tmpfs','32');
DeleteFile('C:\Program Files\Edu App\bin\utilEduApp.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','AceWebException');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','SmartWeb');
DeleteFile('C:\Documents and Settings\Nail\Local Settings\Application Data\SmartWeb\SmartWebHelper.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','upgmsd_ru_235.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gmsd_ru_235');
DeleteFile('C:\firefox.bat','32');
DeleteFile('C:\iexplore.bat','32');
DeleteFile('C:\Documents and Settings\Nail\Local Settings\Application Data\Host installer\1423376841_monster.exe','32');
DeleteFile('C:\WINDOWS\Tasks\Soft installer.job','32');
DeleteFile('C:\WINDOWS\Tasks\SmartWeb Upgrade Trigger Task.job','32');
ExecuteSysClean;
RebootWindows(true);
end.