Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
QuarantineFile('C:\PROGRA~1\MYCENT~1\InfoBar\MYCENT~1.DLL','');
QuarantineFile('C:\Users\user\AppData\Local\Temp\UNSTYX_GMAIL_COM.txt','');
QuarantineFile('C:\Users\user\AppData\Roaming\Microsoft\quokafu.exe','');
QuarantineFile('C:\Users\user\AppData\Roaming\Microsoft\joken.exe','');
QuarantineFile('C:\Users\user\AppData\Roaming\Microsoft\hydequo.exe','');
QuarantineFile('C:\Users\user\AppData\Roaming\Microsoft\hilojiv.exe','');
QuarantineFile('C:\Users\user\AppData\Roaming\Microsoft\guwa.exe','');
QuarantineFile('C:\Users\user\AppData\Roaming\Microsoft\guvu.exe','');
QuarantineFile('C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\88E5FCDQ\подарочек)[1].exe','');
DeleteFile('C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\88E5FCDQ\подарочек)[1].exe','32');
DeleteFile('C:\Users\user\AppData\Roaming\Microsoft\guvu.exe','32');
DeleteFile('C:\Users\user\AppData\Roaming\Microsoft\guwa.exe','32');
DeleteFile('C:\Users\user\AppData\Roaming\Microsoft\hilojiv.exe','32');
DeleteFile('C:\Users\user\AppData\Roaming\Microsoft\hydequo.exe','32');
DeleteFile('C:\Users\user\AppData\Roaming\Microsoft\joken.exe','32');
DeleteFile('C:\Users\user\AppData\Roaming\Microsoft\quokafu.exe','32');
DeleteFile('C:\Users\user\AppData\Local\Temp\UNSTYX_GMAIL_COM.txt','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Green Christmas Tree');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ficinib');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','fiquoun');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','gokoosu');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','gesoum');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','moojourif');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','hoojal');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ReminderText');
BC_ImportALL;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
ExecuteWizard('TSW',2,2,true);
BC_Activate;
RebootWindows(true);
end.