Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
TerminateProcessByName('c:\users\ramp\appdata\local\microsoft\windows\system.exe');
TerminateProcessByName('c:\programdata\iepluginservices\pluginservice.exe');
TerminateProcessByName('c:\users\ramp\appdata\local\temp\net3b2a.tmp.exe');
TerminateProcessByName('c:\users\ramp\appdata\local\temp\net3b28.tmp.exe');
StopService('IePluginServices');
QuarantineFile('C:\Users\Ramp\appdata\local\systemdir\setsearchm.exe', '');
QuarantineFile('C:\Users\Ramp\appdata\local\kometa\kometaup.exe', '');
QuarantineFile('C:\Users\Ramp\AppData\Local\SystemDir\nethost.exe', '');
QuarantineFile('C:\Program Files (x86)\Microsoft Data\InstallAddons.exe', '');
QuarantineFile('C:\Program Files (x86)\VK Downloader\Toolbar32.dll', '');
QuarantineFile('C:\Program Files (x86)\advPlugin\Toolbar32.dll', '');
QuarantineFile('C:\Users\Ramp\AppData\Local\Temp\NET3B2~4.EXE', '');
QuarantineFile('C:\Users\Ramp\AppData\Local\Temp\NET3B2~3.EXE', '');
QuarantineFile('C:\Users\Ramp\AppData\Local\Temp\NET2D1~1.EXE', '');
QuarantineFile('C:\Users\Ramp\AppData\Local\Temp\NE8349~1.EXE', '');
QuarantineFile('C:\Program Files (x86)\Mobogenie\DaemonProcess.exe', '');
QuarantineFile('C:\PROGRA~2\SupTab\SEARCH~2.DLL', '');
QuarantineFile('C:\PROGRA~2\SupTab\SEARCH~1.DLL', '');
QuarantineFile('C:\Program Files (x86)\VK Downloader\Basement\ExtensionUpdaterService.exe', '');
QuarantineFile('C:\Windows\system32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}w64.sys', '');
QuarantineFile('c:\users\ramp\appdata\local\microsoft\windows\system.exe', '');
QuarantineFile('c:\programdata\iepluginservices\pluginservice.exe', '');
QuarantineFile('c:\users\ramp\appdata\local\temp\net3b2a.tmp.exe', '');
QuarantineFile('c:\users\ramp\appdata\local\temp\net3b28.tmp.exe', '');
DeleteFile('C:\Windows\system32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}w64.sys', '32');
DeleteFile('C:\ProgramData\IePluginServices\PluginService.exe', '32');
DeleteFile('C:\PROGRA~2\SupTab\SEARCH~1.DLL', '32');
DeleteFile('C:\PROGRA~2\SupTab\SEARCH~2.DLL', '32');
DeleteFile('C:\Program Files (x86)\Mobogenie\DaemonProcess.exe', '32');
DeleteFile('C:\Users\Ramp\AppData\Local\Temp\NE8349~1.EXE', '32');
DeleteFile('C:\Users\Ramp\AppData\Local\Temp\NET2D1~1.EXE', '32');
DeleteFile('C:\Users\Ramp\AppData\Local\Temp\NET3B2~3.EXE', '32');
DeleteFile('C:\Users\Ramp\AppData\Local\Temp\NET3B2~4.EXE', '32');
DeleteFile('C:\Users\Ramp\AppData\Local\Temp\net3B28.tmp.exe', '32');
DeleteFile('C:\Users\Ramp\AppData\Local\Temp\net3B2A.tmp.exe', '32');
DeleteFile('C:\Program Files (x86)\Microsoft Data\InstallAddons.exe', '32');
DeleteFile('C:\Windows\system32\Tasks\chrome5', '64');
DeleteFile('C:\Windows\system32\Tasks\chrome5_logon', '64');
DeleteFile('C:\Windows\system32\Tasks\LaunchApp', '64');
DeleteFile('C:\Users\Ramp\AppData\Local\SystemDir\nethost.exe', '32');
DeleteFile('C:\Windows\system32\Tasks\nethost task', '64');
DeleteFile('C:\Windows\system32\Tasks\SystemScript', '64');
DeleteFile('C:\Users\Ramp\appdata\local\kometa\kometaup.exe', '32');
DeleteFile('C:\Users\Ramp\appdata\local\microsoft\windows\system.exe', '32');
DeleteFile('C:\Users\Ramp\appdata\local\systemdir\setsearchm.exe', '32');
DeleteService('IePluginServices');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon', 'command');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'SystemScript');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'GoSearch_startsetsearch_firefox');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'GoSearch_startsetsearch_chrome');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'GoSearchRemoveAppoldopera');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'GoSearchRemoveAppiexplore');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'GoSearchRemoveAppchrome');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.