Код:
begin
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
QuarantineFile('C:\Users\Алексей\appdata\roaming\windows\wasppacer.exe','');
QuarantineFile('C:\Users\Алексей\AppData\Roaming\TS3Client\googleupd.exe','');
QuarantineFile('C:\Users\Алексей\AppData\Roaming\Windows\service.exe','');
QuarantineFile('C:\Users\Алексей\AppData\Roaming\WinRar\service.exe','');
QuarantineFile('C:\Users\Алексей\AppData\Local\c422f0\svсhоst.exe','');
QuarantineFile('C:\ProgramData\TimeTasks\TimeTasksSetup.exe','');
TerminateProcessByName('c:\users\Алексей\appdata\local\c422f0\svсhоst.exe');
QuarantineFile('c:\users\Алексей\appdata\local\c422f0\svсhоst.exe','');
TerminateProcessByName('c:\users\Алексей\appdata\roaming\windows\service.exe');
QuarantineFile('c:\users\Алексей\appdata\roaming\windows\service.exe','');
DeleteFile('c:\users\Алексей\appdata\roaming\windows\service.exe','32');
DeleteFile('c:\users\Алексей\appdata\local\c422f0\svсhоst.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ZaxarLoader');
DeleteFile('C:\ProgramData\TimeTasks\TimeTasksSetup.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Timestasks');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Adobe');
DeleteFile('C:\Users\Алексей\AppData\Local\c422f0\svсhоst.exe','32');
DeleteFile('C:\Users\Алексей\AppData\Roaming\WinRar\service.exe','32');
DeleteFile('C:\Users\Алексей\AppData\Roaming\Windows\service.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ChromeUpdater');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','AdobeUpdater');
DeleteFile('C:\Windows\system32\Tasks\ExtensionInstallerX_12','64');
DeleteFile('C:\Windows\system32\Tasks\ExtensionInstallerX_14','64');
DeleteFile('C:\Windows\system32\Tasks\ExtensionInstallerX_8','64');
DeleteFile('C:\Windows\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-1970835742GUI','64');
DeleteFile('C:\Users\Алексей\AppData\Roaming\TS3Client\googleupd.exe','32');
DeleteFile('C:\Users\Алексей\appdata\roaming\windows\wasppacer.exe','32');
ExecuteSysClean;
RebootWindows(true);
end.