Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
TerminateProcessByName('e:\users\4918~1\appdata\local\temp\nsd9131.tmp\20769084-98aa-4bc3-9b49-74ac4e85f300.exe');
TerminateProcessByName('e:\program files (x86)\filter\2\cppwindowsservice.exe');
TerminateProcessByName('e:\program files (x86)\filter\2\pfhttpcontentfilter.exe');
StopService('CppWindowsService');
QuarantineFileF('e:\program files (x86)\filter', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js, *.tmp*', true, '', 0 , 0);
QuarantineFileF('E:\Program Files (x86)\Kinoroom Browser', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js, *.tmp*', true, '', 0 , 0);
QuarantineFileF('E:\Program Files (x86)\VK OK AdBlock', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js, *.tmp*', true, '', 0 , 0);
QuarantineFile('e:\users\4918~1\appdata\local\temp\nsd9131.tmp\20769084-98aa-4bc3-9b49-74ac4e85f300.exe', '');
QuarantineFile('e:\program files (x86)\filter\2\cppwindowsservice.exe', '');
QuarantineFile('e:\program files (x86)\filter\2\pfhttpcontentfilter.exe', '');
QuarantineFile('E:\WINDOWS\system32\drivers\netfilter2.sys', '');
QuarantineFile('E:\Program Files (x86)\Kinoroom Browser\krbrowser.exe', '');
QuarantineFileF('E:\Users\Владислав\AppData\Local\Kometa\', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js, *.tmp*', true, '', 0, 0);
QuarantineFile('E:\ProgramData\Microsoft\Adobe\Flash Player\B18A6498-A0B8-499D-A8DF-ED334F1493F3\299442D9-88C1-4C71-A0FB-54B27A53D75B.exe', '');
QuarantineFile('E:\Users\Владислав\AppData\Local\Kometa\StartButton\kometastartvx64.exe', '');
QuarantineFile('E:\Program Files (x86)\VK OK AdBlock\jWWNvdE.exe', '');
DeleteFile('E:\WINDOWS\Tasks\Update Service for VK OK AdBlock.job', '64');
DeleteFile('E:\WINDOWS\Tasks\Update Service for VK OK AdBlock2.job', '64');
DeleteFile('e:\users\4918~1\appdata\local\temp\nsd9131.tmp\20769084-98aa-4bc3-9b49-74ac4e85f300.exe', '32');
DeleteFile('e:\program files (x86)\filter\2\cppwindowsservice.exe', '32');
DeleteFile('e:\program files (x86)\filter\2\pfhttpcontentfilter.exe', '32');
DeleteFile('E:\WINDOWS\system32\drivers\netfilter2.sys', '32');
DeleteFile('E:\Program Files (x86)\Kinoroom Browser\krbrowser.exe', '32');
DeleteFile('E:\ProgramData\Microsoft\Adobe\Flash Player\B18A6498-A0B8-499D-A8DF-ED334F1493F3\299442D9-88C1-4C71-A0FB-54B27A53D75B.exe', '32');
DeleteFile('E:\Users\Владислав\AppData\Local\Kometa\StartButton\kometastartvx64.exe', '32');
DeleteFile('E:\Program Files (x86)\VK OK AdBlock\jWWNvdE.exe', '32');
ExecuteFile('schtasks.exe', '/delete /TN "KRBLNKRUN" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "AB18A6498-A0B8-499D-A8DF-ED334F1493F3" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Update Service for VK OK AdBlock" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Update Service for VK OK AdBlock2" /F', 0, 15000, true);
DeleteService('CppWindowsService');
DeleteService('netfilter2');
DeleteFileMask('e:\program files (x86)\filter', '*', true);
DeleteFileMask('E:\Program Files (x86)\Kinoroom Browser', '*', true);
DeleteFileMask('E:\Program Files (x86)\VK OK AdBlock', '*', true);
DeleteDirectory('e:\program files (x86)\filter');
DeleteDirectory('E:\Program Files (x86)\Kinoroom Browser');
DeleteDirectory('E:\Program Files (x86)\VK OK AdBlock');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Kinoroom Browser');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'vlulmoujqw');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'B18A6498-A0B8-499D-A8DF-ED334F1493F3');
QuarantineFile('E:\ProgramData\Microsoft\Adobe\Flash Player\B18A6498-A0B8-499D-A8DF-ED334F1493F3\299442D9-88C1-4C71-A0FB-54B27A53D75B.exe','');
DeleteFile('E:\ProgramData\Microsoft\Adobe\Flash Player\B18A6498-A0B8-499D-A8DF-ED334F1493F3\299442D9-88C1-4C71-A0FB-54B27A53D75B.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','B18A6498-A0B8-499D-A8DF-ED334F1493F3');
DeleteFile('E:\WINDOWS\system32\Tasks\Microsoft\Windows\AB18A6498-A0B8-499D-A8DF-ED334F1493F3','64');
QuarantineFileF('E:\ProgramData\KRB Updater Utility\', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js, *.tmp*', true, '', 0, 0);
DeleteFileMask('E:\ProgramData\KRB Updater Utility\', '*', true);
DeleteDirectory('E:\ProgramData\KRB Updater Utility\');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.