Код:
begin
ExecuteRepair(21);
ExecuteAVUpdate;
TerminateProcessByName('c:\programdata\cloudprinter\cloudprinter.exe');
TerminateProcessByName('c:\program files (x86)\drivertoolkit\drivertoolkit.exe');
TerminateProcessByName('c:\program files (x86)\6ea3fd00-1455835015-11d5-903a-5404a699fc7d\jnso7f4e.tmp');
TerminateProcessByName('c:\program files (x86)\iobit\advanced systemcare\monitor.exe');
TerminateProcessByName('c:\programdata\service.exe');
StopService('CloudPrinter');
StopService('GoogleChromeUpService');
StopService('netfilter2');
QuarantineFileF('c:\programdata\cloudprinter', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\program files (x86)\drivertoolkit', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('C:\Users\User\AppData\Roaming\FreeVPN', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFile('c:\program files (x86)\iobit\advanced systemcare\ascservice.exe', '');
QuarantineFile('c:\programdata\cloudprinter\cloudprinter.exe', '');
QuarantineFile('c:\program files (x86)\drivertoolkit\drivertoolkit.exe', '');
QuarantineFile('c:\program files (x86)\6ea3fd00-1455835015-11d5-903a-5404a699fc7d\jnso7f4e.tmp', '');
QuarantineFile('c:\program files (x86)\iobit\advanced systemcare\monitor.exe', '');
QuarantineFile('c:\programdata\service.exe', '');
QuarantineFile('C:\Program Files (x86)\DriverToolkit\network.dll', '');
QuarantineFile('C:\Program Files (x86)\DriverToolkit\zlibwapi.dll', '');
QuarantineFile('C:\Program Files (x86)\6EA3FD00-1455835015-11D5-903A-5404A699FC7D\hnso958E.tmp', '');
QuarantineFile('C:\Program Files (x86)\6EA3FD00-1455835015-11D5-903A-5404A699FC7D\knsy67C2.tmpfs', '');
QuarantineFile('C:\Windows\system32\drivers\netfilter2.sys', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\QMUdisk64.sys', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\softaal64.sys', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TsNetHlpX64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\tsskx64.sys', '');
QuarantineFile('C:\Program Files (x86)\IObit\Advanced SystemCare\DiskDefrag.exe', '');
QuarantineFile('C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe', '');
QuarantineFile('C:\Users\User\AppData\Local\Birds\birds365.exe', '');
QuarantineFile('C:\ProgramData\HomePage.exe', '');
QuarantineFile('C:\Users\User\AppData\Local\Kometa\kometaup.exe', '');
QuarantineFile('C:\ProgramData\LightGate.exe', '');
QuarantineFile('c:\programdata\msiql.exe', '');
QuarantineFile('C:\ProgramData\ShJUJTZS\chdPcMtq0.bat', '');
QuarantineFile('C:\ProgramData\ArArSt\syuBFRlGI5.bat', '');
QuarantineFile('C:\PROGRA~1\GROOVE~1\Omakguh.bat', '');
QuarantineFile('C:\Users\User\AppData\Roaming\FreeVPN\FreeVPN.exe', '');
QuarantineFile('C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe', '');
QuarantineFile('D:\Documents\systemfile.exe', '');
DeleteFile('C:\Windows\Tasks\DriverToolkit Autorun.job', '64');
DeleteFile('c:\programdata\cloudprinter\cloudprinter.exe', '32');
DeleteFile('c:\program files (x86)\drivertoolkit\drivertoolkit.exe', '32');
DeleteFile('c:\program files (x86)\6ea3fd00-1455835015-11d5-903a-5404a699fc7d\jnso7f4e.tmp', '32');
DeleteFile('c:\programdata\service.exe', '32');
DeleteFile('C:\Program Files (x86)\DriverToolkit\network.dll', '32');
DeleteFile('C:\Program Files (x86)\6EA3FD00-1455835015-11D5-903A-5404A699FC7D\hnso958E.tmp', '32');
DeleteFile('C:\Program Files (x86)\6EA3FD00-1455835015-11D5-903A-5404A699FC7D\knsy67C2.tmpfs', '32');
DeleteFile('C:\Windows\system32\drivers\netfilter2.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\QMUdisk64.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\softaal64.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TsNetHlpX64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\tsskx64.sys', '32');
DeleteFile('C:\Users\User\AppData\Local\Birds\birds365.exe', '32');
DeleteFile('C:\ProgramData\HomePage.exe', '32');
DeleteFile('C:\Users\User\AppData\Local\Kometa\kometaup.exe', '32');
DeleteFile('C:\ProgramData\LightGate.exe', '32');
DeleteFile('c:\programdata\msiql.exe', '32');
DeleteFile('C:\ProgramData\ShJUJTZS\chdPcMtq0.bat', '32');
DeleteFile('C:\ProgramData\ArArSt\syuBFRlGI5.bat', '32');
DeleteFile('C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe', '32');
DeleteFile('C:\PROGRA~1\GROOVE~1\Omakguh.bat', '32');
DeleteFile('C:\Users\User\AppData\Roaming\FreeVPN\FreeVPN.exe', '32');
DeleteFile('D:\Documents\systemfile.exe', '32');
DeleteService('CloudPrinter');
DeleteService('GoogleChromeUpService');
DeleteService('LiveUpdateSvc');
DeleteService('wucotusy');
DeleteService('xijeminuzbt');
DeleteService('netfilter2');
DeleteService('QMUdisk');
DeleteService('softaal');
DeleteService('tsnethlpx64');
DeleteService('TSSKX64');
DeleteFileMask('c:\programdata\cloudprinter', '*', true);
DeleteFileMask('c:\program files (x86)\drivertoolkit', '*', true);
DeleteFileMask('C:\Program Files (x86)\Tencent', '*', true);
DeleteFileMask('C:\Users\User\AppData\Local\Birds', '*', true);
DeleteFileMask('C:\Users\User\AppData\Local\Kometa', '*', true);
DeleteFileMask('C:\Users\User\AppData\Roaming\FreeVPN', '*', true);
DeleteDirectory('c:\programdata\cloudprinter');
DeleteDirectory('c:\program files (x86)\drivertoolkit');
DeleteDirectory('C:\Program Files (x86)\Tencent');
DeleteDirectory('C:\Users\User\AppData\Local\Birds');
DeleteDirectory('C:\Users\User\AppData\Local\Kometa');
DeleteDirectory('C:\Users\User\AppData\Roaming\FreeVPN');
ExecuteFile('schtasks.exe', '/delete /TN "Dakshun" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "DriverToolkit Autorun" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "FreeVPN" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Uninstaller_SkipUac_User" /F', 0, 15000, true);
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath', '');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Birds', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HomePageHelper', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\kometaup', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LightGate', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\msiql', 'command');
ExecuteSysClean;
ExecuteRepair(4);
ExecuteRepair(23);
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.