Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
TerminateProcessByName('c:\users\Калек\appdata\roaming\nssm.exe');
TerminateProcessByName('c:\users\Калек\appdata\local\host service\nssm.exe');
QuarantineFileF('c:\users\Калек\appdata\local\host service\', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\Users\Калек\AppData\Local\Host Service', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFile('c:\users\Калек\appdata\roaming\nssm.exe', '');
QuarantineFile('c:\users\Калек\appdata\local\host service\nssm.exe', '');
QuarantineFileF('C:\Program Files\Common Files\{B3C39FE3-4A16-ADFE-B0F3-9C99DF6E204A}', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0, 0);
DeleteFile('c:\users\Калек\appdata\roaming\nssm.exe', '32');
DeleteFile('c:\users\Калек\appdata\local\host service\nssm.exe', '32');
ExecuteFile('schtasks.exe', '/delete /TN "{F27FED97-53F0-47FF-8852-ECD299484820}" /F', 0, 15000, true);
DeleteService('clr_optimization_v1.02');
DeleteService('dofilter');
DeleteFileMask('C:\Program Files\Common Files\{B3C39FE3-4A16-ADFE-B0F3-9C99DF6E204A}', '*', true);
DeleteDirectory('C:\Program Files\Common Files\{B3C39FE3-4A16-ADFE-B0F3-9C99DF6E204A}');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\Eventlog\Application\NSSM', 'EventMessageFile');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.