Код:
begin
TerminateProcessByName('c:\programdata\cloudprinter\cloudprinter.exe');
TerminateProcessByName('c:\program files (x86)\4044084e-1472617732-e111-bc1b-88c5720e9dc9\kns529b.tmp');
TerminateProcessByName('c:\users\Олег\appdata\local\mail.ru\mailruupdater.exe');
StopService('CloudPrinter');
QuarantineFile('c:\programdata\cloudprinter\cloudprinter.exe', '');
QuarantineFile('c:\program files (x86)\4044084e-1472617732-e111-bc1b-88c5720e9dc9\kns529b.tmp', '');
QuarantineFile('c:\users\Олег\appdata\local\mail.ru\mailruupdater.exe', '');
QuarantineFile('C:\Program Files\Aiduwb\Jijfes.exe', '');
QuarantineFile('C:\Program Files\3160955829f7ed47cbc1c45d715e6fbd\95c9769390416948c6a73cdad9987517.exe', '');
QuarantineFile('C:\Program Files (x86)\Gajightckeperward\FrtReportsGcy.exe', '');
QuarantineFile('C:\Users\SoeasyHelper\Helper.exe', '');
QuarantineFile('C:\Program Files (x86)\SoSoEasy\SoSoEasySvc.exe', '');
QuarantineFile('C:\Program Files (x86)\Mail.Ru\MailRuUpdater\MailRuUpdater.exe', '');
QuarantineFile('C:\Windows\system32\DRIVERS\BAPIDRV64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\cherimoya.sys', '');
QuarantineFile('C:\Program Files (x86)\SystemHealer\SystemHealer.exe', '');
QuarantineFile('C:\Windows\8f6222cd1abac1772a387746d736d4a5.ps1', '');
QuarantineFile('C:\Program Files (x86)\IObit\Driver', '');
QuarantineFile('C:\Program Files (x86)\Gajightckeperward\FrtReportsPrq.exe', '');
QuarantineFile('C:\ProgramData\RenewalService\Renewal.exe', '');
QuarantineFile('C:\Users\Олег\AppData\Roaming\Adobe\Manager.exe', '');
QuarantineFile('C:\Users\Олег\AppData\Local\Video4you\perfchecker.exe', '');
QuarantineFile('C:\Program Files (x86)\SystemHealer\HealerConsole.exe', '');
QuarantineFile('C:\Program Files\SpaceSoundPro\uninstaller.exe', '');
QuarantineFile('C:\Program Files (x86)\mpck\uninstaller.exe', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Doublezozflex\uninstall.exe', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Doublezozflex\uninstall.dat', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Faxfan\uninstall.exe', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Faxfan\uninstall.dat', '');
QuarantineFile('C:\Users\Олег\appdata\local\pricefountain\prfo.dll', '');
QuarantineFile('C:\Program Files\spacesoundpro\idscservice.exe', '');
QuarantineFile('C:\Program Files (x86)\AdBlocker\Service.WinServiceHost.exe', '');
DeleteFile('C:\Windows\Tasks\System HealerPeriod.job', '64');
DeleteFile('C:\Windows\Tasks\System HealerStartUp.job', '64');
DeleteFile('c:\programdata\cloudprinter\cloudprinter.exe', '32');
DeleteFile('c:\program files (x86)\4044084e-1472617732-e111-bc1b-88c5720e9dc9\kns529b.tmp', '32');
DeleteFile('c:\users\Олег\appdata\local\mail.ru\mailruupdater.exe', '32');
DeleteFile('C:\Program Files\Aiduwb\Jijfes.exe', '32');
DeleteFile('C:\Program Files\3160955829f7ed47cbc1c45d715e6fbd\95c9769390416948c6a73cdad9987517.exe', '32');
DeleteFile('fisovije.sys', '32');
DeleteFile('C:\Program Files (x86)\Gajightckeperward\FrtReportsGcy.exe', '32');
DeleteFile('kybenene.sys', '32');
DeleteFile('nugofotizbt.sys', '32');
DeleteFile('qkseeService.sys', '32');
DeleteFile('rumyvebu.sys', '32');
DeleteFile('C:\Users\SoeasyHelper\Helper.exe', '32');
DeleteFile('C:\Program Files (x86)\SoSoEasy\SoSoEasySvc.exe', '32');
DeleteFile('C:\Program Files (x86)\Mail.Ru\MailRuUpdater\MailRuUpdater.exe', '32');
DeleteFile('WdMan.sys', '32');
DeleteFile('winsaber.sys', '32');
DeleteFile('winzipersvc.sys', '32');
DeleteFile('C:\Windows\system32\DRIVERS\BAPIDRV64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\cherimoya.sys', '32');
DeleteFile('C:\Program Files (x86)\SystemHealer\SystemHealer.exe', '32');
DeleteFile('C:\Windows\8f6222cd1abac1772a387746d736d4a5.ps1', '32');
DeleteFile('C:\Program Files (x86)\IObit\Driver', '32');
DeleteFile('C:\Program Files (x86)\Gajightckeperward\FrtReportsPrq.exe', '32');
DeleteFile('C:\ProgramData\RenewalService\Renewal.exe', '32');
DeleteFile('C:\Users\Олег\AppData\Roaming\Adobe\Manager.exe', '32');
DeleteFile('C:\Users\Олег\AppData\Local\Video4you\perfchecker.exe', '32');
DeleteFile('AdCleaner\AdCleaner.exe', '32');
DeleteFile('C:\PROGRA~2\SYSTEM~1\RESCUE~1.EXE', '32');
DeleteFile('C:\Program Files (x86)\SystemHealer\HealerConsole.exe', '32');
DeleteFile('C:\Program Files\SpaceSoundPro\uninstaller.exe', '32');
DeleteFile('C:\Program Files (x86)\mpck\uninstaller.exe', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Doublezozflex\uninstall.exe', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Doublezozflex\uninstall.dat', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Faxfan\uninstall.exe', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Faxfan\uninstall.dat', '32');
DeleteFile('C:\Users\Олег\appdata\local\pricefountain\prfo.dll', '32');
DeleteFile('C:\Program Files\spacesoundpro\idscservice.exe', '32');
DeleteService('CloudPrinter');
DeleteService('05B93BAB-FAE5-44A8-9846-753385F00C07');
DeleteService('3160955829f7ed47cbc1c45d715e6fbd');
DeleteService('fisovije');
DeleteService('FrtReportsGcy.exe');
DeleteService('kybenene');
DeleteService('nugofotizbt');
DeleteService('qkseeService');
DeleteService('rumyvebu');
DeleteService('SoEasyHelper');
DeleteService('SoEasySvc');
DeleteService('Updater.Mail.Ru');
DeleteService('WdMan');
DeleteService('winsaber');
DeleteService('winzipersvc');
DeleteService('BAPIDRV');
DeleteService('cherimoya');
DeleteFileMask('c:\programdata\cloudprinter', '*', true);
DeleteFileMask('c:\users\олег\appdata\local\mail.ru', '*', true);
DeleteFileMask('c:\program files\aiduwb', '*', true);
DeleteFileMask('c:\program files\3160955829f7ed47cbc1c45d715e6fbd', '*', true);
DeleteFileMask('c:\program files (x86)\gajightckeperward', '*', true);
DeleteFileMask('c:\users\soeasyhelper', '*', true);
DeleteFileMask('c:\program files (x86)\sosoeasy', '*', true);
DeleteFileMask('c:\program files (x86)\mail.ru', '*', true);
DeleteFileMask('c:\program files (x86)\systemhealer', '*', true);
DeleteFileMask('c:\program files (x86)\iobit', '*', true);
DeleteFileMask('c:\programdata\renewalservice', '*', true);
DeleteFileMask('c:\users\олег\appdata\local\video4you', '*', true);
DeleteFileMask('c:\progra~2\system~1', '*', true);
DeleteFileMask('c:\program files\spacesoundpro', '*', true);
DeleteFileMask('c:\program files (x86)\mpck', '*', true);
DeleteFileMask('c:\program files (x86)\common files\doublezozflex', '*', true);
DeleteFileMask('c:\program files (x86)\common files\faxfan', '*', true);
DeleteFileMask('c:\users\олег\appdata\local\pricefountain', '*', true);
DeleteDirectory('c:\programdata\cloudprinter');
DeleteDirectory('c:\users\олег\appdata\local\mail.ru');
DeleteDirectory('c:\program files\aiduwb');
DeleteDirectory('c:\program files\3160955829f7ed47cbc1c45d715e6fbd');
DeleteDirectory('c:\program files (x86)\gajightckeperward');
DeleteDirectory('c:\users\soeasyhelper');
DeleteDirectory('c:\program files (x86)\sosoeasy');
DeleteDirectory('c:\program files (x86)\mail.ru');
DeleteDirectory('c:\program files (x86)\systemhealer');
DeleteDirectory('c:\program files (x86)\iobit');
DeleteDirectory('c:\programdata\renewalservice');
DeleteDirectory('c:\users\олег\appdata\local\video4you');
DeleteDirectory('c:\progra~2\system~1');
DeleteDirectory('c:\program files\spacesoundpro');
DeleteDirectory('c:\program files (x86)\mpck');
DeleteDirectory('c:\program files (x86)\common files\doublezozflex');
DeleteDirectory('c:\program files (x86)\common files\faxfan');
DeleteDirectory('c:\users\олег\appdata\local\pricefountain');
ExecuteFile('schtasks.exe', '/delete /TN "8f6222cd1abac1772a387746d736d4a5" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Driver Booster SkipUAC (Олег)" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Furtionckseck Reports" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "MailRuUpdater" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Application Experience\RenewalService" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Multimedia\Manager" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Wininet\PerfChecker" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "System Healer Task" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "System HealerPeriod" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "System HealerStartUp" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SystemHealer Monitor" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SystemHealer Run Delay" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{59DEC7A4-267E-4C7B-BDCC-7C7F2C7FBFAC}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{60A1A008-79F7-4128-BB67-9B5B1E3BE759}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{7B8EE6FD-0ABA-41F8-9F9E-EFC9ECDE87A5}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{888E6721-982A-497B-B3FB-05E1D0BD9C2F}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "MPC AdCleaner" /F', 0, 15000, true);
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'MailRuUpdater');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MailRuUpdater', 'command');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
RebootWindows(true);
end.
Компьютер перезагрузится.