Код:
begin
TerminateProcessByName('c:\programdata\service.exe');
TerminateProcessByName('c:\programdata\networkpacketmanitor\nettrans.exe');
TerminateProcessByName('c:\program files (x86)\bikaqrssreader\bikaq.exe');
StopService('StanduckSU');
StopService('GoogleChromeUpService');
StopService('iThemes5');
StopService('Nettrans');
StopService('ed2kidle');
QuarantineFile('C:\Users\Егор\appdata\roaming\event monitor\isxdl.dll', '');
QuarantineFile('C:\Users\Егор\appdata\roaming\event monitor\em.exe', '');
QuarantineFile('C:\Program Files (x86)\Stedthrerward Log\local64spl.dll', '');
QuarantineFile('C:\Users\Егор\AppData\Roaming\WinSnare\WinSnare.dll', '');
QuarantineFile('C:\Program Files (x86)\bilibili\bilibili.dll', '');
QuarantineFile('C:\WINDOWS\TEMP\nsi6413.tmp\BaofengUpdate_U.exe', '');
QuarantineFile('C:\Program Files (x86)\amuleCexx\ed2k.exe', '');
QuarantineFile('C:\Users\A946~1\AppData\Local\Temp\bk60F.tmp\p1487616987am.sys', '');
QuarantineFile('C:\Users\A946~1\AppData\Local\Temp\bk6829.tmp\p1487616953am.sys', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Services\iThemes.dll', '');
QuarantineFile('c:\users\егор\appdata\roaming\winsapsvc\winsap.dll', '');
QuarantineFile('c:\programdata\service.exe', '');
QuarantineFileF('C:\Program Files (x86)\Stedthrerward Log', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\users\егор\appdata\roaming\winsapsvc', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\programdata\networkpacketmanitor', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFile('c:\programdata\networkpacketmanitor\nettrans.exe', '');
QuarantineFile('c:\program files (x86)\bikaqrssreader\bikaq.exe', '');
DeleteFile('c:\program files (x86)\bikaqrssreader\bikaq.exe', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Services\iThemes.dll', '32');
DeleteFile('C:\Users\A946~1\AppData\Local\Temp\bk6829.tmp\p1487616953am.sys', '32');
DeleteFile('C:\Users\A946~1\AppData\Local\Temp\bk60F.tmp\p1487616987am.sys', '32');
DeleteFile('C:\Program Files (x86)\amuleCexx\ed2k.exe', '32');
DeleteFile('C:\ProgramData\NetworkPacketManitor\Nettrans.exe', '32');
DeleteFile('C:\ProgramData\service.exe', '32');
DeleteFile('C:\WINDOWS\TEMP\nsi6413.tmp\BaofengUpdate_U.exe', '32');
DeleteFile('C:\Program Files (x86)\bilibili\bilibili.dll', '32');
DeleteFile('C:\Users\Егор\AppData\Roaming\WinSnare\WinSnare.dll', '32');
DeleteFile('C:\Program Files (x86)\Stedthrerward Log\local64spl.dll', '32');
DeleteFile('C:\Users\Егор\appdata\roaming\event monitor\em.exe', '32');
DeleteFile('C:\Users\Егор\appdata\roaming\event monitor\isxdl.dll', '32');
DeleteFile('C:\Users\Егор\appdata\roaming\winsapsvc\winsap.dll', '32');
DeleteService('StanduckSU');
DeleteService('GoogleChromeUpService');
DeleteService('iThemes5');
DeleteService('Nettrans');
DeleteService('ed2kidle');
DeleteFileMask('C:\Users\Егор\appdata\roaming\winsapsvc', '*', true);
DeleteFileMask('C:\Users\Егор\appdata\roaming\event monitor', '*', true);
DeleteFileMask('C:\Users\Егор\AppData\Roaming\WinSnare', '*', true);
DeleteFileMask('C:\ProgramData\NetworkPacketManitor', '*', true);
DeleteDirectory('C:\Users\Егор\appdata\roaming\winsapsvc');
DeleteDirectory('C:\Users\Егор\appdata\roaming\event monitor');
DeleteDirectory('C:\Users\Егор\AppData\Roaming\WinSnare');
DeleteDirectory('C:\ProgramData\NetworkPacketManitor');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\bilibili\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\WinSAPSvc\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\WinSnare\Parameters', 'ServiceDll');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
RebootWindows(true);
end.
Компьютер будет перезагружен.