Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
TerminateProcessByName('c:\program files (x86)\adshield\svc.exe');
TerminateProcessByName('c:\windows\temp\sppsvc.exe');
StopService('adshieldsvc');
QuarantineFile('C:\Program Files (x86)\AdShield\libcrypto-1_1.dll', '');
QuarantineFile('C:\Program Files (x86)\AdShield\libssl-1_1.dll', '');
QuarantineFile('C:\Program Files (x86)\AdShield\MSVCP140_1.dll', '');
QuarantineFile('c:\program files (x86)\adshield\svc.exe', '');
QuarantineFile('C:\Program Files (x86)\AdShield\updater.exe', '');
QuarantineFile('C:\Program Files (x86)\BIjiUDbcwIE\kJe1N7cX.dll', '');
QuarantineFile('C:\Program Files (x86)\BIjiUDbcwIE\tHIXVKsZt.dll', '');
QuarantineFile('C:\Program Files (x86)\HYFUTLkTSgAU2\LetzQjxkyCyyA.dll', '');
QuarantineFile('C:\Program Files (x86)\QpSoxVj\QpSoxVj.dll', '');
QuarantineFile('C:\Program Files (x86)\TMPxRiOdU\ezjkCy.dll', '');
QuarantineFile('C:\ProgramData\cCjDGqfufCNhvYVB\HzIrzdv.wsf', '');
QuarantineFile('C:\ProgramData\WindowsMenu\westat.exe', '');
QuarantineFile('C:\Users\Maxim\AppData\Local\Browserupdphenix\Browserupdphenix.exe', '');
QuarantineFile('C:\Users\Maxim\AppData\Local\Temp\nmpjrpz4.hjf\nuwpqicunde.exe', '');
QuarantineFile('C:\Users\Maxim\AppData\Local\Temp\yb2.exe', '');
QuarantineFile('C:\Users\Maxim\AppData\Roaming\Microsoft\Windows\Update\UpdateHelper.exe', '');
QuarantineFile('C:\Users\Maxim\AppData\Roaming\utctimer\utc.exe', '');
QuarantineFile('c:\windows\temp\sppsvc.exe', '');
QuarantineFileF('c:\program files (x86)\bijiudbcwie', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\program files (x86)\hyfutlktsgau2', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\program files (x86)\qpsoxvj', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\program files (x86)\tmpxriodu', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\users\maxim\appdata\roaming\microsoft\windows\update', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
DeleteFile('C:\Program Files (x86)\AdShield\libcrypto-1_1.dll', '');
DeleteFile('C:\Program Files (x86)\AdShield\libssl-1_1.dll', '');
DeleteFile('C:\Program Files (x86)\AdShield\MSVCP140_1.dll', '');
DeleteFile('c:\program files (x86)\adshield\svc.exe', '');
DeleteFile('C:\Program Files (x86)\AdShield\svc.exe', '64');
DeleteFile('C:\Program Files (x86)\AdShield\updater.exe', '64');
DeleteFile('C:\Program Files (x86)\BIjiUDbcwIE\kJe1N7cX.dll', '');
DeleteFile('C:\Program Files (x86)\BIjiUDbcwIE\kJe1N7cX.dll', '32');
DeleteFile('C:\Program Files (x86)\BIjiUDbcwIE\tHIXVKsZt.dll', '64');
DeleteFile('C:\Program Files (x86)\HYFUTLkTSgAU2\LetzQjxkyCyyA.dll', '64');
DeleteFile('C:\Program Files (x86)\QpSoxVj\QpSoxVj.dll', '64');
DeleteFile('C:\Program Files (x86)\TMPxRiOdU\ezjkCy.dll', '64');
DeleteFile('C:\ProgramData\cCjDGqfufCNhvYVB\HzIrzdv.wsf', '64');
DeleteFile('C:\ProgramData\WindowsMenu\westat.exe', '64');
DeleteFile('C:\Users\Maxim\appdata\local\browserupdphenix\browserupdphenix.exe', '');
DeleteFile('C:\Users\Maxim\AppData\Local\Browserupdphenix\Browserupdphenix.exe', '64');
DeleteFile('C:\Users\Maxim\AppData\Local\Temp\nmpjrpz4.hjf\nuwpqicunde.exe', '32');
DeleteFile('C:\Users\Maxim\AppData\Local\Temp\nmpjrpz4.hjf\nuwpqicunde.exe', '64');
DeleteFile('C:\Users\Maxim\AppData\Local\Temp\yb2.exe', '32');
DeleteFile('C:\Users\Maxim\AppData\Local\Temp\yb2.exe', '64');
DeleteFile('C:\Users\Maxim\AppData\Roaming\Microsoft\Windows\Update\UpdateHelper.exe', '64');
DeleteFile('C:\Users\Maxim\AppData\Roaming\utctimer\utc.exe', '64');
DeleteFile('c:\windows\temp\sppsvc.exe', '');
DeleteService('adshieldsvc');
DeleteService('QMEmulatorService');
DeleteFileMask('c:\program files (x86)\adshield', '*', true);
DeleteFileMask('c:\program files (x86)\bijiudbcwie', '*', true);
DeleteFileMask('c:\program files (x86)\hyfutlktsgau2', '*', true);
DeleteFileMask('c:\program files (x86)\qpsoxvj', '*', true);
DeleteFileMask('c:\program files (x86)\tmpxriodu', '*', true);
DeleteFileMask('c:\programdata\windowsmenu', '*', true);
DeleteFileMask('c:\users\maxim\appdata\local\browserupdphenix', '*', true);
DeleteFileMask('c:\users\maxim\appdata\roaming\microsoft\windows\update', '*', true);
DeleteFileMask('c:\users\maxim\appdata\roaming\utctimer', '*', true);
DeleteDirectory('c:\program files (x86)\adshield');
DeleteDirectory('c:\program files (x86)\bijiudbcwie');
DeleteDirectory('c:\program files (x86)\hyfutlktsgau2');
DeleteDirectory('c:\program files (x86)\qpsoxvj');
DeleteDirectory('c:\program files (x86)\tmpxriodu');
DeleteDirectory('c:\programdata\windowsmenu');
DeleteDirectory('c:\users\maxim\appdata\local\browserupdphenix');
DeleteDirectory('c:\users\maxim\appdata\roaming\microsoft\windows\update');
DeleteDirectory('c:\users\maxim\appdata\roaming\utctimer');
DelBHO('{D66F89F5-3AA9-4682-8D12-773042AF857F}');
DeleteSchedulerTask('AdShield scheduled autoupdate');
DeleteSchedulerTask('bkuDxteYrfmSTMeheIc');
DeleteSchedulerTask('bkuDxteYrfmSTMeheIc.job');
DeleteSchedulerTask('bkumFIMKdacufODaJpU');
DeleteSchedulerTask('bkumFIMKdacufODaJpU.job');
DeleteSchedulerTask('Browserupdphenix');
DeleteSchedulerTask('fltMhdOsmhPWyxm2');
DeleteSchedulerTask('IObitSelfCheckTask');
DeleteSchedulerTask('LenYUMVtweMhCQ');
DeleteSchedulerTask('Microsoft\QuickLaunch');
DeleteSchedulerTask('Microsoft\Windows\PerfTrack\UtcTimeViewer');
DeleteSchedulerTask('Microsoft\Windows\Starter');
DeleteSchedulerTask('Opera scheduled assistant Autoupdate 1559225507');
DeleteSchedulerTask('Opera scheduled Autoupdate 1559225505');
DeleteSchedulerTask('QpSoxVj');
DeleteSchedulerTask('ueQQxKuCSAVWe2');
DeleteSchedulerTask('Windows Update');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteRepair(21);
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.