Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
QuarantineFile('C:\ProgramData\windowstask\amd.exe', '');
QuarantineFile('C:\ProgramData\windowstask\appmodule.exe', '');
QuarantineFile('C:\Users\Tom\AppData\Local\Adaware\GenericSetup.exe_Url_csbf2bdrxkuyl0kstwo40arljrnqpgpv\1.0.0.4630\xpcom_core.dll', '');
QuarantineFile('C:\Users\Tom\AppData\Local\NVIDIA\cf123937\voplayer.exe', '');
QuarantineFile('C:\Users\Tom\AppData\Local\PowerMonitor\PowerMonitor.exe', '');
QuarantineFile('C:\Users\Tom\AppData\Roaming\firefox.exe', '');
QuarantineFile('C:\Users\Tom\AppData\Roaming\npm\node_modules\pm2-windows-startup\invisible.vbs', '');
QuarantineFile('C:\Users\Tom\AppData\Roaming\npm\node_modules\pm2-windows-startup\pm2_resurrect.cmd', '');
QuarantineFileF('c:\users\tom\appdata\local\adaware', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\users\tom\appdata\local\nvidia\cf123937', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\users\tom\appdata\roaming\npm', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
DeleteFile('C:\ProgramData\windowstask\amd.exe', '');
DeleteFile('C:\ProgramData\windowstask\appmodule.exe', '');
DeleteFile('C:\ProgramData\windowstask\xmrig-cuda.dll', '');
DeleteFile('C:\Users\Tom\AppData\Local\Adaware\GenericSetup.exe_Url_csbf2bdrxkuyl0kstwo40arljrnqpgpv\1.0.0.4630\xpcom_core.dll', '');
DeleteFile('C:\Users\Tom\AppData\Local\NVIDIA\cf123937\voplayer.exe', '32');
DeleteFile('C:\Users\Tom\AppData\Local\NVIDIA\cf123937\voplayer.exe', '64');
DeleteFile('C:\Users\Tom\AppData\Local\PowerMonitor\PowerMonitor.exe', '64');
DeleteFile('C:\Users\Tom\AppData\Roaming\firefox.exe', '32');
DeleteFile('C:\Users\Tom\AppData\Roaming\firefox.exe', '64');
DeleteFile('C:\Users\Tom\AppData\Roaming\npm\node_modules\pm2-windows-startup\invisible.vbs', '32');
DeleteFile('C:\Users\Tom\AppData\Roaming\npm\node_modules\pm2-windows-startup\invisible.vbs', '64');
DeleteFile('C:\Users\Tom\AppData\Roaming\npm\node_modules\pm2-windows-startup\pm2_resurrect.cmd', '32');
DeleteFile('C:\Users\Tom\AppData\Roaming\npm\node_modules\pm2-windows-startup\pm2_resurrect.cmd', '64');
DeleteFileMask('c:\programdata\windowstask', '*', true);
DeleteFileMask('c:\users\tom\appdata\local\adaware', '*', true);
DeleteFileMask('c:\users\tom\appdata\local\nvidia\cf123937', '*', true);
DeleteFileMask('c:\users\tom\appdata\local\powermonitor', '*', true);
DeleteFileMask('c:\users\tom\appdata\roaming\npm', '*', true);
DeleteDirectory('c:\programdata\windowstask');
DeleteDirectory('c:\users\tom\appdata\local\adaware');
DeleteDirectory('c:\users\tom\appdata\local\nvidia\cf123937');
DeleteDirectory('c:\users\tom\appdata\local\powermonitor');
DeleteDirectory('c:\users\tom\appdata\roaming\npm');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'PM2', '32');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'PM2', '64');
DeleteSchedulerTask('C:\WINDOWS\Task\firefox.job');
DeleteSchedulerTask('C:\WINDOWS\Task\voplayer.job');
DeleteSchedulerTask('firefox');
DeleteSchedulerTask('PowerMonitor');
DeleteSchedulerTask('Sump Task (One-Time)');
DeleteSchedulerTask('voplayer');
DeleteSchedulerTask('WiseCleaner\WRCSkipUAC');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
RebootWindows(true);
end.
Компьютер перезагрузится.