Код:
begin
TerminateProcessByName('c:\program files\searchsnacks\service\sssvc.exe');
TerminateProcessByName('c:\program files\v-bates\notifier.exe');
TerminateProcessByName('c:\program files\v-bates\guardsvc.exe');
StopService('V-bates Updater');
QuarantineFile('C:\Users\user\appdata\roaming\newsi_2\s_inst.exe','');
QuarantineFile('C:\Users\user\appdata\roaming\newsi_10\s_inst.exe','');
QuarantineFile('C:\Program Files\V-bates\startsc.bat','');
QuarantineFile('C:\Program Files\V-bates\PrefHelper.exe','');
QuarantineFile('C:\Users\user\AppData\Roaming\DIGITA~2\UPDATE~1\UPDATE~1.EXE','');
QuarantineFile('C:\Program Files\SearchSnacks\IE\SearchSnacksClientIE.dll','');
QuarantineFile('C:\Program Files\V-bates\Extension32.dll','');
QuarantineFile('C:\Program Files\V-bates\ExtensionUpdaterService.exe','');
QuarantineFile('c:\program files\searchsnacks\service\sssvc.exe','');
QuarantineFile('c:\program files\v-bates\notifier.exe','');
QuarantineFile('c:\program files\v-bates\guardsvc.exe','');
DeleteFile('c:\program files\v-bates\guardsvc.exe','32');
DeleteFile('c:\program files\searchsnacks\service\sssvc.exe','32');
DeleteFile('C:\Program Files\V-bates\libinject.dll','32');
DeleteFile('C:\Program Files\V-bates\ExtensionUpdaterService.exe','32');
DeleteFile('C:\Program Files\V-bates\notifier.exe','32');
DeleteFile('C:\Program Files\V-bates\Extension32.dll','32');
DeleteFile('C:\Program Files\SearchSnacks\IE\SearchSnacksClientIE.dll','32');
DeleteFile('C:\Users\user\AppData\Roaming\DIGITA~2\UPDATE~1\UPDATE~1.EXE','32');
DeleteFile('C:\Windows\Tasks\Digital Sites.job','32');
DeleteFile('C:\Program Files\V-bates\PrefHelper.exe','32');
DeleteFile('C:\Windows\Tasks\FF Watcher {10296F25-EE11-4BBA-9882-4BF8EBF6AF89}.job','32');
DeleteFile('C:\Windows\system32\Tasks\Digital Sites','32');
DeleteFile('C:\Windows\system32\Tasks\FF Watcher {10296F25-EE11-4BBA-9882-4BF8EBF6AF89}','32');
DeleteFile('C:\Program Files\V-bates\startsc.bat','32');
DeleteFile('C:\Windows\system32\Tasks\Mext Guard FBE8818C-5B13-48C2-A93E-AD731167DBF2','32');
DeleteFile('C:\Users\user\appdata\roaming\newsi_10\s_inst.exe','32');
DeleteFile('C:\Users\user\appdata\roaming\newsi_2\s_inst.exe','32');
DelBHO('{7D1B27B2-3DE0-4F26-94A0-E14FDB06D292}');
DelBHO('{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','mobilegeni daemon');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','MyCuteBuddy');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GetNowUpdater','command');
RegKeyStrParamWrite('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings', 'ProxyServer', '');
RegKeyParamWrite('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings', 'ProxyEnable', 'REG_DWORD', '0');
DeleteService('V-bates Updater');
DeleteFileMask('C:\Users\user\appdata\roaming\newsi_2','*',true);
DeleteFileMask('C:\Users\user\appdata\roaming\newsi_10','*',true);
DeleteFileMask('C:\Program Files\V-bates','*',true);
DeleteFileMask('C:\Users\user\AppData\Roaming\DIGITA~2\UPDATE~1','*',true);
DeleteFileMask('C:\Program Files\SearchSnacks','*',true);
DeleteDirectory('C:\Users\user\appdata\roaming\newsi_2');
DeleteDirectory('C:\Users\user\appdata\roaming\newsi_10');
DeleteDirectory('C:\Program Files\V-bates');
DeleteDirectory('C:\Users\user\AppData\Roaming\DIGITA~2\UPDATE~1');
DeleteDirectory('C:\Program Files\SearchSnacks');
ExecuteSysClean;
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('SCU',2,2,true);
BC_Activate;
end.
Компьютер перезагрузится.