Код:
begin
TerminateProcessByName('c:\programdata\schedule\timetasks.exe');
TerminateProcessByName('c:\users\Пк\appdata\local\ocrpathwindows\ocrpathwindows.exe');
TerminateProcessByName('c:\windows\syswow64\metafileroottext\metafileroottext.exe');
TerminateProcessByName('c:\program files (x86)\edealpop\edealpop.exe');
StopService('storegidfilter');
StopService('{9edd0ea8-2819-47c2-8320-b007d5996f8a}w64');
QuarantineFile('C:\Users\Пк\appdata\roaming\funspace\shadow\funspace.update\funspace.update.process.exe', '');
QuarantineFile('C:\Users\Пк\AppData\Local\Microsoft\Extensions\safebrowser.exe', '');
QuarantineFile('C:\Program Files\V-bates\startsc.bat', '');
QuarantineFile('C:\ProgramData\Kbrowser utility\kbrowser-updater-utility.exe', '');
QuarantineFile('c:\Users\All Users\dtdata\R001.exe', '');
QuarantineFile('c:\Users\All Users\dtdata\R002.exe', '');
QuarantineFile('c:\Users\All Users\dtdata\R003.exe', '');
QuarantineFile('c:\Users\All Users\dl159\159.dll', '');
QuarantineFile('C:\Windows\SysWow64\config\systemprofile\AppData\Roaming\defaulttab\defaulttab\DefaultTabBHO.dll', '');
QuarantineFile('C:\ProgramData\Program status\scheck.exe', '');
QuarantineFile('C:\Program Files (x86)\eDealsPop\eDealsPop.exe', '');
QuarantineFile('C:\Program Files (x86)\Twilight Tech\Pretty Search\dummyDlg.exe', '');
QuarantineFile('C:\Windows\storegidfilter.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}w64.sys', '');
QuarantineFile('C:\Program Files (x86)\Аудио и видео скачивание\IE\x86\Downloader.dll', '');
QuarantineFile('c:\programdata\schedule\timetasks.exe', '');
QuarantineFile('c:\users\Пк\appdata\local\ocrpathwindows\ocrpathwindows.exe', '');
QuarantineFile('c:\windows\syswow64\metafileroottext\metafileroottext.exe', '');
QuarantineFile('c:\program files (x86)\edealpop\edealpop.exe', '');
DeleteFile('c:\windows\syswow64\metafileroottext\metafileroottext.exe', '32');
DeleteFile('c:\users\Пк\appdata\local\ocrpathwindows\ocrpathwindows.exe', '32');
DeleteFile('C:\Program Files (x86)\Аудио и видео скачивание\IE\x86\Downloader.dll', '32');
DeleteFile('C:\Windows\system32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}w64.sys', '32');
DeleteFile('C:\Windows\storegidfilter.sys', '32');
DeleteFile('C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll', '32');
DeleteFile('C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll', '32');
DeleteFile('C:\Program Files (x86)\Kinoroom Browser\kinoroom-browser.exe', '32');
DeleteFile('C:\Program Files (x86)\Obnovi Soft\ObnoviSoft.exe', '32');
DeleteFile('C:\Program Files (x86)\Twilight Tech\Pretty Search\dummyDlg.exe', '32');
DeleteFile('C:\Program Files (x86)\eDealPop\eDealPop.exe', '32');
DeleteFile('C:\Program Files (x86)\eDealsPop\eDealsPop.exe', '32');
DeleteFile('C:\ProgramData\Program status\scheck.exe', '32');
DeleteFile('C:\ProgramData\Schedule\timetasks.exe', '32');
DeleteFile('C:\Windows\SysWow64\config\systemprofile\AppData\Roaming\defaulttab\defaulttab\DefaultTabBHO.dll', '32');
DeleteFile('c:\Users\All Users\dl159\159.dll', '32');
DeleteFile('C:\Windows\Tasks\AmiUpdXp.job', '32');
DeleteFile('C:\Windows\Tasks\FF Watcher {DB96462B-A355-41CB-918C-08BDF0B42008}.job', '32');
DeleteFile('C:\Windows\Tasks\PC SpeedUp Service Deactivator.job', '32');
DeleteFile('C:\Windows\system32\Tasks\AmiUpdXp', '32');
DeleteFile('C:\Windows\system32\Tasks\DealPly', '32');
DeleteFile('C:\Windows\system32\Tasks\DealPlyUpdate', '32');
DeleteFile('c:\Users\All Users\dtdata\R003.exe', '32');
DeleteFile('c:\Users\All Users\dtdata\R002.exe', '32');
DeleteFile('c:\Users\All Users\dtdata\R001.exe', '32');
DeleteFile('C:\Windows\system32\Tasks\DefaultReg', '32');
DeleteFile('C:\Windows\system32\Tasks\DefaultCheck', '32');
DeleteFile('C:\Windows\system32\Tasks\Default2Check', '32');
DeleteFile('C:\Windows\system32\Tasks\DSite', '32');
DeleteFile('C:\Windows\system32\Tasks\FF Watcher {DB96462B-A355-41CB-918C-08BDF0B42008}', '32');
DeleteFile('C:\ProgramData\Kbrowser utility\kbrowser-updater-utility.exe', '32');
DeleteFile('C:\Windows\system32\Tasks\kbrowser-updater-utility', '32');
DeleteFile('C:\Program Files\V-bates\startsc.bat', '32');
DeleteFile('C:\Windows\system32\Tasks\Mext Guard FBE8818C-5B13-48C2-A93E-AD731167DBF2', '32');
DeleteFile('C:\Users\Пк\AppData\Local\Microsoft\Extensions\safebrowser.exe', '32');
DeleteFile('C:\Windows\system32\Tasks\Safebrowser', '32');
DeleteFile('C:\Users\Пк\appdata\roaming\funspace\shadow\funspace.update\funspace.update.process.exe', '32');
DeleteService('RgFltX64');
DeleteService('RegFltrX64');
DeleteService('storegidfilter');
DeleteService('{9edd0ea8-2819-47c2-8320-b007d5996f8a}w64');
DeleteService('MetafileRootText');
DeleteFileMask('C:\Users\Пк\appdata\roaming\funspace', '*', true);
DeleteFileMask('C:\Users\Пк\AppData\Local\Microsoft\Extensions', '*', true);
DeleteFileMask('C:\Program Files\V-bates', '*', true);
DeleteFileMask('C:\ProgramData\Kbrowser utility', '*', true);
DeleteFileMask('c:\Users\All Users\dtdata', '*', true);
DeleteFileMask('C:\Windows\SysWow64\config\systemprofile\AppData\Roaming\defaulttab', '*', true);
DeleteFileMask('C:\ProgramData\Schedule', '*', true);
DeleteFileMask('C:\ProgramData\Program status', '*', true);
DeleteFileMask('c:\users\Пк\appdata\local\ocrpathwindows', '*', true);
DeleteFileMask('c:\windows\syswow64\metafileroottext', '*', true);
DeleteFileMask('C:\Program Files (x86)\Аудио и видео скачивание', '*', true);
DeleteFileMask('C:\Program Files (x86)\eDealsPop', '*', true);
DeleteFileMask('C:\PROGRA~2\SearchProtect\SearchProtect', '*', true);
DeleteFileMask('C:\Program Files (x86)\Kinoroom Browser', '*', true);
DeleteFileMask('C:\Program Files (x86)\Obnovi Soft', '*', true);
DeleteFileMask('C:\Program Files (x86)\Twilight Tech', '*', true);
DeleteDirectory('C:\Users\Пк\appdata\roaming\funspace');
DeleteDirectory('C:\Users\Пк\AppData\Local\Microsoft\Extensions');
DeleteDirectory('C:\Program Files\V-bates');
DeleteDirectory('C:\ProgramData\Kbrowser utility');
DeleteDirectory('c:\Users\All Users\dtdata');
DeleteDirectory('C:\Windows\SysWow64\config\systemprofile\AppData\Roaming\defaulttab');
DeleteDirectory('C:\ProgramData\Schedule');
DeleteDirectory('C:\ProgramData\Program status');
DeleteDirectory('c:\users\Пк\appdata\local\ocrpathwindows');
DeleteDirectory('c:\windows\syswow64\metafileroottext');
DeleteDirectory('C:\Program Files (x86)\Аудио и видео скачивание');
DeleteDirectory('C:\Program Files (x86)\eDealsPop');
DeleteDirectory('C:\PROGRA~2\SearchProtect\SearchProtect');
DeleteDirectory('C:\Program Files (x86)\Kinoroom Browser');
DeleteDirectory('C:\Program Files (x86)\Obnovi Soft');
DeleteDirectory('C:\Program Files (x86)\Twilight Tech');
DelBHO('{fe704bf8-384b-44e1-8cf2-8dbeb3637a8a}');
DelBHO('{C35B7206-62EB-F808-5475-18A6FDE7DD94}');
DelBHO('{8984B388-A5BB-4DF7-B274-77B879E179DB}');
DelBHO('{7F6AFBF1-E065-4627-A2FD-810366367D01}');
DelBHO('{79E1CFFB-E2E0-436C-B82A-9902BBEA6391}');
DelBHO('{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}');
DelBHO('{0EEDB912-C5FA-486F-8334-57288578C627}');
DelBHO('{57FC7EA7-2F0D-4F3E-89BB-A1651B3F39AA}');
RegKeyParamDel('HKEY_USERS', 'S-1-5-21-2736890739-3939850286-320192451-1000\Software\Microsoft\Windows\CurrentVersion\Run', 'PCSpeedUp');
RegKeyStrParamWrite('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings', 'ProxyServer', '');
RegKeyParamWrite('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings', 'ProxyEnable', 'REG_DWORD', '0');
ExecuteSysClean;
ExecuteRepair(2);
ExecuteRepair(4);
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.