Код:
begin
TerminateProcessByName('C:\Program Files\UBar\UbarService.exe');
TerminateProcessByName('C:\Program Files\UBar\ubar.exe');
TerminateProcessByName('c:\users\fbi\appdata\local\03000200-1445713163-0500-0006-000700080009\snsn825d.tmp');
TerminateProcessByName('c:\program files (x86)\03000200-1445684270-0500-0006-000700080009\knsn3e34.tmpfs');
TerminateProcessByName('c:\program files (x86)\03000200-1445684270-0500-0006-000700080009\jnss6b23.tmp');
QuarantineFile('C:\Users\FBI\appdata\roaming\aspackage\aspackage.exe', '');
QuarantineFile('C:\Program Files (x86)\Torrent Search\aH8A6wF.exe', '');
QuarantineFile('C:\Program Files (x86)\Internet Explorer\iexplore.bat', '');
QuarantineFile('C:\Users\FBI\AppData\Local\Google\Chrome\Application\chrome.bat', '');
QuarantineFile('C:\Users\FBI\AppData\Local\valuablecoupons\valuablecoupons_stb.exe', '');
QuarantineFile('C:\Program Files\UBar\UbarDriver.sys', '');
QuarantineFile('C:\Program Files\UBar\UbarService.exe', '');
QuarantineFile('C:\Program Files\UBar\ubar.exe', '');
QuarantineFile('c:\users\fbi\appdata\local\03000200-1445713163-0500-0006-000700080009\snsn825d.tmp', '');
QuarantineFile('c:\program files (x86)\03000200-1445684270-0500-0006-000700080009\knsn3e34.tmpfs', '');
QuarantineFile('c:\program files (x86)\03000200-1445684270-0500-0006-000700080009\jnss6b23.tmp', '');
DeleteFile('c:\program files (x86)\03000200-1445684270-0500-0006-000700080009\jnss6b23.tmp', '32');
DeleteFile('c:\program files (x86)\03000200-1445684270-0500-0006-000700080009\knsn3e34.tmpfs', '32');
DeleteFile('c:\users\fbi\appdata\local\03000200-1445713163-0500-0006-000700080009\snsn825d.tmp', '32');
DeleteFile('C:\Program Files\UBar\ubar.exe', '32');
DeleteFile('C:\Program Files\UBar\UbarService.exe', '32');
DeleteFile('C:\Program Files\UBar\UbarDriver.sys', '32');
DeleteFile('C:\Users\FBI\AppData\Local\valuablecoupons\valuablecoupons_stb.exe', '32');
DeleteFile('C:\Users\FBI\AppData\Local\valuablecoupons\config.json', '32');
DeleteFile('C:\Users\FBI\AppData\Local\Google\Chrome\Application\chrome.bat', '32');
DeleteFile('C:\Program Files (x86)\Internet Explorer\iexplore.bat', '32');
DeleteFile('C:\Program Files (x86)\Torrent Search\aH8A6wF.exe', '32');
DeleteFile('C:\Windows\Tasks\Update Service for Torrent Search.job', '32');
DeleteFile('C:\Windows\Tasks\Update Service for Torrent Search2.job', '32');
DeleteFile('C:\Users\FBI\appdata\roaming\aspackage\aspackage.exe', '32');
DeleteFileMask('C:\Users\FBI\appdata\roaming\aspackage', '*', true);
DeleteFileMask('C:\Program Files (x86)\Torrent Search', '*', true);
DeleteFileMask('C:\Program Files\UBar', '*', true);
DeleteFileMask('c:\users\fbi\appdata\local\03000200-1445713163-0500-0006-000700080009', '*', true);
DeleteFileMask('c:\program files (x86)\03000200-1445684270-0500-0006-000700080009', '*', true);
DeleteFileMask('C:\Users\FBI\AppData\Local\valuablecoupons', '*', true);
DeleteDirectory('C:\Users\FBI\appdata\roaming\aspackage');
DeleteDirectory('C:\Program Files (x86)\Torrent Search');
DeleteDirectory('C:\Program Files\UBar');
DeleteDirectory('c:\users\fbi\appdata\local\03000200-1445713163-0500-0006-000700080009');
DeleteDirectory('c:\program files (x86)\03000200-1445684270-0500-0006-000700080009');
DeleteDirectory('C:\Users\FBI\AppData\Local\valuablecoupons');
DelBHO('{6E727987-C8EA-44DA-8749-310C0FBE3C3E}');
ExecuteFile('schtasks.exe', '/delete /TN "Update Service for Torrent Search" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Update Service for Torrent Search2" /F', 0, 15000, true);
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\valuablecoupons', 'command');
ExecuteSysClean;
RebootWindows(true);
end.
Компьютер перезагрузится.