Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\users\user\appdata\local\amigo\application\44.4.2403.3\amigo_cr.exe');
TerminateProcessByName('c:\users\user\appdata\local\mail.ru\mailruupdater.exe');
TerminateProcessByName('c:\program files\mail.ru\mailruupdater\mailruupdater.exe');
TerminateProcessByName('c:\windows\system32\searchprotectservice.exe');
TerminateProcessByName('c:\program files\ubar\ubar.exe');
TerminateProcessByName('c:\program files\ubar\ubarservice.exe');
StopService('SPS');
StopService('UbarPolicyProvider');
StopService('Updater.Mail.Ru');
StopService('TsFltMgr');
StopService('UbarCalloutDriver');
QuarantineFile('c:\users\user\appdata\local\amigo\application\44.4.2403.3\amigo_cr.exe', '');
QuarantineFile('c:\users\user\appdata\local\mail.ru\mailruupdater.exe', '');
QuarantineFile('c:\program files\mail.ru\mailruupdater\mailruupdater.exe', '');
QuarantineFile('c:\windows\system32\searchprotectservice.exe', '');
QuarantineFile('c:\program files\ubar\ubar.exe', '');
QuarantineFile('c:\program files\ubar\ubarservice.exe', '');
QuarantineFile('C:\Program Files\Tencent\QQPCMgr\11.1.16923.222\QMContextUninstall.dll', '');
QuarantineFile('C:\Program Files\Tencent\QQPCMgr\11.1.16923.222\QMContextScan.dll', '');
QuarantineFile('C:\Windows\system32\Drivers\TsFltMgr.sys', '');
QuarantineFile('C:\Program Files\UBar\UbarDriver.sys', '');
QuarantineFile('C:\Program Files\Mobogenie\DaemonProcess.exe', '');
QuarantineFile('C:\Windows\system32\GroupPolicy\Machine\Registry.pol', '');
QuarantineFile('C:\Windows\system32\GroupPolicy\Machine\R', '');
QuarantineFile('C:\Users\User\AppData\Local\Amigo\Application\amigo.exe', '');
QuarantineFile('C:\Users\User\AppData\Local\Hostinstaller\1511034642_monster.exe', '');
QuarantineFile('C:\Users\User\AppData\Local\SystemMonitor2016\1511034642.exe', '');
QuarantineFile('C:\Users\User\appdata\roaming\daemon2.exe', '');
DeleteFile('c:\users\user\appdata\local\amigo\application\44.4.2403.3\amigo_cr.exe', '32');
DeleteFile('c:\users\user\appdata\local\mail.ru\mailruupdater.exe', '32');
DeleteFile('c:\program files\mail.ru\mailruupdater\mailruupdater.exe', '32');
DeleteFile('c:\windows\system32\searchprotectservice.exe', '32');
DeleteFile('c:\program files\ubar\ubar.exe', '32');
DeleteFile('c:\program files\ubar\ubarservice.exe', '32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\11.1.16923.222\QMContextUninstall.dll', '32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\11.1.16923.222\QMContextScan.dll', '32');
DeleteFile('C:\Windows\system32\Drivers\TsFltMgr.sys', '32');
DeleteFile('C:\Program Files\UBar\UbarDriver.sys', '32');
DeleteFile('C:\Program Files\Mobogenie\DaemonProcess.exe', '32');
DeleteFile('C:\Windows\system32\GroupPolicy\Machine\Registry.pol', '32');
DeleteFile('C:\Windows\system32\GroupPolicy\Machine\R', '32');
DeleteFile('C:\Users\User\AppData\Local\Amigo\Application\amigo.exe', '32');
DeleteFile('C:\Users\User\AppData\Local\Hostinstaller\1511034642_monster.exe', '32');
DeleteFile('C:\Users\User\AppData\Local\SystemMonitor2016\1511034642.exe', '32');
DeleteFile('C:\Users\User\appdata\roaming\daemon2.exe', '32');
DeleteService('SPS');
DeleteService('UbarPolicyProvider');
DeleteService('Updater.Mail.Ru');
DeleteService('TsFltMgr');
DeleteService('UbarCalloutDriver');
DeleteFileMask('c:\users\user\appdata\local\amigo', '*', true);
DeleteFileMask('c:\users\user\appdata\local\mail.ru', '*', true);
DeleteFileMask('c:\program files\mail.ru', '*', true);
DeleteFileMask('c:\program files\ubar', '*', true);
DeleteFileMask('C:\Program Files\Tencent', '*', true);
DeleteFileMask('C:\Program Files\Mobogenie', '*', true);
DeleteFileMask('C:\Users\User\AppData\Local\Hostinstaller', '*', true);
DeleteDirectory('c:\users\user\appdata\local\amigo');
DeleteDirectory('c:\users\user\appdata\local\mail.ru');
DeleteDirectory('c:\program files\mail.ru');
DeleteDirectory('c:\program files\ubar');
DeleteDirectory('C:\Program Files\Tencent');
DeleteDirectory('C:\Program Files\Mobogenie');
DeleteDirectory('C:\Users\User\AppData\Local\Hostinstaller');
ExecuteFile('schtasks.exe', '/delete /TN "Soft installer" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SystemMonitor2016" /F', 0, 15000, true);
DelCLSID('{CBDECEF7-7A29-4cbf-A009-2673D82C7BF9}');
DelCLSID('{63332668-8CE1-445D-A5EE-25929176714E}');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'mobilegeni daemon');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'C');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'MailRuUpdater');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'amigo');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved', '{CBDECEF7-7A29-4cbf-A009-2673D82C7BF9}');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved', '{63332668-8CE1-445D-A5EE-25929176714E}');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Advair');
BC_ImportALL;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
ExecuteRepair(23);
ExecuteRepair(2);
ExecuteRepair(4);
ExecuteRepair(3);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.