Код:
begin
QuarantineFile('C:\Program Files\Advanced PC Care\advancedpccare.exe', '');
QuarantineFile('C:\ProgramData\Appverifier\AppVerifierService.exe', '');
QuarantineFile('c:\program files (x86)\1e00db00-1455989441-4700-5799-f46d04ad3fb1\knsm3412.tmp', '');
QuarantineFile('c:\users\rkh\appdata\local\mail.ru\mailruupdater.exe', '');
QuarantineFile('c:\program files (x86)\mail.ru\mailruupdater\mailruupdater.exe', '');
QuarantineFile('c:\program files (x86)\mtv20160128\mtview.exe', '');
QuarantineFile('c:\program files (x86)\universal driver updater\universaldriverupdater.exe', '');
QuarantineFile('C:\Program Files (x86)\1E00DB00-1455989441-4700-5799-F46D04AD3FB1\knsc2E0.tmp', '');
QuarantineFile('C:\Program Files (x86)\1E00DB00-1455989441-4700-5799-F46D04AD3FB1\hnstCB6B.tmp', '');
QuarantineFile('C:\Program Files (x86)\IconRunner\MoneyBot.exe', '');
QuarantineFile('C:\Program Files (x86)\mpck_en_005030252\mpck_en_005030252.exe', '');
QuarantineFile('C:\Program Files (x86)\Max Driver Updater\idscservice.exe', '');
QuarantineFile('C:\ProgramData\rhNBGobx\SLdibS0.bat', '');
QuarantineFile('C:\ProgramData\yfWlMVFzW\HGQFqei5.bat', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Baidu\WebSafe\WebMonBHO.dll', '');
QuarantineFile('C:\Users\RKh\AppData\Roaming\567377707A_1036\kCv30ZrefA.exe', '');
QuarantineFile('C:\Users\RKh\AppData\Roaming\FreeVPN\FreeVPN.exe', '');
QuarantineFile('C:\Users\RKh\AppData\Local\Hostinstaller\1180473850_installcube.exe', '');
QuarantineFile('C:\Users\RKh\AppData\Local\SystemMonitor2016\1180473850.exe', '');
DeleteFile('C:\Windows\Tasks\567377707A_1036.job', '64');
DeleteFile('C:\Program Files\Advanced PC Care\advancedpccare.exe', '32');
DeleteFile('c:\users\rkh\appdata\local\amigo\application\amigo.exe', '32');
DeleteFile('c:\users\rkh\appdata\local\amigo\application\44.4.2403.3\amigo_cr.exe', '32');
DeleteFile('C:\ProgramData\Appverifier\AppVerifierService.exe', '32');
DeleteFile('c:\program files (x86)\baidu\baiduan\4.0.0.8029\baiduansvc.exe', '32');
DeleteFile('c:\program files (x86)\baidu\baiduan\4.0.0.8029\baiduantray.exe', '32');
DeleteFile('c:\program files (x86)\common files\baidu\baiduhips\1.2.0.892\baiduhips.exe', '32');
DeleteFile('c:\program files (x86)\common files\baidu\bddownload\108\bddownloader.exe', '32');
DeleteFile('c:\program files (x86)\1e00db00-1455989441-4700-5799-f46d04ad3fb1\knsm3412.tmp', '32');
DeleteFile('c:\users\rkh\appdata\local\mail.ru\mailruupdater.exe', '32');
DeleteFile('c:\program files (x86)\mail.ru\mailruupdater\mailruupdater.exe', '32');
DeleteFile('c:\program files (x86)\mtv20160128\mtview.exe', '32');
DeleteFile('c:\program files (x86)\tencent\qqpcmgr\11.3.17201.218\qmchext.exe', '32');
DeleteFile('c:\program files (x86)\tencent\qqpcmgr\11.3.17201.218\qmsignscan.exe', '32');
DeleteFile('c:\program files (x86)\tencent\qqpcmgr\11.3.17201.218\qqpcleakscan.exe', '32');
DeleteFile('c:\program files (x86)\tencent\qqpcmgr\11.3.17201.218\plugins\qmnetmon\qqpcnetflow.exe', '32');
DeleteFile('c:\program files (x86)\tencent\qqpcmgr\11.3.17201.218\qqpcrealtimespeedup.exe', '32');
DeleteFile('c:\program files (x86)\tencent\qqpcmgr\11.3.17201.218\qqpcrtp.exe', '32');
DeleteFile('c:\program files (x86)\tencent\qqpcmgr\11.3.17201.218\qqpctray.exe', '32');
DeleteFile('c:\program files (x86)\universal driver updater\universaldriverupdater.exe', '32');
DeleteFile('C:\ProgramData\Tencent\TSVulFw\TSVulFW.DAT', '32');
DeleteFile('C:\Program Files (x86)\1E00DB00-1455989441-4700-5799-F46D04AD3FB1\knsc2E0.tmp', '32');
DeleteFile('C:\Program Files (x86)\1E00DB00-1455989441-4700-5799-F46D04AD3FB1\hnstCB6B.tmp', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\QMUdisk64.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\QQSysMonX64.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\softaal64.sys', '32');
DeleteFile('C:\Windows\system32\Drivers\TAOAccelerator64.sys', '32');
DeleteFile('C:\Windows\system32\Drivers\TAOKernel64.sys', '32');
DeleteFile('C:\Windows\system32\Drivers\TFsFltX64.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TS888x64.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TsNetHlpX64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\tsskx64.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TSSysKit64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\BDEnhanceBoost.sys', '32');
DeleteFile('C:\Windows\system32\drivers\swsedrvr_vt_1_10_0_25.sys', '32');
DeleteFile('C:\Program Files (x86)\IconRunner\MoneyBot.exe', '32');
DeleteFile('C:\Program Files (x86)\mpck_en_005030252\mpck_en_005030252.exe', '32');
DeleteFile('C:\Program Files (x86)\Baidu\BaiduAn\4.0.0.8029\BDSWShellExt.dll', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\QMContextScan.dll', '32');
DeleteFile('C:\Program Files (x86)\Max Driver Updater\idscservice.exe', '32');
DeleteFile('C:\ProgramData\rhNBGobx\SLdibS0.bat', '32');
DeleteFile('C:\ProgramData\yfWlMVFzW\HGQFqei5.bat', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Baidu\WebSafe\WebMonBHO.dll', '32');
DeleteFile('C:\Users\RKh\AppData\Roaming\567377707A_1036\kCv30ZrefA.exe', '32');
DeleteFile('C:\Users\RKh\AppData\Roaming\FreeVPN\FreeVPN.exe', '32');
DeleteFile('C:\Users\RKh\AppData\Local\Hostinstaller\1180473850_installcube.exe', '32');
DeleteFile('C:\Users\RKh\AppData\Local\SystemMonitor2016\1180473850.exe', '32');
DeleteFile('C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe', '32');
DeleteService('AppVerifier');
DeleteService('BaiduHips');
DeleteService('BDMRTP');
DeleteService('niderymuzbt');
DeleteService('QQPCRTP');
DeleteService('Updater.Mail.Ru');
DeleteService('mitymelizbt');
DeleteService('wucotusy');
DeleteService('QMUdisk');
DeleteService('QQSysMonX64');
DeleteService('softaal');
DeleteService('TAOAccelerator');
DeleteService('TAOKernelDriver');
DeleteService('TFsFlt');
DeleteService('TS888x64');
DeleteService('tsnethlpx64');
DeleteService('TSSKX64');
DeleteService('TSSysKit');
DeleteService('BDEnhanceBoost');
DeleteService('swsedrvr_vt_1_10_0_25');
DeleteFileMask('C:\Program Files\Advanced PC Care', '*', true);
DeleteFileMask('c:\users\rkh\appdata\local\amigo', '*', true);
DeleteFileMask('C:\ProgramData\Appverifier', '*', true);
DeleteFileMask('c:\program files (x86)\baidu', '*', true);
DeleteFileMask('c:\program files (x86)\common files\baidu', '*', true);
DeleteFileMask('c:\users\rkh\appdata\local\mail.ru', '*', true);
DeleteFileMask('c:\program files (x86)\mail.ru', '*', true);
DeleteFileMask('c:\program files (x86)\mtv20160128', '*', true);
DeleteFileMask('c:\program files (x86)\tencent', '*', true);
DeleteFileMask('c:\program files (x86)\universal driver updater', '*', true);
DeleteFileMask('C:\ProgramData\Tencent', '*', true);
DeleteFileMask('C:\Program Files (x86)\IconRunner', '*', true);
DeleteFileMask('C:\Program Files (x86)\mpck_en_005030252', '*', true);
DeleteFileMask('C:\Program Files (x86)\Max Driver Updater', '*', true);
DeleteFileMask('C:\Users\RKh\AppData\Roaming\567377707A_1036', '*', true);
DeleteFileMask('C:\Users\RKh\AppData\Roaming\FreeVPN', '*', true);
DeleteFileMask('C:\Users\RKh\AppData\Local\Hostinstaller', '*', true);
DeleteFileMask('C:\Program Files (x86)\IObit', '*', true);
DeleteDirectory('C:\Program Files\Advanced PC Care');
DeleteDirectory('c:\users\rkh\appdata\local\amigo');
DeleteDirectory('C:\ProgramData\Appverifier');
DeleteDirectory('c:\program files (x86)\baidu');
DeleteDirectory('c:\program files (x86)\common files\baidu');
DeleteDirectory('c:\users\rkh\appdata\local\mail.ru');
DeleteDirectory('c:\program files (x86)\mail.ru');
DeleteDirectory('c:\program files (x86)\mtv20160128');
DeleteDirectory('c:\program files (x86)\tencent');
DeleteDirectory('c:\program files (x86)\universal driver updater');
DeleteDirectory('C:\ProgramData\Tencent');
DeleteDirectory('C:\Program Files (x86)\IconRunner');
DeleteDirectory('C:\Program Files (x86)\mpck_en_005030252');
DeleteDirectory('C:\Program Files (x86)\Max Driver Updater');
DeleteDirectory('C:\Users\RKh\AppData\Roaming\567377707A_1036');
DeleteDirectory('C:\Users\RKh\AppData\Roaming\FreeVPN');
DeleteDirectory('C:\Users\RKh\AppData\Local\Hostinstaller');
DeleteDirectory('C:\Program Files (x86)\IObit');
DelBHO('{15DEE173-1BE9-4424-81E0-58A87076E9B1}');
ExecuteFile('schtasks.exe', '/delete /TN "567377707A_1036" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Advanced PC Care_Logon" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "MailRuUpdater" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "FreeVPN" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Soft installer" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SystemMonitor2016" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Uninstaller_SkipUac_RKh" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Start Universal Driver Updater оn logon" /F', 0, 15000, true);
DelCLSID('{11292110-6F8D-4D56-863C-44902A1E7880}');
DelCLSID('{63332668-8CE1-445D-A5EE-25929176714E}');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Adobe Flash Player SU');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'IconRunner');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'mpck_en_005030252');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'MTview');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'BaiduAnTray');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', ' QQPCTray');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'amigo');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'MailRuUpdater');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved', '{11292110-6F8D-4D56-863C-44902A1E7880}');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved', '{63332668-8CE1-445D-A5EE-25929176714E}');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'IDSCPRODUCT');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.