Код:
begin
TerminateProcessByName('C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe');
TerminateProcessByName('C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe');
TerminateProcessByName('c:\programdata\serfev\serfev.exe');
StopService('ReimageRealTimeProtector');
StopService('serfev');
QuarantineFile('C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe', '');
QuarantineFile('C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe', '');
QuarantineFile('c:\programdata\serfev\serfev.exe', '');
QuarantineFile('C:\Program Files (x86)\28354751-1448473675-DF11-B8FE-705AB686D7A0\hnsuECF0.tmp', '');
QuarantineFile('C:\Program Files (x86)\Manager\Manager.exe', '');
QuarantineFile('C:\Program Files (x86)\28354751-1448473675-DF11-B8FE-705AB686D7A0\jnsjCC63.tmp', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\QQPCRtp.exe', '');
QuarantineFile('C:\ProgramData\Ronzap\Ronzap.exe', '');
QuarantineFile('C:\Program Files (x86)\28354751-1448473675-DF11-B8FE-705AB686D7A0\knsr8027.tmp', '');
QuarantineFile('C:\Windows\svchost.exe', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\QMUdisk64.sys', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\softaal64.sys', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TsDefenseBT64.sys', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TsNetHlpX64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\tsskx64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\ynhdufuv.sys', '');
QuarantineFile('C:\Program Files (x86)\MTV20160128\MTView.exe', '');
QuarantineFile('C:\ProgramData\serfev\San-Fax.dll', '');
QuarantineFile('C:\ProgramData\serfev\ZenTouch.dll', '');
QuarantineFile('C:\Users\Romanyuk\AppData\Local\jaPkI\ooPJGymF0.bat', '');
QuarantineFile('C:\ProgramData\wuTAieQ\cwPWTgwwGT0.bat', '');
QuarantineFile('C:\Program Files (x86)\Common Files\Baidu\WebSafe\WebMonBHO.dll', '');
QuarantineFile('C:\Program Files (x86)\Torrent Search\IEEF\J9XxfYKVq7YT.dll', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\Med-Com', '');
QuarantineFile('C:\Users\Romanyuk\AppData\Roaming\Media Center Programs\Java\jusched.exe', '');
QuarantineFile('C:\Users\Romanyuk\AppData\Roaming\Steam\Caches\mdm', '');
QuarantineFile('C:\Users\Romanyuk\ReportSender\ReportSender.exe', '');
QuarantineFile('C:\Program Files\Reimage\Reimage Repair\ReimageReminder.exe', '');
QuarantineFile('C:\Windows\csrss.exe', '');
DeleteFile('C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe', '32');
DeleteFile('C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe', '32');
DeleteFile('c:\programdata\serfev\serfev.exe', '32');
DeleteFile('C:\Program Files (x86)\28354751-1448473675-DF11-B8FE-705AB686D7A0\hnsuECF0.tmp', '32');
DeleteFile('C:\Program Files (x86)\Manager\Manager.exe', '32');
DeleteFile('C:\Program Files (x86)\28354751-1448473675-DF11-B8FE-705AB686D7A0\jnsjCC63.tmp', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\QQPCRtp.exe', '32');
DeleteFile('C:\ProgramData\Ronzap\Ronzap.exe', '32');
DeleteFile('C:\Program Files (x86)\28354751-1448473675-DF11-B8FE-705AB686D7A0\knsr8027.tmp', '32');
DeleteFile('C:\Windows\svchost.exe', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\QMUdisk64.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\softaal64.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TsDefenseBT64.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TsNetHlpX64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\tsskx64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\ynhdufuv.sys', '32');
DeleteFile('C:\Program Files (x86)\MTV20160128\MTView.exe', '32');
DeleteFile('C:\ProgramData\serfev\San-Fax.dll', '32');
DeleteFile('C:\ProgramData\serfev\ZenTouch.dll', '32');
DeleteFile('C:\Users\Romanyuk\AppData\Local\jaPkI\ooPJGymF0.bat', '32');
DeleteFile('C:\ProgramData\wuTAieQ\cwPWTgwwGT0.bat', '32');
DeleteFile('C:\Program Files (x86)\Common Files\Baidu\WebSafe\WebMonBHO.dll', '32');
DeleteFile('C:\Program Files (x86)\Torrent Search\IEEF\J9XxfYKVq7YT.dll', '32');
DeleteFile('C:\Windows\system32\config\systemprofile\AppData\Local\Med-Com', '32');
DeleteFile('C:\Users\Romanyuk\AppData\Roaming\Media Center Programs\Java\jusched.exe', '32');
DeleteFile('C:\Users\Romanyuk\AppData\Roaming\Steam\Caches\mdm', '32');
DeleteFile('C:\Users\Romanyuk\ReportSender\ReportSender.exe', '32');
DeleteFile('C:\Program Files\Reimage\Reimage Repair\ReimageReminder.exe', '32');
DeleteFile('C:\Windows\csrss.exe', '32');
DeleteService('ReimageRealTimeProtector');
DeleteService('serfev');
DeleteService('cuzihece');
DeleteService('HHandler Service');
DeleteService('mucifyfy');
DeleteService('QQPCRTP');
DeleteService('Ronzap');
DeleteService('werivuwi');
DeleteService('Windows');
DeleteService('QMUdisk');
DeleteService('softaal');
DeleteService('TsDefenseBt');
DeleteService('tsnethlpx64');
DeleteService('TSSKX64');
DeleteService('ynhdufuv');
DeleteFileMask('C:\Program Files\Reimage', '*', true);
DeleteFileMask('c:\programdata\serfev', '*', true);
DeleteFileMask('C:\Program Files (x86)\Manager', '*', true);
DeleteFileMask('C:\Program Files (x86)\Tencent', '*', true);
DeleteFileMask('C:\ProgramData\Ronzap', '*', true);
DeleteFileMask('C:\Program Files (x86)\MTV20160128', '*', true);
DeleteFileMask('C:\Program Files (x86)\Common Files\Baidu', '*', true);
DeleteFileMask('C:\Program Files (x86)\Torrent Search', '*', true);
DeleteFileMask('C:\Users\Romanyuk\AppData\Roaming\Media Center Programs', '*', true);
DeleteFileMask('C:\Users\Romanyuk\AppData\Roaming\Steam\Caches', '*', true);
DeleteFileMask('C:\Users\Romanyuk\ReportSender', '*', true);
DeleteDirectory('C:\Program Files\Reimage');
DeleteDirectory('c:\programdata\serfev');
DeleteDirectory('C:\Program Files (x86)\Manager');
DeleteDirectory('C:\Program Files (x86)\Tencent');
DeleteDirectory('C:\ProgramData\Ronzap');
DeleteDirectory('C:\Program Files (x86)\MTV20160128');
DeleteDirectory('C:\Program Files (x86)\Common Files\Baidu');
DeleteDirectory('C:\Program Files (x86)\Torrent Search');
DeleteDirectory('C:\Users\Romanyuk\AppData\Roaming\Media Center Programs');
DeleteDirectory('C:\Users\Romanyuk\AppData\Roaming\Steam\Caches');
DeleteDirectory('C:\Users\Romanyuk\ReportSender');
DelBHO('{15DEE173-1BE9-4424-81E0-58A87076E9B1}');
DelBHO('{6E727987-C8EA-44DA-8749-310C0FBE3C3E}');
DelBHO('{03AE1B7B-A9E7-4D5A-9D34-89999C31B659}');
ExecuteFile('schtasks.exe', '/delete /TN "downyoadup" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Java Update Schedule" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "MdmUpdateTaskMachineCore" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ReportSender" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Reimage Reminder" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ReimageUpdater" /F', 0, 15000, true);
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'MTview');
ExecuteSysClean;
ExecuteRepair(13);
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.