Код:
begin
QuarantineFile('C:\Users\zz\AppData\Local\Hostinstaller\975215560_monster.exe','');
QuarantineFile('C:\Users\zz\AppData\Local\SearchGo\searchgo.exe','');
QuarantineFile('C:\Users\zz\AppData\Local\PowerMonitor\PowerMonitor.exe','');
QuarantineFile('C:\Users\zz\AppData\Local\fupdate\fupdate.exe','');
QuarantineFile('C:\Program Files (x86)\VK OK AdBlock\tX9fFsH.exe','');
DelCLSID('{754DF2CE-51E8-4895-B53C-6381418B84AE}');
DelBHO('{03AE1B7B-A9E7-4D5A-9D34-89999C31B659}');
DelBHO('{6E727987-C8EA-44DA-8749-310C0FBE3C3E}');
QuarantineFile('C:\ProgramData\TimeTasks\timetasks.exe','');
DeleteService('tsnethlpx64');
DeleteService('swsedrvr_vw_1_10_0_25');
DeleteService('SRepairDrv');
DeleteService('SPBIUpdd');
DeleteService('softaal');
DeleteService('QMUdisk');
DeleteService('vehuqipo');
DeleteService('totyseku');
DeleteService('SPBIUpd');
DeleteService('rijufoze');
DeleteService('lekycykezbt');
DeleteService('jivucibizbt');
DeleteService('hotnix32');
DeleteService('GoogleChromeUpService');
DeleteService('gerocyni');
DeleteService('ContentProtectorUpdate');
DeleteService('ContentProtector');
DeleteService('AppthgildeM');
DeleteService('ApplicationHosting');
DeleteService('ADSafeSvc');
StopService('Bonjoiur Host Controller');
DeleteService('Bonjoiur Host Controller');
TerminateProcessByName('c:\users\zz\appdata\roaming\nssm.exe');
QuarantineFile('c:\users\zz\appdata\roaming\nssm.exe','');
TerminateProcessByName('c:\program files (x86)\bonjoiur host controller\bhctrl32.exe');
QuarantineFile('c:\program files (x86)\bonjoiur host controller\bhctrl32.exe','');
DeleteFile('c:\program files (x86)\bonjoiur host controller\bhctrl32.exe','32');
DeleteFile('c:\users\zz\appdata\roaming\nssm.exe','32');
DeleteFile('C:\Program Files (x86)\ADSafe\ADSafeSvc.exe','32');
DeleteFile('C:\ProgramData\ApplicationHosting\ApplicationHosting.exe','32');
DeleteFile('C:\Program Files (x86)\19879E3F-1459479071-FA45-B290-2C600C894AFE\knsrC397.tmp','32');
DeleteFile('C:\Program Files (x86)\19879E3F-1459479071-FA45-B290-2C600C894AFE\knsi7CA0.tmp','32');
DeleteFile('C:\Program Files\Common Files\ShopperPro\spbiu.exe','32');
DeleteFile('C:\Program Files (x86)\19879E3F-1440821282-FA45-B290-2C600C894AFE\hnsb2904.tmp','32');
DeleteFile('C:\Program Files (x86)\19879E3F-1440821282-FA45-B290-2C600C894AFE\knsdE852.tmp','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMUdisk64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17339.217\softaal64.sys','32');
DeleteFile('C:\Program Files\Common Files\ShopperPro\spbiw.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\SRepairDrv','32');
DeleteFile('C:\Windows\system32\drivers\swsedrvr_vw_1_10_0_25.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17339.217\TsNetHlpX64.sys','32');
DeleteFile('D:\Documents\systemfile.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','SystemClose');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','apphide');
DeleteFile('C:\Program Files (x86)\badu\uc.exe','32');
DeleteFile('C:\Program Files (x86)\badu\sys.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','app');
DeleteFile('C:\ProgramData\TimeTasks\timetasks.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run-','Timestasks');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run-','Tencent');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','pwbdwiamgn');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','svchost0');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','apphide');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Google Chrome');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Visual C++ 2010');
DeleteFile('C:\Users\zz\AppData\Roaming\cppredistx86.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run-','ppvxdegowo');
DeleteFile('C:\Program Files (x86)\Torrent Search\IEEF\uNaRp1RpKmSW.dll','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17339.217\plugins\FileSmash\QMSoftExt.dll','32');
DeleteFile('C:\Program Files (x86)\VK OK AdBlock\tX9fFsH.exe','32');
DeleteFile('C:\Windows\Tasks\Update Service for VK OK AdBlock.job','32');
DeleteFile('C:\Windows\Tasks\Update Service for VK OK AdBlock2.job','32');
DeleteFile('C:\Windows\system32\Tasks\fupdate','64');
DeleteFile('C:\Users\zz\AppData\Local\fupdate\fupdate.exe','32');
DeleteFile('C:\Windows\system32\Tasks\ipro2','64');
DeleteFile('C:\Windows\system32\Tasks\PowerMonitor','64');
DeleteFile('C:\Users\zz\AppData\Local\PowerMonitor\PowerMonitor.exe','32');
DeleteFile('C:\Windows\system32\Tasks\SearchGo Task','64');
DeleteFile('C:\Users\zz\AppData\Local\SearchGo\searchgo.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Soft installer','64');
DeleteFile('C:\Users\zz\AppData\Local\Hostinstaller\975215560_monster.exe','32');
DeleteFile('C:\Windows\system32\Tasks\SystemMonitor2016','64');
DeleteFile('C:\Windows\system32\Tasks\Update Service for VK OK AdBlock','64');
DeleteFile('C:\Windows\system32\Tasks\Update Service for VK OK AdBlock2','64');
ExecuteSysClean;
RebootWindows(true);
end.