Код:
begin
TerminateProcessByName('c:\program files (x86)\application assistance\apphelper.exe');
QuarantineFile('c:\program files (x86)\application assistance\apphelper.exe','');
QuarantineFile('C:\Program Files (x86)\Microsoft Data\nsi.exe','');
QuarantineFile('C:\Program Files (x86)\ver5SpeeditUp\d1SpeeditUpU54.exe','');
QuarantineFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe','');
QuarantineFile('C:\Users\АдминистраторAppData\Local\10321\a4973.exe','');
DelBHO('{B02B31AE-2C6B-6448-C4B7-F6BC28498D0E}');
DelBHO('{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}');
QuarantineFile('C:\Program Files (x86)\ver5SpeeditUp\189.dll','');
QuarantineFile('C:\Program Files (x86)\XTab\SupTab.dll','');
DelBHO('{17177FAA-3830-43D3-A70B-FDE532676B1E}');
QuarantineFile('C:\Users\АдминистраторAppData\Local\mbot_ru_77\upmbot_ru_77.exe','');
QuarantineFile('C:\Users\АдминистраторAppData\Local\Microsoft\Windows\system.vbs','');
QuarantineFile('C:\Users\АдминистраторAppData\Local\03000200-1425144523-0500-0006-000700080009\bnszF5E6.exe','');
QuarantineFile('C:\Program Files (x86)\WinZipper\eshellctx64.dll','');
QuarantineFile('C:\Windows\system32\DRIVERS\iSafeKrnlBoot.sys','');
DeleteService('dumfzvbn');
DeleteService('BAPIDRV');
QuarantineFile('C:\Windows\system32\Drivers\webTinstMK.sys','');
QuarantineFile('C:\Windows\system32\DRIVERS\iSafeNetFilter.sys','');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys','');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys','');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys','');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys','');
DeleteService('webTinstMK');
DeleteService('iSafeKrnlBoot');
DeleteService('QMUdisk');
DeleteService('iSafeNetFilter');
DeleteService('iSafeKrnlR3');
DeleteService('iSafeKrnlMon');
DeleteService('iSafeKrnlKit');
DeleteService('iSafeKrnl');
DeleteService('servervo');
DeleteService('PennyBee');
DeleteService('IePluginServices');
TerminateProcessByName('c:\program files (x86)\winzipper\winzipersvc.exe');
QuarantineFile('c:\program files (x86)\winzipper\winzipersvc.exe','');
TerminateProcessByName('c:\users\Администраторappdata\local\mbot_ru_77\upmbot_ru_77.exe');
QuarantineFile('c:\users\Администраторappdata\local\mbot_ru_77\upmbot_ru_77.exe','');
TerminateProcessByName('c:\program files (x86)\ask.com\updater\updater.exe');
QuarantineFile('c:\program files (x86)\ask.com\updater\updater.exe','');
TerminateProcessByName('c:\programdata\schedule\timetasks.exe');
QuarantineFile('c:\programdata\schedule\timetasks.exe','');
TerminateProcessByName('c:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe');
QuarantineFile('c:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe','');
TerminateProcessByName('c:\program files\bns\qqpcmgr\10.6.15950.224\taoframe.exe');
QuarantineFile('c:\program files\bns\qqpcmgr\10.6.15950.224\taoframe.exe','');
TerminateProcessByName('c:\users\Администраторappdata\roaming\steam\reversed\steam.exe');
QuarantineFile('c:\users\Администраторappdata\roaming\steam\reversed\steam.exe','');
TerminateProcessByName('c:\users\Администраторappdata\local\03000200-1425144681-0500-0006-000700080009\snsk5784.tmp');
QuarantineFile('c:\users\Администраторappdata\local\03000200-1425144681-0500-0006-000700080009\snsk5784.tmp','');
TerminateProcessByName('c:\program files\bns\qqpcmgr\10.6.15950.224\qqpctray.exe');
QuarantineFile('c:\program files\bns\qqpcmgr\10.6.15950.224\qqpctray.exe','');
TerminateProcessByName('c:\program files\bns\qqpcmgr\10.6.15950.224\qqpcrtp.exe');
QuarantineFile('c:\program files\bns\qqpcmgr\10.6.15950.224\qqpcrtp.exe','');
TerminateProcessByName('c:\program files\bns\qqpcmgr\10.6.15950.224\qmspeedupplugin\phonerocket\dock_5.3.0.3\qqpcphonedock.exe');
QuarantineFile('c:\program files\bns\qqpcmgr\10.6.15950.224\qmspeedupplugin\phonerocket\dock_5.3.0.3\qqpcphonedock.exe','');
TerminateProcessByName('c:\program files\bns\qqpcmgr\10.6.15950.224\qmdl.exe');
QuarantineFile('c:\program files\bns\qqpcmgr\10.6.15950.224\qmdl.exe','');
TerminateProcessByName('c:\programdata\windowsmangerprotect\protectwindowsmanager.exe');
QuarantineFile('c:\programdata\windowsmangerprotect\protectwindowsmanager.exe','');
TerminateProcessByName('c:\users\Администраторappdata\roaming\03000200-1425144394-0500-0006-000700080009\nsd5a9c.tmpfs');
QuarantineFile('c:\users\Администраторappdata\roaming\03000200-1425144394-0500-0006-000700080009\nsd5a9c.tmpfs','');
TerminateProcessByName('c:\program files (x86)\mbot_ru_77\mbot_ru_77.exe');
QuarantineFile('c:\program files (x86)\mbot_ru_77\mbot_ru_77.exe','');
TerminateProcessByName('c:\users\Администраторappdata\roaming\03000200-1425144394-0500-0006-000700080009\jnsl948e.tmp');
QuarantineFile('c:\users\Администраторappdata\roaming\03000200-1425144394-0500-0006-000700080009\jnsl948e.tmp','');
TerminateProcessByName('c:\program files (x86)\elex-tech\yac\isafetray.exe');
QuarantineFile('c:\program files (x86)\elex-tech\yac\isafetray.exe','');
TerminateProcessByName('c:\program files (x86)\elex-tech\yac\isafesvc2.exe');
QuarantineFile('c:\program files (x86)\elex-tech\yac\isafesvc2.exe','');
TerminateProcessByName('c:\program files (x86)\elex-tech\yac\isafesvc.exe');
QuarantineFile('c:\program files (x86)\elex-tech\yac\isafesvc.exe','');
TerminateProcessByName('c:\program files (x86)\elex-tech\yac\ipcdl.exe');
QuarantineFile('c:\program files (x86)\elex-tech\yac\ipcdl.exe','');
TerminateProcessByName('c:\program files (x86)\xtab\hpnotify.exe');
QuarantineFile('c:\program files (x86)\xtab\hpnotify.exe','');
QuarantineFile('c:\program files (x86)\xtab\cmdshell.exe','');
DeleteFile('c:\program files (x86)\xtab\cmdshell.exe','32');
DeleteFile('c:\program files (x86)\xtab\hpnotify.exe','32');
DeleteFile('c:\program files (x86)\elex-tech\yac\ipcdl.exe','32');
DeleteFile('c:\program files (x86)\elex-tech\yac\isafesvc.exe','32');
DeleteFile('c:\program files (x86)\elex-tech\yac\isafesvc2.exe','32');
DeleteFile('c:\program files (x86)\elex-tech\yac\isafetray.exe','32');
DeleteFile('c:\users\Администраторappdata\roaming\03000200-1425144394-0500-0006-000700080009\jnsl948e.tmp','32');
DeleteFile('c:\program files (x86)\mbot_ru_77\mbot_ru_77.exe','32');
DeleteFile('c:\users\Администраторappdata\roaming\03000200-1425144394-0500-0006-000700080009\nsd5a9c.tmpfs','32');
DeleteFile('c:\programdata\windowsmangerprotect\protectwindowsmanager.exe','32');
DeleteFile('c:\program files\bns\qqpcmgr\10.6.15950.224\qmdl.exe','32');
DeleteFile('c:\program files\bns\qqpcmgr\10.6.15950.224\qmspeedupplugin\phonerocket\dock_5.3.0.3\qqpcphonedock.exe','32');
DeleteFile('c:\program files\bns\qqpcmgr\10.6.15950.224\qqpcrtp.exe','32');
DeleteFile('c:\program files\bns\qqpcmgr\10.6.15950.224\qqpctray.exe','32');
DeleteFile('c:\users\Администраторappdata\local\03000200-1425144681-0500-0006-000700080009\snsk5784.tmp','32');
DeleteFile('c:\users\Администраторappdata\roaming\steam\reversed\steam.exe','32');
DeleteFile('c:\program files\bns\qqpcmgr\10.6.15950.224\taoframe.exe','32');
DeleteFile('c:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe','32');
DeleteFile('c:\programdata\schedule\timetasks.exe','32');
DeleteFile('c:\program files (x86)\ask.com\updater\updater.exe','32');
DeleteFile('c:\users\Администраторappdata\local\mbot_ru_77\upmbot_ru_77.exe','32');
DeleteFile('c:\program files (x86)\winzipper\winzipersvc.exe','32');
DeleteFile('C:\program files (x86)\common files\tencent\qqdownload\130\dlcore.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\curlpp.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iCommon.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iCommu.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iImportLib.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\ipcproxy.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeAdless.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafebs.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeCheckEngine.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafechlp.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeDisp.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeEngineBase.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlCall.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMonCall.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafemc.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeMon.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafenpf.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafepxy.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isaferpt.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafesopt.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafeupbiz.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSvc.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSvc2.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPDesk.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPFeedback.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPFloaty.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPMsgCenter.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPNodisturb.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPProtect.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPPush.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPStartupAssist.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPVirus.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\libcurl.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\LIBEAY32.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\libpng.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\ouilibx.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\sqlite3.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\SSLEAY32.dll','32');
DeleteFile('C:\Program Files (x86)\WinZipper\ebase.dll','32');
DeleteFile('C:\Program Files (x86)\WinZipper\sqlite3.dll','32');
DeleteFile('C:\Program Files (x86)\XTab\BrowerWatchCH.dll','32');
DeleteFile('C:\Program Files (x86)\XTab\BrowerWatchFF.dll','32');
DeleteFile('C:\Users\АдминистраторAppData\Roaming\Steam\Reversed\libcurl.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\iSafeNetFilter.sys','32');
DeleteFile('C:\Windows\system32\Drivers\webTinstMK.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\iSafeKrnlBoot.sys','32');
DeleteFile('C:\Program Files (x86)\WinZipper\eshellctx64.dll','32');
DeleteFile('C:\Users\АдминистраторAppData\Local\03000200-1425144523-0500-0006-000700080009\bnszF5E6.exe','32');
DeleteFile('C:\Users\АдминистраторAppData\Local\Microsoft\Windows\system.vbs','32');
DeleteFile('C:\Users\АдминистраторAppData\Local\mbot_ru_77\upmbot_ru_77.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','CMD');
DeleteFile('C:\Program Files (x86)\XTab\SupTab.dll','32');
DeleteFile('C:\Program Files (x86)\ver5SpeeditUp\189.dll','32');
DeleteFile('C:\Users\АдминистраторAppData\Local\10321\a4973.exe','32');
DeleteFile('C:\Windows\Tasks\AmiUpdXp.job','64');
DeleteFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP1.job','64');
DeleteFile('C:\Windows\Tasks\APSnotifierPP2.job','64');
DeleteFile('C:\Windows\Tasks\APSnotifierPP3.job','64');
DeleteFile('C:\Program Files (x86)\ver5SpeeditUp\d1SpeeditUpU54.exe','32');
DeleteFile('C:\Windows\Tasks\SpeeditUp Update.job','64');
DeleteFile('C:\Windows\system32\Tasks\AmiUpdXp','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP1','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP2','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP3','64');
DeleteFile('C:\Program Files (x86)\Microsoft Data\nsi.exe','32');
DeleteFile('C:\Windows\system32\Tasks\chrome5','64');
DeleteFile('C:\Windows\system32\Tasks\chrome5_logon','64');
DeleteFile('C:\Windows\system32\Tasks\SpeeditUp Update','64');
DeleteFile('C:\Windows\system32\Tasks\Steam-S-1-8-22-9865GUI','64');
DeleteFile('C:\Windows\system32\Tasks\SystemScript','64');
DeleteFile('c:\program files (x86)\application assistance\apphelper.exe','32');
ExecuteRepair(2);
ExecuteRepair(4);
ExecuteRepair(3);
DeleteFileMask('c:\program files (x86)\application assistance','*',true);
DeleteDirectory('c:\program files (x86)\application assistance');
DeleteFileMask('C:\Program Files (x86)\Microsoft Data','*',true);
DeleteDirectory('C:\Program Files (x86)\Microsoft Data');
DeleteFileMask('C:\Program Files (x86)\ver5SpeeditUp','*',true);
DeleteDirectory('C:\Program Files (x86)\ver5SpeeditUp');
DeleteFileMask('C:\Program Files (x86)\AnyProtectEx','*',true);
DeleteDirectory('C:\Program Files (x86)\AnyProtectEx');
DeleteFileMask('C:\Program Files (x86)\XTab','*',true);
DeleteDirectory('C:\Program Files (x86)\XTab');
DeleteFileMask('C:\Users\АдминистраторAppData\Local\mbot_ru_77','*',true);
DeleteDirectory('C:\Users\АдминистраторAppData\Local\mbot_ru_77');
DeleteFileMask('C:\Users\АдминистраторAppData\Local\03000200-1425144523-0500-0006-000700080009','*',true);
DeleteDirectory('C:\Users\АдминистраторAppData\Local\03000200-1425144523-0500-0006-000700080009');
DeleteFileMask('C:\Program Files (x86)\WinZipper','*',true);
DeleteDirectory('C:\Program Files (x86)\WinZipper');
DeleteFileMask('C:\Program Files (x86)\Elex-tech','*',true);
DeleteDirectory('C:\Program Files (x86)\Elex-tech');
DeleteFileMask('C:\Users\АдминистраторAppData\Roaming\Steam\Reversed','*',true);
DeleteDirectory('C:\Users\АдминистраторAppData\Roaming\Steam\Reversed');
DeleteFileMask('C:\Users\АдминистраторAppData\Local\10321','*',true);
DeleteDirectory('C:\Users\АдминистраторAppData\Local\10321');
ExecuteSysClean;
DeleteFile('C:\Users\АдминистраторAppData\Roaming\Browsers\exe.emorhc.bat','32');
ExecuteWizard('TSW',2,2,true);
ExecuteWizard('SCU',2,2,true);
RebootWindows(true);
end.
Компьютер перезагрузится.