Код:
begin
QuarantineFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\wuapp.exe','');
QuarantineFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\wecutil.exe','');
QuarantineFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\Utilman.exe','');
QuarantineFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\TSTheme.exe','');
QuarantineFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\taskkill.exe','');
QuarantineFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\ntkrnlpa.exe','');
QuarantineFile('C:\Users\Metka\AppData\Local\SystemDir\nethost.exe','');
QuarantineFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\mshta.exe','');
QuarantineFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\icardagt.exe','');
QuarantineFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\at.exe','');
QuarantineFile('C:\Program Files (x86)\help4u\help4u_notification_service.exe','');
QuarantineFile('C:\Program Files (x86)\coupons and fun\coupons_and_fun_notification_service.exe','');
DelBHO('{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}');
DelBHO('{11111111-1111-1111-1111-110611511123}');
DelBHO('{11111111-1111-1111-1111-110611191115}');
QuarantineFile('C:\Users\Metka\AppData\Roaming\tej\yisifa.exe','');
QuarantineFile('C:\Users\Metka\AppData\Roaming\WinTds\wintds.exe','');
QuarantineFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\takeown.exe','');
QuarantineFile('C:\Users\Metka\AppData\Local\Eption\65yfk3f1.dll','');
DeleteService('soalxlmb');
DeleteService('eahyplxd');
StopService('{c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64');
StopService('{b9f73d40-1a45-43a0-9a38-3e55d05b3bd4}Gw64');
StopService('{b2aa7bb9-5668-402a-97c7-7dabffe0f82d}w64');
StopService('{b2aa7bb9-5668-402a-97c7-7dabffe0f82d}Gw64');
StopService('{b0ff63b8-ba6f-45bb-b13c-8474c0d8fc94}Gw64');
StopService('{adb41315-fba7-4b86-be27-b2401a20c8d2}Gw64');
StopService('{ab3b6fe8-8ffe-4d0c-aa1e-8030c4760982}Gw64');
StopService('{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw64');
StopService('{98e700ee-1d13-4cd6-97a6-d8d4d2f0a35b}Gw64');
StopService('{9642e31c-2703-4a31-ba45-9e8dfb693e38}Gw64');
StopService('{6b9234ab-d79f-41db-86f9-8be7a3e9ee74}Gw64');
StopService('{51d6aaf3-0bd7-47b0-8963-1c6f4d58b8fd}Gw64');
StopService('{37853ded-5f26-4b06-88d4-a4f00ea1c972}Gw64');
StopService('{00c97d86-accb-4288-9972-6d929c1fe93a}Gw64');
DeleteService('{c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64');
DeleteService('{b9f73d40-1a45-43a0-9a38-3e55d05b3bd4}Gw64');
DeleteService('{b2aa7bb9-5668-402a-97c7-7dabffe0f82d}w64');
DeleteService('{b2aa7bb9-5668-402a-97c7-7dabffe0f82d}Gw64');
DeleteService('{b0ff63b8-ba6f-45bb-b13c-8474c0d8fc94}Gw64');
DeleteService('{adb41315-fba7-4b86-be27-b2401a20c8d2}Gw64');
DeleteService('{ab3b6fe8-8ffe-4d0c-aa1e-8030c4760982}Gw64');
DeleteService('{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw64');
DeleteService('{98e700ee-1d13-4cd6-97a6-d8d4d2f0a35b}Gw64');
DeleteService('{9642e31c-2703-4a31-ba45-9e8dfb693e38}Gw64');
DeleteService('{6b9234ab-d79f-41db-86f9-8be7a3e9ee74}Gw64');
DeleteService('{51d6aaf3-0bd7-47b0-8963-1c6f4d58b8fd}Gw64');
DeleteService('{37853ded-5f26-4b06-88d4-a4f00ea1c972}Gw64');
DeleteService('{00c97d86-accb-4288-9972-6d929c1fe93a}Gw64');
DeleteService('globalUpdatem');
DeleteService('globalUpdate');
StopService('MaintainerSvc6.89.573444');
DeleteService('MaintainerSvc6.89.573444');
TerminateProcessByName('c:\progra~2\youtub~1\youtubeacceleratorservice.exe');
QuarantineFile('c:\progra~2\youtub~1\youtubeacceleratorservice.exe','');
TerminateProcessByName('c:\users\metka\appdata\roaming\wintds\wintds.exe');
QuarantineFile('c:\users\metka\appdata\roaming\wintds\wintds.exe','');
TerminateProcessByName('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\mmc.exe');
QuarantineFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\mmc.exe','');
TerminateProcessByName('c:\programdata\01e58235-010d-43b1-8340-277d43a75321\maintainer.exe');
QuarantineFile('c:\programdata\01e58235-010d-43b1-8340-277d43a75321\maintainer.exe','');
TerminateProcessByName('c:\program files (x86)\senses\bc0a4064-916d-4450-9576-83b8e8d45d52-6.exe');
QuarantineFile('c:\program files (x86)\senses\bc0a4064-916d-4450-9576-83b8e8d45d52-6.exe','');
TerminateProcessByName('c:\program files (x86)\iwebar\839ac62c-3543-4dce-abf4-74492843eb53-6.exe');
QuarantineFile('c:\program files (x86)\iwebar\839ac62c-3543-4dce-abf4-74492843eb53-6.exe','');
DeleteFile('c:\program files (x86)\iwebar\839ac62c-3543-4dce-abf4-74492843eb53-6.exe','32');
DeleteFile('c:\program files (x86)\senses\bc0a4064-916d-4450-9576-83b8e8d45d52-6.exe','32');
DeleteFile('c:\programdata\01e58235-010d-43b1-8340-277d43a75321\maintainer.exe','32');
DeleteFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\mmc.exe','32');
DeleteFile('c:\users\metka\appdata\roaming\wintds\wintds.exe','32');
DeleteFile('c:\progra~2\youtub~1\youtubeacceleratorservice.exe','32');
DeleteFile('C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321\maintainer.exe','32');
DeleteFile('C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe','32');
DeleteFile('C:\Windows\system32\drivers\{00c97d86-accb-4288-9972-6d929c1fe93a}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{37853ded-5f26-4b06-88d4-a4f00ea1c972}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{51d6aaf3-0bd7-47b0-8963-1c6f4d58b8fd}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{6b9234ab-d79f-41db-86f9-8be7a3e9ee74}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{9642e31c-2703-4a31-ba45-9e8dfb693e38}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{98e700ee-1d13-4cd6-97a6-d8d4d2f0a35b}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{ab3b6fe8-8ffe-4d0c-aa1e-8030c4760982}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{adb41315-fba7-4b86-be27-b2401a20c8d2}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{b0ff63b8-ba6f-45bb-b13c-8474c0d8fc94}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{b2aa7bb9-5668-402a-97c7-7dabffe0f82d}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{b2aa7bb9-5668-402a-97c7-7dabffe0f82d}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{b9f73d40-1a45-43a0-9a38-3e55d05b3bd4}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\eahyplxd.sys','32');
DeleteFile('C:\Windows\system32\drivers\soalxlmb.sys','32');
DeleteFile('C:\Users\Metka\AppData\Local\Eption\65yfk3f1.dll','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Ihsoft');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','mmc');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','mmc');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Command Processor','AutoRun');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Command Processor\','Autorun');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer','Run');
DeleteFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\takeown.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','takeown');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','wincl');
DeleteFile('C:\Users\Metka\AppData\Roaming\WinTds\wintds.exe','32');
DeleteFile('C:\Users\Metka\AppData\Roaming\tej\yisifa.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','bino');
DeleteFile('C:\ProgramData\YTAHelper\YTAHelper.dll','32');
DeleteFile('C:\Program Files (x86)\iWebar\iWebar-bho.dll','32');
DeleteFile('C:\Program Files (x86)\Senses\Senses-bho.dll','32');
DeleteFile('C:\Windows\Tasks\839ac62c-3543-4dce-abf4-74492843eb53-1.job','64');
DeleteFile('C:\Windows\Tasks\839ac62c-3543-4dce-abf4-74492843eb53-11.job','64');
DeleteFile('C:\Windows\Tasks\839ac62c-3543-4dce-abf4-74492843eb53-4.job','64');
DeleteFile('C:\Windows\Tasks\839ac62c-3543-4dce-abf4-74492843eb53-5.job','64');
DeleteFile('C:\Windows\Tasks\839ac62c-3543-4dce-abf4-74492843eb53-5_user.job','64');
DeleteFile('C:\Windows\Tasks\839ac62c-3543-4dce-abf4-74492843eb53-6.job','64');
DeleteFile('C:\Windows\Tasks\839ac62c-3543-4dce-abf4-74492843eb53-7.job','64');
DeleteFile('C:\Windows\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-1.job','64');
DeleteFile('C:\Windows\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-11.job','64');
DeleteFile('C:\Windows\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-3.job','64');
DeleteFile('C:\Windows\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-4.job','64');
DeleteFile('C:\Windows\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-5.job','64');
DeleteFile('C:\Windows\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-5_user.job','64');
DeleteFile('C:\Windows\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-6.job','64');
DeleteFile('C:\Windows\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-7.job','64');
DeleteFile('C:\Windows\Tasks\coupons_and_fun_notification_service.job','64');
DeleteFile('C:\Windows\Tasks\coupons_and_fun_updating_service.job','64');
DeleteFile('C:\Program Files (x86)\coupons and fun\coupons_and_fun_notification_service.exe','32');
DeleteFile('C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job','64');
DeleteFile('C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job','64');
DeleteFile('C:\Windows\Tasks\help4u_notification_service.job','64');
DeleteFile('C:\Windows\Tasks\help4u_updating_service.job','64');
DeleteFile('C:\Program Files (x86)\help4u\help4u_notification_service.exe','32');
DeleteFile('C:\Windows\Tasks\SpeedUpMyPC Maintenance.job','64');
DeleteFile('C:\Windows\Tasks\SpeedUpMyPC Startup.job','64');
DeleteFile('C:\Windows\system32\Tasks\839ac62c-3543-4dce-abf4-74492843eb53-1','64');
DeleteFile('C:\Windows\system32\Tasks\839ac62c-3543-4dce-abf4-74492843eb53-11','64');
DeleteFile('C:\Windows\system32\Tasks\839ac62c-3543-4dce-abf4-74492843eb53-4','64');
DeleteFile('C:\Windows\system32\Tasks\839ac62c-3543-4dce-abf4-74492843eb53-5','64');
DeleteFile('C:\Windows\system32\Tasks\839ac62c-3543-4dce-abf4-74492843eb53-5_user','64');
DeleteFile('C:\Windows\system32\Tasks\839ac62c-3543-4dce-abf4-74492843eb53-6','64');
DeleteFile('C:\Windows\system32\Tasks\839ac62c-3543-4dce-abf4-74492843eb53-7','64');
DeleteFile('C:\Windows\system32\Tasks\at','64');
DeleteFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\at.exe','32');
DeleteFile('C:\Windows\system32\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-1','64');
DeleteFile('C:\Windows\system32\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-11','64');
DeleteFile('C:\Windows\system32\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-3','64');
DeleteFile('C:\Windows\system32\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-4','64');
DeleteFile('C:\Windows\system32\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-5','64');
DeleteFile('C:\Windows\system32\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-5_user','64');
DeleteFile('C:\Windows\system32\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-6','64');
DeleteFile('C:\Windows\system32\Tasks\bc0a4064-916d-4450-9576-83b8e8d45d52-7','64');
DeleteFile('C:\Windows\system32\Tasks\coupons_and_fun_notification_service','64');
DeleteFile('C:\Windows\system32\Tasks\coupons_and_fun_updating_service','64');
DeleteFile('C:\Windows\system32\Tasks\globalUpdateUpdateTaskMachineCore','64');
DeleteFile('C:\Windows\system32\Tasks\globalUpdateUpdateTaskMachineUA','64');
DeleteFile('C:\Windows\system32\Tasks\help4u_notification_service','64');
DeleteFile('C:\Windows\system32\Tasks\help4u_updating_service','64');
DeleteFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\icardagt.exe','32');
DeleteFile('C:\Windows\system32\Tasks\icardagt','64');
DeleteFile('C:\Windows\system32\Tasks\mmc','64');
DeleteFile('C:\Windows\system32\Tasks\mshta','64');
DeleteFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\mshta.exe','32');
DeleteFile('C:\Windows\system32\Tasks\nethost task','64');
DeleteFile('C:\Users\Metka\AppData\Local\SystemDir\nethost.exe','32');
DeleteFile('C:\Windows\system32\Tasks\ntkrnlpa','64');
DeleteFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\ntkrnlpa.exe','32');
DeleteFile('C:\Windows\system32\Tasks\SpeedUpMyPC Maintenance','64');
DeleteFile('C:\Windows\system32\Tasks\SpeedUpMyPC Startup','64');
DeleteFile('C:\Windows\system32\Tasks\takeown','64');
DeleteFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\taskkill.exe','32');
DeleteFile('C:\Windows\system32\Tasks\taskkill','64');
DeleteFile('C:\Windows\system32\Tasks\TSTheme','64');
DeleteFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\TSTheme.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Utilman','64');
DeleteFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\Utilman.exe','32');
DeleteFile('C:\Windows\system32\Tasks\wecutil','64');
DeleteFile('C:\Windows\system32\Tasks\wuapp','64');
DeleteFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\wecutil.exe','32');
DeleteFile('C:\Users\Metka\AppData\Roaming\Microsoft\Windows\IEUpdate\wuapp.exe','32');
DeleteFile('C:\Windows\system32\Tasks\YTAUpdate','64');
DeleteFile('C:\Windows\system32\Tasks\YTAUpdate_logon','64');
DeleteFile('C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll','32');
ExecuteSysClean;
ExecuteRepair(15);
ExecuteAVUpdate;
RebootWindows(true);
end.