Код:
begin
TerminateProcessByName('c:\programdata\twminiprot\wminipro.exe');
TerminateProcessByName('c:\program files (x86)\sfk\ssfk.exe');
TerminateProcessByName('c:\users\arseniy\appdata\local\temp\nsn5e2f.tmp');
TerminateProcessByName('c:\program files (x86)\fa0b9138-1446816202-11e3-9182-9995a3c40e00\knsqbfdf.tmp');
TerminateProcessByName('c:\program files (x86)\fa0b9138-1446816202-11e3-9182-9995a3c40e00\knsic66f.tmp');
TerminateProcessByName('c:\program files (x86)\gmsd_ru_005010146\gmsd_ru_005010146.exe');
TerminateProcessByName('c:\program files (x86)\mybrowser 1.0.2v07.11\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-1-6.exe');
StopService('punutume');
StopService('WdsManPro');
StopService('ginoquci');
StopService('qefyfuzy');
QuarantineFile('C:\Program Files (x86)\MyBrowser 1.0.2V07.11\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-5.exe', '');
QuarantineFile('C:\Program Files (x86)\MyBrowser 1.0.2V07.11\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-11.exe', '');
QuarantineFile('C:\Program Files (x86)\MyBrowser 1.0.2V07.11\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-10.exe', '');
QuarantineFile('C:\Program Files (x86)\MyBrowser 1.0.2V07.11\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-1-7.exe', '');
QuarantineFile('C:\Users\Arseniy\AppData\Local\Yandex\browser.bat', '');
QuarantineFile('C:\Program Files (x86)\FA0B9138-1446816202-11E3-9182-9995A3C40E00\jnsgA5D.tmp', '');
QuarantineFile('c:\programdata\twminiprot\wminipro.exe', '');
QuarantineFile('c:\program files (x86)\sfk\ssfk.exe', '');
QuarantineFile('c:\users\arseniy\appdata\local\temp\nsn5e2f.tmp', '');
QuarantineFile('c:\program files (x86)\fa0b9138-1446816202-11e3-9182-9995a3c40e00\knsqbfdf.tmp', '');
QuarantineFile('c:\program files (x86)\fa0b9138-1446816202-11e3-9182-9995a3c40e00\knsic66f.tmp', '');
QuarantineFile('c:\program files (x86)\gmsd_ru_005010146\gmsd_ru_005010146.exe', '');
QuarantineFile('c:\program files (x86)\mybrowser 1.0.2v07.11\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-1-6.exe', '');
DeleteFile('c:\program files (x86)\fa0b9138-1446816202-11e3-9182-9995a3c40e00\knsic66f.tmp', '32');
DeleteFile('c:\program files (x86)\fa0b9138-1446816202-11e3-9182-9995a3c40e00\knsqbfdf.tmp', '32');
DeleteFile('c:\program files (x86)\sfk\ssfk.exe', '32');
DeleteFile('C:\Program Files (x86)\FA0B9138-1446816202-11E3-9182-9995A3C40E00\jnsgA5D.tmp', '32');
DeleteFile('C:\Program Files (x86)\gmsd_ru_005010146\gmsd_ru_005010146.exe', '32');
DeleteFile('C:\Users\Arseniy\AppData\Local\SmartWeb\SmartWebHelper.exe', '32');
DeleteFile('C:\Program Files (x86)\MyBrowser 1.0.2V07.11\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-1-6.exe', '32');
DeleteFile('C:\Program Files (x86)\MyBrowser 1.0.2V07.11\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-1-7.exe', '32');
DeleteFile('C:\Program Files (x86)\MyBrowser 1.0.2V07.11\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-10.exe', '32');
DeleteFile('C:\Program Files (x86)\MyBrowser 1.0.2V07.11\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-11.exe', '32');
DeleteFile('C:\Program Files (x86)\MyBrowser 1.0.2V07.11\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-5.exe', '32');
DeleteFile('C:\WINDOWS\Tasks\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-1-6.job', '32');
DeleteFile('C:\WINDOWS\Tasks\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-1-7.job', '32');
DeleteFile('C:\WINDOWS\Tasks\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-10_user.job', '32');
DeleteFile('C:\WINDOWS\Tasks\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-11.job', '32');
DeleteFile('C:\WINDOWS\Tasks\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-5.job', '32');
DeleteFile('C:\WINDOWS\Tasks\1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-5_user.job', '32');
DeleteFile('C:\WINDOWS\Tasks\5cd5369b-9824-445f-9f45-100be6ed8734-1-6.job', '32');
DeleteFile('C:\WINDOWS\Tasks\5cd5369b-9824-445f-9f45-100be6ed8734-1-7.job', '32');
DeleteFile('C:\WINDOWS\Tasks\5cd5369b-9824-445f-9f45-100be6ed8734-10_user.job', '32');
DeleteFile('C:\WINDOWS\Tasks\5cd5369b-9824-445f-9f45-100be6ed8734-11.job', '32');
DeleteFile('C:\WINDOWS\Tasks\5cd5369b-9824-445f-9f45-100be6ed8734-5.job', '32');
DeleteFile('C:\WINDOWS\Tasks\5cd5369b-9824-445f-9f45-100be6ed8734-5_user.job', '32');
DeleteFile('C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job', '32');
DeleteFile('C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job', '32');
DeleteFile('C:\Users\Arseniy\AppData\Local\Temp\nsn5E2F.tmp', '32');
DeleteFile('C:\ProgramData\tWMiniProt\WMiniPro.exe', '32');
DeleteService('punutume');
DeleteService('globalUpdatem');
DeleteService('globalUpdate');
DeleteService('WdsManPro');
DeleteService('ginoquci');
DeleteService('qefyfuzy');
DeleteFileMask('C:\ProgramData\tWMiniProt', '*', true);
DeleteFileMask('C:\Program Files (x86)\MyBrowser 1.0.2V07.11', '*', true);
DeleteFileMask('C:\Program Files (x86)\gmsd_ru_005010146', '*', true);
DeleteFileMask('C:\Program Files (x86)\FA0B9138-1446816202-11E3-9182-9995A3C40E00', '*', true);
DeleteFileMask('c:\program files (x86)\sfk', '*', true);
DeleteDirectory('C:\ProgramData\tWMiniProt');
DeleteDirectory('C:\Program Files (x86)\MyBrowser 1.0.2V07.11');
DeleteDirectory('C:\Program Files (x86)\gmsd_ru_005010146');
DeleteDirectory('C:\Program Files (x86)\FA0B9138-1446816202-11E3-9182-9995A3C40E00');
DeleteDirectory('c:\program files (x86)\sfk');
ExecuteFile('schtasks.exe', '/delete /TN "1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-1-6" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-1-7" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-10_user" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-5" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "1a3f5184-c7fc-4d6e-9d3e-6f4f1e957b58-5_user" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "5cd5369b-9824-445f-9f45-100be6ed8734-1-6" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "5cd5369b-9824-445f-9f45-100be6ed8734-1-7" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "5cd5369b-9824-445f-9f45-100be6ed8734-10_user" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "5cd5369b-9824-445f-9f45-100be6ed8734-11" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "5cd5369b-9824-445f-9f45-100be6ed8734-5" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "5cd5369b-9824-445f-9f45-100be6ed8734-5_user" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "globalUpdateUpdateTaskMachineCore" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "globalUpdateUpdateTaskMachineUA" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SwiftSearch Auto Updater 1.10.0.25 Core" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SwiftSearch Auto Updater 1.10.0.25 Pending Update" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{00420121-A725-4F04-9697-A03B50EFDF1A}" /F', 0, 15000, true);
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'ZaxarGameBrowser');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'ZaxarLoader');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Timestasks');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'rec_en_77');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'gmsd_ru_005010137');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'SpaceSoundPro');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.