Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
DelCLSID('{754DF2CE-51E8-4895-B53C-6381418B84AE}');
DelCLSID('{CBDECEF7-7A29-4cbf-A009-2673D82C7BF9}');
DeleteService('TSSK');
SetServiceStart('TSSysKit', 4);
SetServiceStart('TSKSP', 4);
SetServiceStart('TsFltMgr', 4);
SetServiceStart('TSDefenseBt', 4);
SetServiceStart('TSCPM', 4);
SetServiceStart('TFsFlt', 4);
SetServiceStart('TAOKernelDriver', 4);
SetServiceStart('TAOAccelerator', 4);
SetServiceStart('QQSysMon', 4);
SetServiceStart('QQPCHelper', 4);
SetServiceStart('QMUdisk', 4);
DeleteService('QMUdisk');
DeleteService('QQPCHelper');
DeleteService('QQSysMon');
DeleteService('TAOAccelerator');
DeleteService('TAOKernelDriver');
DeleteService('TFsFlt');
DeleteService('TSCPM');
DeleteService('TSDefenseBt');
DeleteService('TsFltMgr');
DeleteService('TSKSP');
DeleteService('TSSysKit');
SetServiceStart('QQPCRTP', 4);
DeleteService('QQPCRTP');
DeleteService('fimevebo');
DeleteService('globalUpdate');
DeleteService('globalUpdatem');
QuarantineFile('C:\Program Files\globalUpdate\Update\globalupdate.exe','');
DeleteService('gopibeko');
DeleteService('jimocoso');
DeleteService('libymymy');
DeleteService('TAOFrame');
QuarantineFile('C:\Program Files\00000000-1440506056-0000-0000-1C6F657F9B32\knsa4BC.tmpfs','');
QuarantineFile('C:\Program Files\00000000-1440506056-0000-0000-1C6F657F9B32\jnsq4D1.tmp','');
QuarantineFile('C:\Documents and Settings\buher12\Local Settings\Application Data\00000000-1440520500-0000-0000-1C6F657F9B32\snsg4F5.tmp','');
QuarantineFile('C:\Program Files\00000000-1440506056-0000-0000-1C6F657F9B32\hnsp4D5.tmp','');
TerminateProcessByName('c:\program files\tencent\qqpcmgr\10.10.16434.218\qqpcrtp.exe');
DeleteFile('c:\program files\tencent\qqpcmgr\10.10.16434.218\qqpcrtp.exe','32');
DeleteFile('C:\Documents and Settings\All Users\Application Data\Tencent\TSVulFw\TSVulFW.DAT','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\communic.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\dr.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\oDayProtect.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\plugins\FileSmash\QMSoftExt.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\plugins\QMBDScanner.dat','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\plugins\QMCloudInter\QMCloudInter.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\plugins\QMCpm.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\plugins\QMHips.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\plugins\qmiemalrtpplugin\qmiemalrtpplugin.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\plugins\QMRepairPlugin.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\plugins\RtpCommon.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\plugins\SpecialPlugin\QMHipsSpecial.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TSWebMon.dat','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TSSysKitProxy.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TAVUpload.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TAVInterface.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TAVEng.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TAVCache.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\SXComBase.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\sqlite.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\SoftMgr\processlogdll.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\scc.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\RefuseInject.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQPCHardware.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQFileFlt.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QMUl.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QMTrayPlugin\QMPerfCtrl\QMPerf.dll','32');
DeleteFile('c:\program files\tencent\qqpcmgr\10.10.16434.218\qmsysrepprov.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QMUdisk.sys','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQPCHelper.sys','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQSysMon.sys','32');
DeleteFile('C:\WINDOWS\system32\Drivers\TAOAccelerator.sys','32');
DeleteFile('C:\WINDOWS\System32\Drivers\TAOKernelXP.sys','32');
DeleteFile('C:\WINDOWS\system32\Drivers\TFsFlt.sys','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\tscpm.sys','32');
DeleteFile('C:\WINDOWS\system32\DRIVERS\TSDefenseBt.sys','32');
DeleteFile('C:\WINDOWS\system32\Drivers\TsFltMgr.sys','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TSKsp.sys','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TSSysKit.sys','32');
DeleteFile('C:\Program Files\00000000-1440506056-0000-0000-1C6F657F9B32\hnsp4D5.tmp','32');
DeleteFile('C:\Documents and Settings\buher12\Local Settings\Application Data\00000000-1440520500-0000-0000-1C6F657F9B32\snsg4F5.tmp','32');
DeleteFile('C:\Program Files\00000000-1440506056-0000-0000-1C6F657F9B32\jnsq4D1.tmp','32');
DeleteFile('C:\Program Files\00000000-1440506056-0000-0000-1C6F657F9B32\knsa4BC.tmpfs','32');
DeleteFile('C:\Program Files\globalUpdate\Update\globalupdate.exe','32');
DeleteFile('C:\WINDOWS\system32\Drivers\TAOKernelXP.sys','32');
DeleteFile('C:\WINDOWS\system32\drivers\TsFltMgr.sys','32');
DeleteFile('C:\WINDOWS\system32\tssk.sys','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QMContextUninstall.dll','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQPCTRAY.EXE','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved','{754DF2CE-51E8-4895-B53C-6381418B84AE}');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','QQPCTray');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved','{CBDECEF7-7A29-4cbf-A009-2673D82C7BF9}');
DeleteFile('C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job','32');
DeleteFile('C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.