Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\Program Files\Rising\RAV\rsdelaylauncher.exe','');
QuarantineFile('C:\Program Files\Mobogenie\DaemonProcess.exe','');
QuarantineFile('C:\Users\Администратор\AppData\Local\Baidu\BaiduClient\1.6.0.359\BaiduUpdate.exe','');
QuarantineFile('C:\Users\Администратор\AppData\Local\Baidu\BaiduClient\1.6.0.359\Baidu.exe','');
QuarantineFile('C:\Windows\system32\tssk.sys','');
QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\TS888.sys','');
QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QMUdisk.sys','');
QuarantineFile('C:\Program Files\BrowseSmart\updateBrowseSmart.exe','');
QuarantineFile('C:\Users\Администратор\cbzvl.exe', '');
QuarantineFile('D:\autorun.inf', '');
DeleteFile('C:\Program Files\BrowseSmart\updateBrowseSmart.exe','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QMUdisk.sys','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\TS888.sys','32');
DeleteFile('C:\Windows\system32\tssk.sys','32');
DeleteFile('C:\Users\Администратор\AppData\Local\Baidu\BaiduClient\1.6.0.359\Baidu.exe','32');
DeleteFile('C:\Users\Администратор\AppData\Local\Baidu\BaiduClient\1.6.0.359\BaiduUpdate.exe','32');
DeleteFile('C:\Program Files\Mobogenie\DaemonProcess.exe','32');
DeleteFile('C:\Program Files\Rising\RAV\rsdelaylauncher.exe','32');
DeleteFile('C:\TEMP\9F2A642A3.sys', '32');
DeleteFile('C:\TEMP\67A53E6DB.sys', '32');
DeleteFile('C:\Users\Администратор\cbzvl.exe', '32');
ExecuteFile('schtasks.exe', '/delete /TN "RsDelayLauncher_{8A34248E-7D35-4832-8378-7659E0B0A380}" /F', 0, 15000, true);
DeleteService('TSSK');
DeleteService('TS888');
DeleteService('QMUdisk');
DeleteService('Update BrowseSmart');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BaiduClient','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BRBrowserInst','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows NT\CurrentVersion\Winlogon', 'Taskman');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
Компьютер