Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ClearQuarantine;
QuarantineFile('C:\Program Files\VK','');
QuarantineFile('C:\Documents and Settings\Admin\Local Settings\Application Data\SystemDir\nethost.exe','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\BDArKit.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\bd0004.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\bd0001.sys','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\KS_KILLER\65331270.sys','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kphonercmdutil.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\knetworkpanel.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kminitray.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kminisiteplugin.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kismain.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kfloatwin.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kfloatres.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kfloatmain.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\keasyipcn.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kdynmrey.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kdump.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kdgui2.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kdefendpop.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kclearpanel.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kcctrl.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kcalhost.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kcalendar.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kbootoptpop.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kbootacc.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kavmenu.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kantbud.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kadscan.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\kadbtool.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\defendmon.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\dbfix.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\data\ksrengz.dll','');
QuarantineFile('C:\program files\kingsoft\kingsoft antivirus\cysvc.dll','');
QuarantineFile('c:\program files\common files\tencent\qqdownload\130\dlcore.dll','');
QuarantineFile('C:\Documents and Settings\All Users\Application Data\Tencent\TSVulFw\TSVulFW.DAT','');
QuarantineFile('c:\program files\common files\tencent\qqdownload\130\tencentdl.exe','');
QuarantineFile('c:\program files\kingsoft\shoujizhushou\sjk_daemon.exe','');
QuarantineFile('c:\program files\tencent\qqpcmgr\10.10.16434.218\qqpctray.exe','');
QuarantineFile('c:\program files\tencent\qqpcmgr\10.10.16434.218\qqpcrtp.exe','');
QuarantineFile('c:\program files\kingsoft\kingsoft antivirus\kxetray.exe','');
QuarantineFile('c:\program files\kingsoft\kingsoft antivirus\kxescore.exe','');
QuarantineFile('c:\program files\kingsoft\shoujizhushou\kphonetray.exe','');
QuarantineFile('c:\program files\kingsoft\kingsoft antivirus\kcalendar.exe','');
TerminateProcessByName('c:\program files\common files\tencent\qqdownload\130\tencentdl.exe');
TerminateProcessByName('c:\program files\kingsoft\shoujizhushou\sjk_daemon.exe');
TerminateProcessByName('c:\program files\tencent\qqpcmgr\10.10.16434.218\qqpctray.exe');
TerminateProcessByName('c:\program files\tencent\qqpcmgr\10.10.16434.218\qqpcrtp.exe');
TerminateProcessByName('c:\program files\kingsoft\kingsoft antivirus\kxetray.exe');
TerminateProcessByName('c:\program files\kingsoft\kingsoft antivirus\kxescore.exe');
TerminateProcessByName('c:\program files\kingsoft\shoujizhushou\kphonetray.exe');
TerminateProcessByName('c:\program files\kingsoft\kingsoft antivirus\kcalendar.exe');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kcalendar.exe','32');
DeleteFile('c:\program files\kingsoft\shoujizhushou\kphonetray.exe','32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kxescore.exe','32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kxetray.exe','32');
DeleteFile('c:\program files\tencent\qqpcmgr\10.10.16434.218\qqpcrtp.exe','32');
DeleteFile('c:\program files\tencent\qqpcmgr\10.10.16434.218\qqpctray.exe','32');
DeleteFile('c:\program files\kingsoft\shoujizhushou\sjk_daemon.exe','32');
DeleteFile('c:\program files\common files\tencent\qqdownload\130\tencentdl.exe','32');
DeleteFile('C:\Documents and Settings\All Users\Application Data\Tencent\TSVulFw\TSVulFW.DAT','32');
DeleteFile('c:\program files\common files\tencent\qqdownload\130\dlcore.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\cysvc.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\data\ksrengz.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\dbfix.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\defendmon.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kadbtool.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kadscan.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kantbud.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kavmenu.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kbootacc.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kbootoptpop.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kcalendar.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kcalhost.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kcctrl.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kclearpanel.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kdefendpop.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kdgui2.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kdump.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kdynmrey.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\keasyipcn.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kfloatmain.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kfloatres.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kfloatwin.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kismain.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kminisiteplugin.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kminitray.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\knetworkpanel.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kphonercmdutil.dll','32');
DeleteFile('C:\program files\kingsoft\kingsoft antivirus\KS_KILLER\65331270.sys','32');
BC_DeleteFile('C:\program files\kingsoft\kingsoft antivirus\KS_KILLER\65331270.sys');
DeleteFile('C:\WINDOWS\system32\DRIVERS\bd0001.sys','32');
BC_DeleteFile('C:\WINDOWS\system32\DRIVERS\bd0001.sys');
DeleteFile('C:\WINDOWS\system32\DRIVERS\bd0004.sys','32');
BC_DeleteFile('C:\WINDOWS\system32\DRIVERS\bd0004.sys');
DeleteFile('C:\WINDOWS\system32\DRIVERS\BDArKit.sys','32');
BC_DeleteFile('C:\WINDOWS\system32\DRIVERS\BDArKit.sys');
BC_DeleteFile('C:\WINDOWS\system32\Drivers\KAVBootC.sys');
BC_DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kdhacker.sys');
BC_DeleteFile('C:\WINDOWS\system32\drivers\kisknl.sys');
BC_DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\ksnetm\kisnetmxp.sys');
BC_DeleteFile('C:\WINDOWS\system32\drivers\ksapi.sys');
BC_DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kusbquery.sys');
BC_DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QMUdisk.sys');
BC_DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQSysMon.sys');
BC_DeleteFile('C:\WINDOWS\system32\Drivers\TAOAccelerator.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\TAOKernelXP.sys');
BC_DeleteFile('C:\WINDOWS\system32\Drivers\TFsFlt.sys');
BC_DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\tscpm.sys');
BC_DeleteFile('C:\WINDOWS\system32\DRIVERS\TSDefenseBt.sys');
BC_DeleteFile('C:\WINDOWS\system32\Drivers\TSFLTMGR.SYS');
BC_DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TSKsp.sys');
BC_DeleteFile('C:\WINDOWS\System32\tssk.sys');
BC_DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\TSSysKit.sys');
BC_DeleteSvc('kxescore');
BC_DeleteSvc('QQPCRtp');
BC_DeleteSvc('Bonjoiur Host Controller');
BC_DeleteSvc('bd0001');
BC_DeleteSvc('bd0004');
BC_DeleteSvc('BDArKit');
BC_DeleteSvc('KAVBootC');
BC_DeleteSvc('KDHacker');
BC_DeleteSvc('kisknl');
BC_DeleteSvc('kisnetm');
BC_DeleteSvc('ksapi');
BC_DeleteSvc('KUsbGuard');
BC_DeleteSvc('QMUdisk');
BC_DeleteSvc('QQPCHelper');
BC_DeleteSvc('QQSysMon');
BC_DeleteSvc('TAOAccelerator');
BC_DeleteSvc('TAOKernelDriver');
BC_DeleteSvc('TFsFlt');
BC_DeleteSvc('TSCPM');
BC_DeleteSvc('TSDefenseBt');
BC_DeleteSvc('TSFLTMGR');
BC_DeleteSvc('Tsksp');
BC_DeleteSvc('TSSK');
BC_DeleteSvc('TSSysKit');
BC_DeleteSvc('BAPIDRV');
BC_DeleteSvc('bd0002');
BC_DeleteSvc('BDAntiExp');
BC_DeleteSvc('BDEnhanceBoost');
BC_DeleteSvc('BDMNetMon');
BC_DeleteFile('C:\Documents and Settings\All Users\Application Data\KRB Updater Utility\krbupdater-utility.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','KRB Updater Utility');
BC_DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kxetray.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','kxesc');
BC_DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQPCTray.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','QQPCTray');
BC_DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QQPCTRAY.EXE');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run-','QQPCTray');
BC_DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16434.218\QMContextUninstall.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved','{CBDECEF7-7A29-4cbf-A009-2673D82C7BF9}');
BC_DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kavmenu.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved','{D21D88E8-4123-48BA-B0B1-3FDBE4AE5FA4}');
DeleteFile('C:\Documents and Settings\Admin\Local Settings\Application Data\SystemDir\nethost.exe','32');
BC_DeleteFile('C:\Documents and Settings\Admin\Local Settings\Application Data\SystemDir\nethost.exe');
DeleteFile('C:\WINDOWS\Tasks\nethost task.job','32');
DeleteFile('C:\Program Files\VK','32');
BC_DeleteFile('C:\Program Files\VK');
DeleteFile('C:\WINDOWS\Tasks\Update Service for VK Downloader.job','32');
DeleteFile('C:\WINDOWS\Tasks\Update Service for VK Downloader2.job','32');
BC_DeleteFile('Downloader\UTikzNzHO9.exe');
BC_DeleteFile('c:\program files\kingsoft\shoujizhushou\kphonetray.exe');
BC_DeleteFile('c:\program files\kingsoft\shoujizhushou\sjk_daemon.exe');
BC_DeleteFile('c:\program files\common files\tencent\qqdownload\130\tencentdl.exe');
BC_DeleteFile('c:\program files\tencent\qqpcmgr\10.10.16434.218\qqpcrtp.exe');
BC_DeleteFile('c:\program files\tencent\qqpcmgr\10.10.16434.218\qqpctray.exe');
BC_DeleteFile('C:\Documents and Settings\All Users\Application Data\Tencent\TSVulFw\TSVulFW.DAT');
BC_DeleteFile('C:\program files\kingsoft\kingsoft antivirus\kwsui.dll');
BC_DeleteFile('C:\program files\kingsoft\kingsoft antivirus\lblocker.dll');
DelCLSID('{00890530-6A9F-4be2-B1BB-73F01E2BB986}');
DelCLSID('{63332668-8CE1-445D-A5EE-25929176714E}');
DelCLSID('{D21D88E8-4123-48BA-B0B1-3FDBE4AE5FA4}');
DelCLSID('{CBDECEF7-7A29-4cbf-A009-2673D82C7BF9}');
DeleteFileMask('C:\program files\kingsoft','*', true);
DeleteDirectory('C:\program files\kingsoft');
DeleteFileMask('C:\Documents and Settings\All Users\Application Data\Tencent','*', true);
DeleteDirectory('C:\Documents and Settings\All Users\Application Data\Tencent');
DeleteFileMask('c:\program files\common files\tencent','*', true);
DeleteDirectory('c:\program files\common files\tencent');
DeleteFileMask('c:\program files\tencent','*', true);
DeleteDirectory('c:\program files\tencent');
BC_ImportAll;
ExecuteSysClean;
ExecuteWizard('TSW',2,2,true);
ExecuteWizard('SCU',2,2,true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.