Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\users\user1\appdata\roaming\texteditor\daemon\texteditor.exe');
TerminateProcessByName('c:\program files (x86)\manager\manager.exe');
TerminateProcessByName('c:\program files (x86)\elex-tech\yac\isafetray.exe');
StopService('softaal');
StopService('QMUdisk');
StopService('iSafeKrnlBoot');
StopService('iSafeNetFilter');
StopService('iSafeKrnlR3');
StopService('iSafeKrnlMon');
StopService('iSafeKrnlKit');
StopService('iSafeKrnl');
StopService('HHandler Service');
QuarantineFile('C:\Users\User1\AppData\Roaming\Browsers\exe.arepo.bat','');
QuarantineFile('C:\ProgramData\VnTbbOuAKfu\QddCJMRWrGVHDx0.bat','');
QuarantineFile('C:\Users\User1\AppData\Roaming\ruescswa\riacubgs.exe','');
QuarantineFile('C:\Users\User1\AppData\Roaming\ACEStream\engine\ace_engine.exe','');
QuarantineFile('C:\Users\User1\AppData\Roaming\AceWebExtension\updater\ace_web_extension.exe','');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\softaal64.sys','');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QMUdisk64.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\iSafeKrnlBoot.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\iSafeNetFilter.sys','');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys','');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys','');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys','');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys','');
QuarantineFile('c:\users\user1\appdata\roaming\texteditor\daemon\texteditor.exe','');
QuarantineFile('c:\program files (x86)\manager\manager.exe','');
DeleteFile('C:\Users\User1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Панель запуска приложений Chrome.lnk');
DeleteFile('C:\Users\User1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Оperа.lnk');
DeleteFile('C:\Users\User1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk');
DeleteFile('c:\program files (x86)\elex-tech\yac\isafetray.exe','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\curlpp.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iCommon.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iCommu.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iImportLib.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\ipcproxy.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeAdless.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeBase.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafebs.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeCheckEngine.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeDisp.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeEngineBase.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeEngineDisp.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlCall.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMonCall.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlShell.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafemadwc.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafemc.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeMon.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafenpf.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafepxy.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isaferpt.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafeupbiz.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSvc.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSvc2.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPAutoClean.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPFeedback.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPFloaty.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPMsgCenter.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPNodisturb.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPProtect.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPPush.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPStartupAssist.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPVirus.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\libcurl.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\LIBEAY32.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\libpng.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\ouilibx.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\sqlite3.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\SSLEAY32.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\tws\AntiRK.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\tws\filau.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\tws\filcmn.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\tws\filvss.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\tws\fupd.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\tws\lsf.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\tws\tsc.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\tws\twsdk.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\tws\twsupd.dll','32');
DeleteFile('C:\Program Files (x86)\Manager\Manager.exe','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys','32');
DeleteFile('C:\WINDOWS\system32\DRIVERS\iSafeNetFilter.sys','32');
DeleteFile('C:\WINDOWS\system32\DRIVERS\iSafeKrnlBoot.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\QMUdisk64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.1.16908.217\softaal64.sys','32');
DeleteFile('C:\Users\User1\AppData\Roaming\ruescswa\riacubgs.exe','32');
DeleteFile('C:\ProgramData\VnTbbOuAKfu\QddCJMRWrGVHDx0.bat','32');
DeleteFile('C:\Users\User1\AppData\Roaming\Browsers\exe.arepo.bat','32');
DelBHO('{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}');
DelBHO('{0633EE93-D776-472f-A0FF-E1416B8B2E3D}');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','7-Zip');
DeleteService('softaal');
DeleteService('QMUdisk');
DeleteService('iSafeKrnlBoot');
DeleteService('iSafeNetFilter');
DeleteService('iSafeKrnlR3');
DeleteService('iSafeKrnlMon');
DeleteService('iSafeKrnlKit');
DeleteService('iSafeKrnl');
DeleteService('HHandler Service');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
После перезагрузки выполните скрипт: