Код:
begin
QuarantineFile('C:\Windows\system32\mintcastnetworks.dll', '');
QuarantineFile('C:\ProgramData\Baidu Security\Duplicaterecord.js', '');
QuarantineFile('C:\Windows\System32\CompMgmtLauncher.exe.bat', '');
QuarantineFile('C:\Windows\System32\Drivers\BDArKit.SYS', '');
QuarantineFile('C:\Windows\system32\DRIVERS\bd0003.sys', '');
QuarantineFile('C:\Windows\system32\DRIVERS\bd0001.sys', '');
QuarantineFile('C:\Windows\system32\DRIVERS\rsutils.sys', '');
QuarantineFile('C:\Windows\system32\DRIVERS\bd0002.sys', '');
QuarantineFile('C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe', '');
QuarantineFile('c:\program files (x86)\rising\rzc\rsdefense.exe', '');
DeleteFile('c:\program files (x86)\rising\rzc\rsdefense.exe', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\cnt09.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\comx3.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\defmon.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\moncomm.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\mondrv.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\MonRule.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\proccomm.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\rscfg.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\rscom.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\rscombas.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\rslog.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\rssqlite.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\rsutils_if.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\rsxml3w.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\selfmon.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RZC\sysmon_if.dll', '32');
DeleteFile('C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe', '32');
DeleteFile('C:\Windows\system32\DRIVERS\bd0002.sys', '32');
DeleteFile('C:\Windows\system32\DRIVERS\rsutils.sys', '32');
DeleteFile('C:\Windows\system32\DRIVERS\bd0001.sys', '32');
DeleteFile('C:\Windows\system32\DRIVERS\bd0003.sys', '32');
DeleteFile('C:\Windows\System32\Drivers\BDArKit.SYS', '32');
DeleteFile('C:\ProgramData\Baidu Security\Duplicaterecord.js', '32');
DeleteFile('C:\Windows\system32\Tasks\060184C3-9766-46a0-B258-F4518A0B2633', '64');
DeleteFile('C:\Windows\system32\mintcastnetworks.dll', '32');
DeleteService('Bprotect');
DeleteService('Bndef');
DeleteService('Bfmon');
DeleteService('Bfilter');
DeleteService('BdCameraProtect');
DeleteService('BDArKit');
DeleteService('BdApiUtil');
DeleteService('bd0003');
DeleteService('bd0001');
DeleteService('rsutils');
DeleteService('bd0002');
DeleteService('RsMgrSvc');
DeleteService('QHActiveDefense');
DeleteService('BDMRTP');
DeleteService('BDKVRTP');
DeleteFileMask('C:\ProgramData\Baidu Security', '*', true);
DeleteFileMask('C:\Program Files (x86)\Rising', '*', true);
DeleteFileMask('C:\Program Files (x86)\360', '*', true);
DeleteDirectory('C:\ProgramData\Baidu Security');
DeleteDirectory('C:\Program Files (x86)\Rising');
DeleteDirectory('C:\Program Files (x86)\360');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'QHSafeTray');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\baidusdTray', 'command');
ExecuteSysClean;
end.
Перезагрузит е сервер вручную.