Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\program files (x86)\uncheckit\uncheckitsvc.exe');
TerminateProcessByName('c:\program files (x86)\uncheckit\uncheckitbsn.exe');
TerminateProcessByName('c:\program files (x86)\elex-tech\yac\isafesvc2.exe');
TerminateProcessByName('c:\program files (x86)\elex-tech\yac\isafesvc.exe');
TerminateProcessByName('c:\program files (x86)\uncheckit\cktsvc.exe');
TerminateProcessByName('c:\program files (x86)\elex-tech\yac\isafetray.exe');
TerminateProcessByName('c:\program files (x86)\tdata\tdata.exe');
TerminateProcessByName('c:\programdata\guntony\protect\protect.exe');
SetServiceStart('iSafeKrnlR3', 4);
SetServiceStart('iSafeKrnlMon', 4);
SetServiceStart('iSafeKrnlKit', 4);
SetServiceStart('iSafeKrnl', 4);
StopService('iSafeKrnlR3');
StopService('iSafeKrnlMon');
StopService('iSafeKrnlKit');
StopService('iSafeKrnl');
StopService('UncheckitSvc');
StopService('TDataSvr');
StopService('Guntony_protect');
StopService('cktSvc');
QuarantineFile('C:\Program Files (x86)\Uncheckit\UncheckitUpdate.exe','');
QuarantineFile('C:\Program Files (x86)\Guntony\Guntony\chrome.exe','');
QuarantineFile('C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe','');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\plugins\FileSmash\QMSoftExt.dll','');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMContextScan.dll','');
QuarantineFile('C:\WINDOWS\system32\drivers\tsskx64.sys','');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TSDefenseBT64.sys','');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TS888x64.sys','');
QuarantineFile('C:\WINDOWS\system32\Drivers\TFsFltX64.sys','');
QuarantineFile('C:\WINDOWS\system32\Drivers\TAOAccelerator.sys','');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\softaal64.sys','');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QQSysMonX64.sys','');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMUdisk64.sys','');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys','');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys','');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys','');
QuarantineFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys','');
QuarantineFile('C:\Program Files (x86)\qksee\qkseeSvc.exe','');
QuarantineFile('C:\Program Files (x86)\Mputyqasied\MputyqasiedHostservice.exe','');
QuarantineFile('C:\Program Files (x86)\Guntony\Guntony\bin\Guntony_server.exe','');
QuarantineFile('C:\Documents and Settings\All Users\Application Data\ANDREA VACONDIO\PDFsam Manager\PDFsam Enhanced\PDFsam Manager.exe','');
QuarantineFile('C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~WY7A.tmp','');
QuarantineFile('c:\program files (x86)\uncheckit\uncheckitsvc.exe','');
QuarantineFile('c:\program files (x86)\uncheckit\uncheckitbsn.exe','');
QuarantineFile('c:\program files (x86)\elex-tech\yac\isafesvc2.exe','');
QuarantineFile('c:\program files (x86)\elex-tech\yac\isafesvc.exe','');
QuarantineFile('c:\program files (x86)\uncheckit\cktsvc.exe','');
QuarantineFile('c:\program files (x86)\elex-tech\yac\isafetray.exe','');
QuarantineFile('c:\program files (x86)\tdata\tdata.exe','');
QuarantineFile('c:\programdata\guntony\protect\protect.exe','');
DeleteFile('C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk');
DeleteFile('c:\program files (x86)\elex-tech\yac\isafetray.exe','32');
DeleteFile('c:\program files (x86)\elex-tech\yac\isafesvc.exe','32');
DeleteFile('c:\program files (x86)\elex-tech\yac\isafesvc2.exe','32');
DeleteFile('c:\program files (x86)\uncheckit\uncheckitbsn.exe','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\curlpp.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iCommon.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iCommu.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iImportLib.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\ipcproxy.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeAdless.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeBase.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafebs.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeDisp.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlCall.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMonCall.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafemc.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafenpf.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafepxy.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafeupbiz.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isaferpt.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSvc.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSvc2.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPAutoClean.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPDesk.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPNodisturb.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPMsgCenter.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPPush.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPProtect.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPVirus.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\libcurl.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\LIBEAY32.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\ouilibx.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\libpng.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\sqlite3.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\SSLEAY32.dll','32');
DeleteFile('C:\Program Files (x86)\Uncheckit\cktSvc.exe','32');
DeleteFile('C:\ProgramData\Guntony\protect\protect.exe','32');
DeleteFile('C:\Program Files (x86)\TData\TData.exe','32');
DeleteFile('C:\Program Files (x86)\Uncheckit\UncheckitSvc.exe','32');
DeleteFile('C:\Program Files (x86)\Guntony\Guntony\bin\Guntony_server.exe','32');
DeleteFile('C:\Program Files (x86)\Mputyqasied\MputyqasiedHostservice.exe','32');
DeleteFile('C:\Program Files (x86)\qksee\qkseeSvc.exe','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QQPCRTP.exe','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMUdisk64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QQSysMonX64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\softaal64.sys','32');
DeleteFile('C:\WINDOWS\system32\Drivers\TAOAccelerator.sys','32');
DeleteFile('C:\WINDOWS\system32\Drivers\TFsFltX64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TS888x64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TSDefenseBT64.sys','32');
DeleteFile('C:\WINDOWS\system32\drivers\tsskx64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMContextScan.dll','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\plugins\FileSmash\QMSoftExt.dll','32');
DeleteFile('C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe','32');
DeleteFile('C:\Program Files (x86)\Guntony\Guntony\chrome.exe','32');
DeleteFile('C:\WINDOWS\Tasks\GuntonyBrowserUpdateCore.job','32');
DeleteFile('C:\WINDOWS\Tasks\GuntonyBrowserUpdateUA.job','32');
DeleteFile('C:\WINDOWS\Tasks\GuntonyCheckTask.job','32');
DeleteFile('C:\WINDOWS\Tasks\UncheckitTaskMN.job','32');
DeleteFile('C:\Program Files (x86)\Uncheckit\UncheckitUpdate.exe','32');
DeleteFile('C:\WINDOWS\Tasks\UncheckitUpdateTaskC.job','32');
DeleteFile('C:\WINDOWS\Tasks\UncheckitUpdateTaskDB.job','32');
DelCLSID('{754DF2CE-51E8-4895-B53C-6381418B84AE}');
DelCLSID('{63332668-8CE1-445D-A5EE-25929176714E}');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved','{63332668-8CE1-445D-A5EE-25929176714E}');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved','{754DF2CE-51E8-4895-B53C-6381418B84AE}');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnTBMon','command');
DeleteService('TSSKX64');
DeleteService('TSDefenseBt');
DeleteService('TS888x64');
DeleteService('TFsFlt');
DeleteService('TAOAccelerator');
DeleteService('softaal');
DeleteService('QQSysMonX64');
DeleteService('QMUdisk');
DeleteService('iSafeKrnlR3');
DeleteService('iSafeKrnlMon');
DeleteService('iSafeKrnlKit');
DeleteService('iSafeKrnl');
DeleteService('QQPCRTP');
DeleteService('qkseeService');
DeleteService('MputyqasiedHostservice');
DeleteService('Guntony_update');
DeleteService('UncheckitSvc');
DeleteService('TDataSvr');
DeleteService('Guntony_protect');
DeleteService('cktSvc');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
После перезагрузки выполните скрипт: