Код:
begin
StopService('QMUdisk');
StopService('QQSysMonX64');
StopService('softaal');
StopService('TAOKernelDriver');
StopService('tsnethlpx64');
StopService('TSSysKit');
StopService('UCGuard');
StopService('YYTOLEHCQV');
QuarantineFileF('c:\users\doom\appdata\local\hostinstaller', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFile('c:\program files\ziptool\ziphost.dll', '');
QuarantineFile('c:\program files\ziptool\ZipUpdater\ZipUpdate.dll', '');
QuarantineFile('c:\program files\ziptool\CheckUpdate.dll', '');
QuarantineFile('c:\program files\ziptool\ZipSubmit\ZipSubmit.dll', '');
QuarantineFile('c:\program files\ziptool\substat.dll', '');
QuarantineFile('c:\program files\ziptool\ZipPlug.dll', '');
QuarantineFile('c:\program files\ziptool\wchsubstat.dll', '');
QuarantineFile('c:\program files\ziptool\tipsdll.dll', '');
QuarantineFile('C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QQPCRTP.exe', '');
QuarantineFile('C:\Program Files (x86)\Qiqerylugase\QqrCloudsrv.html5 {79740E79-A383-47A7-B513-3DF6563D007F} {8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}', '');
QuarantineFile('C:\Program Files (x86)\03DE0294-1465882840-05DF-7106-1F0700080009\hnsaFCFC.tmp', '');
QuarantineFile('C:\Users\Doom\AppData\Local\03DE0294-1465893734-05DF-7106-1F0700080009\qnsg2EA6.tmp', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMUdisk64.sys', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QQSysMonX64.sys', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\softaal64.sys', '');
QuarantineFile('C:\WINDOWS\system32\Drivers\TAOKernelEx64.sys', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TsNetHlpX64.sys', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TSSysKit64.sys', '');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\ucguard.sys', '');
QuarantineFile('C:\WINDOWS\System32\Drivers\askProtect64.sys', '');
QuarantineFile('C:\WINDOWS\system32\drivers\blNetFilter.sys', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMGR\SRepairDrv', '');
QuarantineFile('C:\WINDOWS\system32\Drivers\TAOAccelerator64.sys', '');
QuarantineFile('C:\WINDOWS\system32\Drivers\TFsFltX64.sys', '');
QuarantineFile('C:\Program Files (x86)\badu\uc.exe', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QQPCTray.exe', '');
QuarantineFile('C:\Users\Doom\AppData\Local\Temp\00010991\casrss.exe', '');
QuarantineFile('C:\ProgramData\WindowsMsg\osmsg.exe', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMContextScan.dll', '');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\plugins\FileSmash\QMSoftExt.dll', '');
QuarantineFile('C:\Users\Doom\AppData\Roaming\gplyra\gplyra.exe', '');
QuarantineFile('C:\Program Files (x86)\UCBrowser\Application\update_task.exe', '');
QuarantineFile('C:\PROGRA~1\6A8C~1\X86\Update.exe', '');
QuarantineFile('C:\Program Files (x86)\Qiqerylugase\QqrCloudtsk.exe', '');
QuarantineFile('C:\Users\Doom\AppData\Local\Hostinstaller\685846198_monster.exe', '');
QuarantineFile('C:\Users\Doom\AppData\Local\SystemMonitor2016\685846198.exe', '');
QuarantineFile('C:\Program Files (x86)\ttwifi\tiantianwifi.exe', '');
QuarantineFile('C:\Program Files (x86)\IObit\Advanced SystemCare 8\unins000.exe', '');
QuarantineFile('C:\Program Files (x86)\UCBrowser\Application\5.6.12150.8\Installer\chrmstp.exe', '');
QuarantineFile('C:\Users\Doom\AppData\Local\UCBrowser\User Data\Default\Extensions\pbnmnlipmkfkadfcdocgblonoccmolpe\3.0.0_0\bin\PPHelper\DriverInstallerX86.exe', '');
QuarantineFile('C:\Users\Doom\appdata\roaming\aspackage\uninstall.exe', '');
DeleteFile('C:\WINDOWS\Tasks\UCBrowserUpdater.job', '64');
DeleteFile('c:\program files\ziptool\ziphost.dll', '32');
DeleteFile('c:\program files\ziptool\ZipUpdater\ZipUpdate.dll', '32');
DeleteFile('c:\program files\ziptool\CheckUpdate.dll', '32');
DeleteFile('c:\program files\ziptool\ZipSubmit\ZipSubmit.dll', '32');
DeleteFile('c:\program files\ziptool\substat.dll', '32');
DeleteFile('c:\program files\ziptool\ZipPlug.dll', '32');
DeleteFile('c:\program files\ziptool\wchsubstat.dll', '32');
DeleteFile('c:\program files\ziptool\tipsdll.dll', '32');
DeleteFile('C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QQPCRTP.exe', '32');
DeleteFile('C:\Program Files (x86)\Qiqerylugase\QqrCloudsrv.html5 {79740E79-A383-47A7-B513-3DF6563D007F} {8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}', '32');
DeleteFile('C:\Program Files (x86)\03DE0294-1465882840-05DF-7106-1F0700080009\hnsaFCFC.tmp', '32');
DeleteFile('C:\Users\Doom\AppData\Local\03DE0294-1465893734-05DF-7106-1F0700080009\qnsg2EA6.tmp', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMUdisk64.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QQSysMonX64.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\softaal64.sys', '32');
DeleteFile('C:\WINDOWS\system32\Drivers\TAOKernelEx64.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TsNetHlpX64.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TSSysKit64.sys', '32');
DeleteFile('C:\WINDOWS\system32\DRIVERS\ucguard.sys', '32');
DeleteFile('C:\WINDOWS\System32\Drivers\askProtect64.sys', '32');
DeleteFile('C:\WINDOWS\system32\drivers\blNetFilter.sys', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMGR\SRepairDrv', '32');
DeleteFile('C:\WINDOWS\system32\Drivers\TAOAccelerator64.sys', '32');
DeleteFile('C:\WINDOWS\system32\Drivers\TFsFltX64.sys', '32');
DeleteFile('C:\Program Files (x86)\badu\uc.exe', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QQPCTray.exe', '32');
DeleteFile('C:\Users\Doom\AppData\Local\Temp\00010991\casrss.exe', '32');
DeleteFile('C:\ProgramData\WindowsMsg\osmsg.exe', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMContextScan.dll', '32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\plugins\FileSmash\QMSoftExt.dll', '32');
DeleteFile('C:\Users\Doom\AppData\Roaming\gplyra\gplyra.exe', '32');
DeleteFile('C:\Program Files (x86)\UCBrowser\Application\update_task.exe', '32');
DeleteFile('C:\PROGRA~1\6A8C~1\X86\Update.exe', '32');
DeleteFile('C:\Program Files (x86)\Qiqerylugase\QqrCloudtsk.exe', '32');
DeleteFile('C:\Users\Doom\AppData\Local\Hostinstaller\685846198_monster.exe', '32');
DeleteFile('C:\Users\Doom\AppData\Local\SystemMonitor2016\685846198.exe', '32');
DeleteFile('C:\Program Files (x86)\ttwifi\tiantianwifi.exe', '32');
DeleteFile('C:\Program Files (x86)\IObit\Advanced SystemCare 8\unins000.exe', '32');
DeleteFile('C:\Program Files (x86)\UCBrowser\Application\5.6.12150.8\Installer\chrmstp.exe', '32');
DeleteFile('C:\Users\Doom\AppData\Local\UCBrowser\User Data\Default\Extensions\pbnmnlipmkfkadfcdocgblonoccmolpe\3.0.0_0\bin\PPHelper\DriverInstallerX86.exe', '32');
DeleteFile('C:\Users\Doom\appdata\roaming\aspackage\uninstall.exe', '32');
DeleteService('LiveUpdateSvc');
DeleteService('QQPCRTP');
DeleteService('QqrCloudsrv');
DeleteService('rijufoze');
DeleteService('zigipyro');
DeleteService('QMUdisk');
DeleteService('QQSysMonX64');
DeleteService('softaal');
DeleteService('TAOKernelDriver');
DeleteService('tsnethlpx64');
DeleteService('TSSysKit');
DeleteService('UCGuard');
DeleteService('YYTOLEHCQV');
DeleteService('blNetFilter');
DeleteService('SRepairDrv');
DeleteService('TAOAccelerator');
DeleteService('TFsFlt');
DeleteFileMask('c:\program files\ziptool', '*', true);
DeleteFileMask('c:\program files (x86)\iobit', '*', true);
DeleteFileMask('c:\program files (x86)\tencent', '*', true);
DeleteFileMask('c:\program files (x86)\qiqerylugase', '*', true);
DeleteFileMask('c:\program files (x86)\badu', '*', true);
DeleteFileMask('c:\programdata\windowsmsg', '*', true);
DeleteFileMask('c:\users\doom\appdata\roaming\gplyra', '*', true);
DeleteFileMask('c:\program files (x86)\ucbrowser', '*', true);
DeleteFileMask('c:\progra~1\6a8c~1', '*', true);
DeleteFileMask('c:\users\doom\appdata\local\hostinstaller', '*', true);
DeleteFileMask('c:\program files (x86)\ttwifi', '*', true);
DeleteFileMask('c:\users\doom\appdata\local\ucbrowser\user data\default\extensions', '*', true);
DeleteFileMask('c:\users\doom\appdata\roaming\aspackage', '*', true);
DeleteDirectory('c:\program files\ziptool');
DeleteDirectory('c:\program files (x86)\iobit');
DeleteDirectory('c:\program files (x86)\tencent');
DeleteDirectory('c:\program files (x86)\qiqerylugase');
DeleteDirectory('c:\program files (x86)\badu');
DeleteDirectory('c:\programdata\windowsmsg');
DeleteDirectory('c:\users\doom\appdata\roaming\gplyra');
DeleteDirectory('c:\program files (x86)\ucbrowser');
DeleteDirectory('c:\progra~1\6a8c~1');
DeleteDirectory('c:\users\doom\appdata\local\hostinstaller');
DeleteDirectory('c:\program files (x86)\ttwifi');
DeleteDirectory('c:\users\doom\appdata\local\ucbrowser\user data\default\extensions');
DeleteDirectory('c:\users\doom\appdata\roaming\aspackage');
ExecuteFile('schtasks.exe', '/delete /TN "KuaiZip_Update" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "osTip" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Pritc" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Qiqerylugase Cloud" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Soft installer" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SystemMonitor2016" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ttwifi" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "UCBrowserUpdater" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{FCF338C8-771B-4EEE-BC91-7BA540D51C66}" /F', 0, 15000, true);
DelCLSID('{63332668-8CE1-445D-A5EE-25929176714E}');
DelCLSID('{754DF2CE-51E8-4895-B53C-6381418B84AE}');
DelCLSID('{65122CB0-EA0F-47DF-A953-017170ED12F9}');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'apphide');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', ' QQPCTray');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Pritc');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'osmsg');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'apphide2');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\ziphost\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved', '{63332668-8CE1-445D-A5EE-25929176714E}');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved', '{754DF2CE-51E8-4895-B53C-6381418B84AE}');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'gplyra');
ExecuteSysClean;
ExecuteRepair(13);
ExecuteWizard('SCU', 3, 3, true);
RebootWindows(true);
end.
Компьютер перезагрузится.