Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
StopService('ContentProtectorDrv');
StopService('protectiondrvr');
QuarantineFile('C:\Windows\system32\drivers\ContentProtectorDrv.sys', '');
QuarantineFile('C:\Users\ASKOLD~1\AppData\Local\Temp\nsdFCEB.tmp.sys', '');
QuarantineFile('C:\Windows\System32\ihctrl32.dll', '');
QuarantineFile('C:\Windows\System32\wsaudio.dll', '');
QuarantineFile('C:\Users\Askold_Vespa\AppData\Local\Hostinstaller\3360132372_monster.exe', '');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQPCRTP.exe', '32');
DeleteFile('C:\Windows\system32\drivers\ContentProtectorDrv.sys', '32');
DeleteFile('C:\Users\ASKOLD~1\AppData\Local\Temp\nsdFCEB.tmp.sys', '32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QMUdisk.sys', '32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQSysMon.sys', '32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\softaal.sys', '32');
DeleteFile('C:\Program Files\Tencent\QQPCMGR\Plugins\SRepairDrv', '32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\TS888.sys', '32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\TSKsp.sys', '32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\TsNetHlp.sys', '32');
DeleteFile('C:\Windows\System32\ihctrl32.dll', '32');
DeleteFile('C:\Windows\System32\wsaudio.dll', '32');
DeleteFile('C:\Users\Askold_Vespa\AppData\Local\Amigo\Application\vk.exe', '32');
DeleteFile('C:\Users\Askold_Vespa\AppData\Local\Amigo\Application\amigo.exe', '32');
DeleteFile('C:\Users\Askold_Vespa\AppData\Local\Amigo\Application\ok.exe', '32');
DeleteFile('C:\Users\Askold_Vespa\AppData\Local\Hostinstaller\3360132372_monster.exe', '32');
DeleteService('QQPCRTP');
DeleteService('ContentProtectorDrv');
DeleteService('protectiondrvr');
DeleteService('QMUdisk');
DeleteService('QQSysMon');
DeleteService('softaal');
DeleteService('SRepairDrv');
DeleteService('TS888');
DeleteService('TSKSP');
DeleteService('tsnethlp');
DeleteFileMask('c:\program files\tencent', '*', true);
DeleteFileMask('c:\users\askold_vespa\appdata\local\amigo', '*', true);
DeleteFileMask('c:\users\askold_vespa\appdata\local\hostinstaller', '*', true);
DeleteDirectory('c:\program files\tencent');
DeleteDirectory('c:\users\askold_vespa\appdata\local\amigo');
DeleteDirectory('c:\users\askold_vespa\appdata\local\hostinstaller');
ExecuteFile('schtasks.exe', '/delete /TN "Soft installer" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Phoenix Browser Updater" /F', 0, 15000, true);
ExecuteFile('ipconfig.exe', '/flushdns', 0, 15000, true);
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\ihctrl32\Parameters', 'ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\wsaudio\Parameters', 'ServiceDll');
BC_ImportALL;
ExecuteSysClean;
ExecuteRepair(21);
ExecuteRepair(3);
ExecuteRepair(13);
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.