procedure AV_block_remove;
begin
QuarantineFileF('C:\AdwCleaner', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\Program Files\AVAST Software', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\Program Files\AVG', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\Program Files\ByteFence', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\Program Files\Cezurity', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\Program Files\Common Files\McAfee', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\Program Files\COMODO', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\Program Files\Enigma Software Group', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\Program Files\ESET', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\Program Files\Kaspersky Lab', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\Program Files\Malwarebytes', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\Program Files\SpyHunter', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\360safe', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\AVAST Software', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\Avira', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\Doctor Web', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\ESET', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\Indus', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\install', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\Kaspersky Lab Setup Files', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\Kaspersky Lab', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\Malwarebytes', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\MB3Install', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\McAfee', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\Norton', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\RealtekHD', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\Setup', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\Windows', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\WindowsTask', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFileF('C:\Windows\speechstracing', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0, 0);
DeleteFileMask('C:\AdwCleaner', '*', true);
DeleteFileMask('C:\Program Files\AVAST Software', '*', true);
DeleteFileMask('C:\Program Files\AVG', '*', true);
DeleteFileMask('C:\Program Files\ByteFence', '*', true);
DeleteFileMask('C:\Program Files\Cezurity', '*', true);
DeleteFileMask('C:\Program Files\Common Files\McAfee', '*', true);
DeleteFileMask('C:\Program Files\COMODO', '*', true);
DeleteFileMask('C:\Program Files\Enigma Software Group', '*', true);
DeleteFileMask('C:\Program Files\ESET', '*', true);
DeleteFileMask('C:\Program Files\Kaspersky Lab', '*', true);
DeleteFileMask('C:\Program Files\Malwarebytes', '*', true);
DeleteFileMask('C:\Program Files\SpyHunter', '*', true);
DeleteFileMask('C:\ProgramData\360safe', '*', true);
DeleteFileMask('C:\ProgramData\AVAST Software', '*', true);
DeleteFileMask('C:\ProgramData\Avira', '*', true);
DeleteFileMask('C:\ProgramData\Doctor Web', '*', true);
DeleteFileMask('C:\ProgramData\ESET', '*', true);
DeleteFileMask('C:\ProgramData\Indus', '*', true);
DeleteFileMask('C:\ProgramData\install', '*', true);
DeleteFileMask('C:\ProgramData\Kaspersky Lab Setup Files', '*', true);
DeleteFileMask('C:\ProgramData\Kaspersky Lab', '*', true);
DeleteFileMask('C:\ProgramData\Malwarebytes', '*', true);
DeleteFileMask('C:\ProgramData\MB3Install', '*', true);
DeleteFileMask('C:\ProgramData\McAfee', '*', true);
DeleteFileMask('C:\ProgramData\Norton', '*', true);
DeleteFileMask('C:\ProgramData\RealtekHD', '*', true);
DeleteFileMask('C:\ProgramData\Setup', '*', true);
DeleteFileMask('C:\ProgramData\Windows', '*', true);
DeleteFileMask('C:\ProgramData\WindowsTask', '*', true);
DeleteFileMask('C:\Windows\speechstracing', '*', true);
DeleteDirectory('C:\AdwCleaner');
DeleteDirectory('C:\Program Files\AVAST Software');
DeleteDirectory('C:\Program Files\AVG');
DeleteDirectory('C:\Program Files\ByteFence');
DeleteDirectory('C:\Program Files\Cezurity');
DeleteDirectory('C:\Program Files\Common Files\McAfee');
DeleteDirectory('C:\Program Files\COMODO');
DeleteDirectory('C:\Program Files\Enigma Software Group');
DeleteDirectory('C:\Program Files\ESET');
DeleteDirectory('C:\Program Files\Kaspersky Lab');
DeleteDirectory('C:\Program Files\Malwarebytes');
DeleteDirectory('C:\Program Files\SpyHunter');
DeleteDirectory('C:\ProgramData\360safe');
DeleteDirectory('C:\ProgramData\AVAST Software');
DeleteDirectory('C:\ProgramData\Avira');
DeleteDirectory('C:\ProgramData\Doctor Web');
DeleteDirectory('C:\ProgramData\ESET');
DeleteDirectory('C:\ProgramData\Indus');
DeleteDirectory('C:\ProgramData\install');
DeleteDirectory('C:\ProgramData\Kaspersky Lab Setup Files');
DeleteDirectory('C:\ProgramData\Kaspersky Lab');
DeleteDirectory('C:\ProgramData\Malwarebytes');
DeleteDirectory('C:\ProgramData\MB3Install');
DeleteDirectory('C:\ProgramData\McAfee');
DeleteDirectory('C:\ProgramData\Norton');
DeleteDirectory('C:\ProgramData\RealtekHD');
DeleteDirectory('C:\ProgramData\Setup');
DeleteDirectory('C:\ProgramData\Windows');
DeleteDirectory('C:\ProgramData\WindowsTask');
DeleteDirectory('C:\Windows\speechstracing');
end;
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
QuarantineFile('C:\Programdata\RealtekHD\taskhostw.exe', '');
DeleteSchedulerTask('Microsoft\Windows\Wininet\Taskhost');
DeleteSchedulerTask('Microsoft\Windows\Wininet\Taskhostw');
AV_block_remove;
ExecuteSysClean;
ExecuteFile(GetAVZDirectory+'7za.exe', 'a -mx9 -pmalware quarantine .\Quarantine\*', 1, 300000, false);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
RebootWindows(false);
end.