Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Program Files\content defender\condefsetup.exe','');
QuarantineFile('C:\Users\Инквизитор\AppData\Local\Total Video\{E8C78333-380F-B8CB-9F60-A6140DBCFFF9}\trx.dll','');
QuarantineFile('C:\Users\Инквизитор\AppData\Local\Total Video\{E8C78333-380F-B8CB-9F60-A6140DBCFFF9}\TotalVideo.dll','');
DeleteService('wfdrvr_vt_1_10_0_28');
QuarantineFile('C:\Windows\system32\drivers\wfdrvr_vt_1_10_0_28.sys','');
SetServiceStart('contentdefenderdrv', 4);
DeleteService('contentdefenderdrv');
SetServiceStart('ginoquci', 4);
SetServiceStart('HHandler Service', 4);
SetServiceStart('hidekoqe', 4);
SetServiceStart('legixiwy', 4);
SetServiceStart('nyneryxo', 4);
SetServiceStart('roqenufe', 4);
SetServiceStart('WindowsMangerProtect', 4);
QuarantineFile('C:\Program Files\Extensions for Windows\Extensions\Updater\ExtensionsUpdatesService.exe','');
DeleteService('WindowsMangerProtect');
DeleteService('roqenufe');
DeleteService('nyneryxo');
DeleteService('legixiwy');
DeleteService('hidekoqe');
DeleteService('HHandler Service');
DeleteService('ginoquci');
QuarantineFile('c:\program files\extensions for windows\extensions\pdfprinter\bin\ExtensionsPDFPrinterService.exe','');
SetServiceStart('ContentDefender', 4);
DeleteService('ContentDefender');
QuarantineFile('C:\Windows\system32\drivers\contentdefenderdrv.sys','');
TerminateProcessByName('c:\users\Инквизитор\appdata\local\gmsd_re_005010169\upgmsd_re_005010169.exe');
QuarantineFile('c:\users\Инквизитор\appdata\local\gmsd_re_005010169\upgmsd_re_005010169.exe','');
TerminateProcessByName('c:\users\835b~1\appdata\local\temp\nsy7e9.tmp\setup_0655f1.exe');
TerminateProcessByName('c:\program files (x86)\sfk\ssfk.exe');
QuarantineFile('c:\program files (x86)\sfk\ssfk.exe','');
QuarantineFile('c:\users\835b~1\appdata\local\temp\nsy7e9.tmp\setup_0655f1.exe','');
TerminateProcessByName('c:\program files (x86)\manager\manager.exe');
TerminateProcessByName('c:\users\835b~1\appdata\local\temp\nsb215.tmp');
TerminateProcessByName('c:\users\835b~1\appdata\local\temp\nsb9e3a.tmp');
TerminateProcessByName('c:\users\835b~1\appdata\local\temp\nsic835.tmp');
TerminateProcessByName('c:\users\835b~1\appdata\local\temp\nssc8f6.tmp');
TerminateProcessByName('c:\programdata\tmp0x0x\protectwindowsmanager.exe');
TerminateProcessByName('C:\Users\Инквизитор\AppData\Local\FFFFFFFF-1449584266-FFFF-FFFF-FFFFFFFFFFFF\qnsh5FB.tmp');
TerminateProcessByName('c:\users\Инквизитор\appdata\local\ffffffff-1449584266-ffff-ffff-ffffffffffff\qnsh5fb.tmp');
QuarantineFile('c:\users\Инквизитор\appdata\local\ffffffff-1449584266-ffff-ffff-ffffffffffff\qnsh5fb.tmp','');
QuarantineFile('C:\Users\Инквизитор\AppData\Local\FFFFFFFF-1449584266-FFFF-FFFF-FFFFFFFFFFFF\qnsh5FB.tmp','');
QuarantineFile('c:\programdata\tmp0x0x\protectwindowsmanager.exe','');
QuarantineFile('c:\users\835b~1\appdata\local\temp\nssc8f6.tmp','');
QuarantineFile('c:\users\835b~1\appdata\local\temp\nsic835.tmp','');
QuarantineFile('c:\users\835b~1\appdata\local\temp\nsb9e3a.tmp','');
QuarantineFile('c:\users\835b~1\appdata\local\temp\nsb215.tmp','');
QuarantineFile('c:\program files (x86)\manager\manager.exe','');
TerminateProcessByName('c:\users\Инквизитор\appdata\local\gmsd_re_005010169\download\majmp_gentlerow.exe');
TerminateProcessByName('c:\users\835b~1\appdata\local\temp\is-uafav.tmp\majmp_gentlerow.tmp');
QuarantineFile('c:\users\835b~1\appdata\local\temp\is-uafav.tmp\majmp_gentlerow.tmp','');
QuarantineFile('c:\users\Инквизитор\appdata\local\gmsd_re_005010169\download\majmp_gentlerow.exe','');
TerminateProcessByName('c:\program files (x86)\ffffffff-1449471061-ffff-ffff-ffffffffffff\hnsxdc36.tmp');
TerminateProcessByName('c:\program files (x86)\ffffffff-1449471061-ffff-ffff-ffffffffffff\jnssc485.tmp');
TerminateProcessByName('c:\program files (x86)\ffffffff-1449471061-ffff-ffff-ffffffffffff\knsda3c0.tmp');
QuarantineFile('c:\program files (x86)\ffffffff-1449471061-ffff-ffff-ffffffffffff\knsda3c0.tmp','');
QuarantineFile('c:\program files (x86)\ffffffff-1449471061-ffff-ffff-ffffffffffff\jnssc485.tmp','');
QuarantineFile('c:\program files (x86)\ffffffff-1449471061-ffff-ffff-ffffffffffff\hnsxdc36.tmp','');
TerminateProcessByName('C:\Program Files\Content Defender\ContentDefender.exe');
TerminateProcessByName('c:\program files (x86)\gmsd_re_005010169\gmsd_re_005010169.exe');
QuarantineFile('c:\program files (x86)\gmsd_re_005010169\gmsd_re_005010169.exe','');
QuarantineFile('C:\Program Files\Content Defender\ContentDefender.exe','');
DeleteFile('C:\Program Files\Content Defender\ContentDefender.exe','32');
DeleteFile('c:\program files (x86)\gmsd_re_005010169\gmsd_re_005010169.exe','32');
DeleteFile('c:\program files (x86)\ffffffff-1449471061-ffff-ffff-ffffffffffff\hnsxdc36.tmp','32');
DeleteFile('c:\program files (x86)\ffffffff-1449471061-ffff-ffff-ffffffffffff\jnssc485.tmp','32');
DeleteFile('c:\program files (x86)\ffffffff-1449471061-ffff-ffff-ffffffffffff\knsda3c0.tmp','32');
DeleteFile('c:\users\Инквизитор\appdata\local\gmsd_re_005010169\download\majmp_gentlerow.exe','32');
DeleteFile('c:\users\835b~1\appdata\local\temp\is-uafav.tmp\majmp_gentlerow.tmp','32');
DeleteFile('c:\program files (x86)\manager\manager.exe','32');
DeleteFile('c:\users\835b~1\appdata\local\temp\nsb215.tmp','32');
DeleteFile('c:\users\835b~1\appdata\local\temp\nsb9e3a.tmp','32');
DeleteFile('c:\users\835b~1\appdata\local\temp\nsic835.tmp','32');
DeleteFile('c:\users\835b~1\appdata\local\temp\nssc8f6.tmp','32');
DeleteFile('c:\programdata\tmp0x0x\protectwindowsmanager.exe','32');
DeleteFile('C:\Users\Инквизитор\AppData\Local\FFFFFFFF-1449584266-FFFF-FFFF-FFFFFFFFFFFF\qnsh5FB.tmp','32');
DeleteFile('c:\users\Инквизитор\appdata\local\ffffffff-1449584266-ffff-ffff-ffffffffffff\qnsh5fb.tmp','32');
DeleteFile('c:\users\835b~1\appdata\local\temp\nsy7e9.tmp\setup_0655f1.exe','32');
DeleteFile('c:\program files (x86)\sfk\ssfk.exe','32');
DeleteFile('c:\users\Инквизитор\appdata\local\gmsd_re_005010169\upgmsd_re_005010169.exe','32');
DeleteFile('C:\Windows\system32\drivers\contentdefenderdrv.sys','32');
DeleteFile('C:\Windows\system32\drivers\wfdrvr_vt_1_10_0_28.sys','32');
DeleteFile('C:\Program Files (x86)\gmsd_re_005010169\gmsd_re_005010169.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gmsd_re_005010169');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','upgmsd_re_005010169.exe');
DeleteFile('C:\Program Files (x86)\RCP\RegCleanPro.exe','32');
DeleteFile('C:\Windows\Tasks\RegClean Pro_UPDATES.job','64');
DeleteFile('C:\Windows\system32\Tasks\RegClean Pro','64');
DeleteFile('C:\Windows\system32\Tasks\RegClean Pro_DEFAULT','64');
DeleteFile('C:\Windows\system32\Tasks\RegClean Pro_UPDATES','64');
DeleteFile('C:\Windows\system32\Tasks\Total Video','64');
DeleteFile('C:\Windows\system32\Tasks\Total Video2','64');
DeleteFile('C:\Users\Инквизитор\AppData\Local\Total Video\{E8C78333-380F-B8CB-9F60-A6140DBCFFF9}\TotalVideo.dll','32');
DeleteFile('C:\Users\Инквизитор\AppData\Local\Total Video\{E8C78333-380F-B8CB-9F60-A6140DBCFFF9}\trx.dll','32');
DeleteFile('C:\Program Files\content defender\condefsetup.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.