Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
end;
ClearQuarantine;
QuarantineFile('C:\Users\Вадос\appdata\roaming\newsi_2\s_inst.exe','');
QuarantineFile('C:\Users\Вадос\appdata\roaming\newsi_10\s_inst.exe','');
QuarantineFile('C:\Users\Вадос\appdata\roaming\mediahit\shadow\mediahit.update\mediahit.update.process.exe','');
QuarantineFile('C:\Users\Вадос\appdata\roaming\funspace\shadow\funspace.update\funspace.update.process.exe','');
QuarantineFile('C:\Users\Вадос\AppData\Local\Microsoft\Windows\system.vbs','');
QuarantineFile('C:\Users\Вадос\AppData\Roaming\Steam\Reversed\steam.exe','');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Roaming\DefaultTab\DefaultTab\DTReg.exe','');
QuarantineFile('C:\Users\Вадос\AppData\Local\22148\a25656.exe','');
QuarantineFile('C:\Program Files (x86)\WebConnect\bin\utilWebConnect.exe','');
QuarantineFile('C:\Program Files (x86)\Music Toolbar\Datamngr\DatamngrCoordinator.exe','');
DeleteFile('C:\Program Files (x86)\Music Toolbar\Datamngr\DatamngrCoordinator.exe','32');
DeleteFile('C:\Program Files (x86)\WebConnect\bin\utilWebConnect.exe','32');
DeleteFile('C:\PROGRA~3\Wincert\WIN32C~1.DLL','32');
DeleteFile('C:\PROGRA~3\Wincert\WIN64C~1.DLL','32');
DeleteFile('C:\Users\Вадос\AppData\Local\22148\a25656.exe','32');
DeleteFile('C:\Windows\Tasks\AmiUpdXp.job','64');
DeleteFile('C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job','64');
DeleteFile('C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job','64');
DeleteFile('C:\Windows\Tasks\UpdaterEX.job','64');
DeleteFile('C:\Windows\system32\Tasks\AmiUpdXp','64');
DeleteFile('C:\Windows\system32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore','64');
DeleteFile('C:\Windows\system32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA','64');
DeleteFile('C:\Windows\system32\Tasks\DTChk','64');
DeleteFile('C:\Windows\system32\Tasks\DTReg','64');
DeleteFile('C:\Windows\system32\config\systemprofile\AppData\Roaming\DefaultTab\DefaultTab\DTReg.exe','32');
DeleteFile('C:\Windows\system32\Tasks\LaunchSignup','64');
DeleteFile('C:\Users\Вадос\AppData\Roaming\Steam\Reversed\steam.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Steam-S-1-8-22-9865GUI','64');
DeleteFile('C:\Windows\system32\Tasks\SystemScript','64');
DeleteFile('C:\Users\Вадос\AppData\Local\Microsoft\Windows\system.vbs','32');
DeleteFile('C:\Windows\system32\Tasks\UpdaterEX','64');
DeleteFile('C:\Users\Вадос\appdata\roaming\funspace\shadow\funspace.update\funspace.update.process.exe','32');
DeleteFile('C:\Users\Вадос\appdata\roaming\mediahit\shadow\mediahit.update\mediahit.update.process.exe','32');
DeleteFile('C:\Users\Вадос\appdata\roaming\newsi_10\s_inst.exe','32');
DeleteFile('C:\Users\Вадос\appdata\roaming\newsi_2\s_inst.exe','32');
DeleteService('DatamngrCoordinator');
DeleteService('Util WebConnect');
DeleteFileMask('C:\Users\Вадос\appdata\roaming\funspace', '*', true, ' ');
DeleteFileMask('C:\Users\Вадос\appdata\roaming\mediahit', '*', true, ' ');
DeleteFileMask('C:\Users\Вадос\appdata\roaming\newsi_10', '*', true, ' ');
DeleteFileMask('C:\Users\Вадос\appdata\roaming\newsi_2', '*', true, ' ');
DeleteFileMask('C:\Users\Вадос\AppData\Roaming\Steam\Reversed', '*', true, ' ');
DeleteDirectory('C:\Users\Вадос\appdata\roaming\funspace');
DeleteDirectory('C:\Users\Вадос\appdata\roaming\mediahit');
DeleteDirectory('C:\Users\Вадос\appdata\roaming\newsi_10');
DeleteDirectory('C:\Users\Вадос\appdata\roaming\newsi_2');
DeleteDirectory('C:\Users\Вадос\AppData\Roaming\Steam\Reversed');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(2);
RebootWindows(false);
end.
Код:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=37255642d8510746656ea90cb840e133&text={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://webalta.ru/search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=37255642d8510746656ea90cb840e133&text={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://webalta.ru/search
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=37255642d8510746656ea90cb840e133&text=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=37255642d8510746656ea90cb840e133&text=
R3 - URLSearchHook: (no name) - {0633EE93-D776-472f-A0FF-E1416B8B2E3D} - (no file)