Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Windows\system32\mintcastnetworks.dll','');
QuarantineFile('C:\Program Files\iWebar\5044b360-6d84-4980-9389-b00edfd98d51-5.exe','');
QuarantineFile('C:\Program Files\iWebar\5044b360-6d84-4980-9389-b00edfd98d51-2.exe','');
QuarantineFile('C:\Program Files\iWebar\5044b360-6d84-4980-9389-b00edfd98d51-11.exe','');
QuarantineFile('C:\Program Files\iWebar\iWebar-codedownloader.exe','');
QuarantineFile('C:\Program Files\Senses\07e09f58-224a-46ba-8ea1-f9f35f3ea502-5.exe','');
QuarantineFile('C:\Program Files\Senses\07e09f58-224a-46ba-8ea1-f9f35f3ea502-2.exe','');
QuarantineFile('C:\Program Files\Senses\07e09f58-224a-46ba-8ea1-f9f35f3ea502-11.exe','');
QuarantineFile('C:\Program Files\Senses\Senses-codedownloader.exe','');
DelBHO('{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}');
DelBHO('{acf1c4d3-b7e6-4fa6-baac-dd2a18fc61bf}');
QuarantineFile('C:\Program Files\BrowseStudio\BrowseStudiobho.dll','');
QuarantineFile('C:\ProgramData\ShopperPro\ShopperPro.dll','');
DelBHO('{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}');
QuarantineFile('C:\Users\Andrey.user-ПК\AppData\Local\Microsoft\Internet Explorer\Extensions\APIHelper.dll','');
QuarantineFile('C:\Users\Andrey.user-ПК\Documents\Application Data\explorer.exe','');
QuarantineFile('C:\Users\Andrey.user-ПК\AppData\Roaming\eTranslator\eTranslator.exe','');
QuarantineFile('C:\Users\Andrey.user-ПК\AppData\Local\storegid\storegidup.exe','');
QuarantineFile('C:\Users\Andrey.user-ПК\AppData\Local\Microsoft\Windows\toolbar.exe','');
QuarantineFile('C:\Program Files\Google\Chrome\Application\chrome.exe.bat','');
QuarantineFile('C:\Program Files\ShopperPro\JSDriver\1.37.0.1393\jsdrv.sys','');
QuarantineFile('C:\Program Files\Common Files\ShopperPro\spbiw.sys','');
DeleteService('SPDRIVER_1.37.0.1393');
DeleteService('SPBIUpdd');
SetServiceStart('storegidfilter', 4);
DeleteService('storegidfilter');
QuarantineFile('C:\Program Files\Common Files\ShopperPro\spbiu.exe','');
DeleteService('SPBIUpd');
QuarantineFile('C:\Windows\storegidfilter.sys','');
DeleteFile('C:\Windows\storegidfilter.sys','32');
DeleteFile('C:\Program Files\Common Files\ShopperPro\spbiu.exe','32');
DeleteFile('C:\Program Files\Common Files\ShopperPro\spbiw.sys','32');
DeleteFile('C:\Program Files\ShopperPro\JSDriver\1.37.0.1393\jsdrv.sys','32');
DeleteFile('C:\Program Files\Google\Chrome\Application\chrome.exe.bat','32');
DeleteFile('C:\Users\Andrey.user-ПК\AppData\Local\Microsoft\Windows\toolbar.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','SystemScript');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','SystemScript');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SystemScript','command');
DeleteFile('C:\Users\Andrey.user-ПК\AppData\Local\storegid\storegidup.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\storegidUpdater','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\eTranslator Update','command');
DeleteFile('C:\Users\Andrey.user-ПК\AppData\Roaming\eTranslator\eTranslator.exe','32');
DeleteFile('C:\Users\Andrey.user-ПК\Documents\Application Data\explorer.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\~backup~','command');
DeleteFile('C:\Users\Andrey.user-ПК\AppData\Local\Microsoft\Internet Explorer\Extensions\APIHelper.dll','32');
DeleteFile('C:\ProgramData\ShopperPro\ShopperPro.dll','32');
DeleteFile('C:\Program Files\BrowseStudio\BrowseStudiobho.dll','32');
DeleteFile('C:\Program Files\Senses\Senses-codedownloader.exe','32');
DeleteFile('C:\Windows\Tasks\07e09f58-224a-46ba-8ea1-f9f35f3ea502-1.job','32');
DeleteFile('C:\Windows\Tasks\07e09f58-224a-46ba-8ea1-f9f35f3ea502-11.job','32');
DeleteFile('C:\Program Files\Senses\07e09f58-224a-46ba-8ea1-f9f35f3ea502-11.exe','32');
DeleteFile('C:\Program Files\Senses\07e09f58-224a-46ba-8ea1-f9f35f3ea502-2.exe','32');
DeleteFile('C:\Windows\Tasks\07e09f58-224a-46ba-8ea1-f9f35f3ea502-2.job','32');
DeleteFile('C:\Windows\Tasks\07e09f58-224a-46ba-8ea1-f9f35f3ea502-5.job','32');
DeleteFile('C:\Program Files\Senses\07e09f58-224a-46ba-8ea1-f9f35f3ea502-5.exe','32');
DeleteFile('C:\Windows\Tasks\07e09f58-224a-46ba-8ea1-f9f35f3ea502-5_user.job','32');
DeleteFile('C:\Windows\Tasks\43dbca3c-61c2-44ee-8cd2-3daa8025ab5a-1.job','32');
DeleteFile('C:\Windows\Tasks\43dbca3c-61c2-44ee-8cd2-3daa8025ab5a-11.job','32');
DeleteFile('C:\Windows\Tasks\43dbca3c-61c2-44ee-8cd2-3daa8025ab5a-2.job','32');
DeleteFile('C:\Windows\Tasks\43dbca3c-61c2-44ee-8cd2-3daa8025ab5a-5.job','32');
DeleteFile('C:\Windows\Tasks\43dbca3c-61c2-44ee-8cd2-3daa8025ab5a-5_user.job','32');
DeleteFile('C:\Program Files\iWebar\iWebar-codedownloader.exe','32');
DeleteFile('C:\Windows\Tasks\5044b360-6d84-4980-9389-b00edfd98d51-1.job','32');
DeleteFile('C:\Windows\Tasks\5044b360-6d84-4980-9389-b00edfd98d51-11.job','32');
DeleteFile('C:\Program Files\iWebar\5044b360-6d84-4980-9389-b00edfd98d51-11.exe','32');
DeleteFile('C:\Program Files\iWebar\5044b360-6d84-4980-9389-b00edfd98d51-2.exe','32');
DeleteFile('C:\Windows\Tasks\5044b360-6d84-4980-9389-b00edfd98d51-2.job','32');
DeleteFile('C:\Windows\Tasks\5044b360-6d84-4980-9389-b00edfd98d51-5.job','32');
DeleteFile('C:\Program Files\iWebar\5044b360-6d84-4980-9389-b00edfd98d51-5.exe','32');
DeleteFile('C:\Windows\Tasks\5044b360-6d84-4980-9389-b00edfd98d51-5_user.job','32');
DeleteFile('C:\Windows\system32\Tasks\07e09f58-224a-46ba-8ea1-f9f35f3ea502-1','32');
DeleteFile('C:\Windows\system32\Tasks\07e09f58-224a-46ba-8ea1-f9f35f3ea502-11','32');
DeleteFile('C:\Windows\system32\Tasks\07e09f58-224a-46ba-8ea1-f9f35f3ea502-2','32');
DeleteFile('C:\Windows\system32\Tasks\07e09f58-224a-46ba-8ea1-f9f35f3ea502-5','32');
DeleteFile('C:\Windows\system32\Tasks\07e09f58-224a-46ba-8ea1-f9f35f3ea502-5_user','32');
DeleteFile('C:\Windows\system32\Tasks\43dbca3c-61c2-44ee-8cd2-3daa8025ab5a-1','32');
DeleteFile('C:\Windows\system32\Tasks\43dbca3c-61c2-44ee-8cd2-3daa8025ab5a-11','32');
DeleteFile('C:\Windows\system32\Tasks\43dbca3c-61c2-44ee-8cd2-3daa8025ab5a-2','32');
DeleteFile('C:\Windows\system32\Tasks\43dbca3c-61c2-44ee-8cd2-3daa8025ab5a-5','32');
DeleteFile('C:\Windows\system32\Tasks\43dbca3c-61c2-44ee-8cd2-3daa8025ab5a-5_user','32');
DeleteFile('C:\Windows\system32\Tasks\5044b360-6d84-4980-9389-b00edfd98d51-1','32');
DeleteFile('C:\Windows\system32\Tasks\5044b360-6d84-4980-9389-b00edfd98d51-11','32');
DeleteFile('C:\Windows\system32\Tasks\5044b360-6d84-4980-9389-b00edfd98d51-2','32');
DeleteFile('C:\Windows\system32\Tasks\5044b360-6d84-4980-9389-b00edfd98d51-5','32');
DeleteFile('C:\Windows\system32\Tasks\5044b360-6d84-4980-9389-b00edfd98d51-5_user','32');
DeleteFile('C:\Windows\system32\Tasks\chrome5','32');
DeleteFile('C:\Windows\system32\Tasks\chrome5_logon','32');
DeleteFile('C:\Windows\system32\Tasks\ShopperPro','32');
DeleteFile('C:\Windows\system32\Tasks\ShopperProJSUpd','32');
DeleteFile('C:\Windows\system32\Tasks\SPDriver','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Компьютер перезагрузится.