Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\user\appdata\local\systemdir\setsearchm.exe','');
TerminateProcessByName('c:\documents and settings\user\appdata\local\temp\88244633.exe');
QuarantineFile('c:\documents and settings\user\appdata\local\temp\88244633.exe','');
QuarantineFile('C:\Users\user\AppData\Local\Temp\ibalssa.exe','');
DelBHO('{7CE987D5-11B3-44FC-9C3D-03069360D462}');
DelBHO('{1FE48F08-A2AC-44AC-A21C-0556D91C50DA}');
QuarantineFile('C:\Program Files (x86)\advPlugin\Toolbar32.dll','');
QuarantineFile('C:\Users\user\AppData\Roaming\eTranslator\eTranslator.exe','');
QuarantineFile('C:\Users\user\AppData\Local\Temp\NETAB1~3.EXE','');
QuarantineFile('C:\Users\user\AppData\Local\Temp\NETAB1~2.EXE','');
QuarantineFile('C:\Program Files (x86)\PoivY.com\PoivY\poivy.exe','');
QuarantineFile('C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\x64\safetycrt.dll','');
SetServiceStart('F06DEFF2-5B9C-490D-910F-35D3A9119622', 4);
DeleteService('F06DEFF2-5B9C-490D-910F-35D3A9119622');
SetServiceStart('WindowsMangerProtect', 4);
DeleteService('WindowsMangerProtect');
SetServiceStart('Update Service for advPlugin', 4);
DeleteService('Update Service for advPlugin');
SetServiceStart('SafetyNutManager', 4);
DeleteService('SafetyNutManager');
SetServiceStart('Rerun service for advPlugin', 4);
DeleteService('Rerun service for advPlugin');
SetServiceStart('BackupStack', 4);
DeleteService('BackupStack');
QuarantineFile('C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\x64\configmgrc3.cfg','');
QuarantineFile('C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\safetycrt.dll','');
TerminateProcessByName('c:\program files (x86)\browser tab search by ask\safetynut\safetynutmanager.exe');
QuarantineFile('c:\program files (x86)\browser tab search by ask\safetynut\safetynutmanager.exe','');
TerminateProcessByName('c:\program files (x86)\browser tab search by ask\safetynut\safetynut.exe');
QuarantineFile('c:\program files (x86)\browser tab search by ask\safetynut\safetynut.exe','');
TerminateProcessByName('c:\programdata\windowsmangerprotect\protectwindowsmanager.exe');
QuarantineFile('c:\programdata\windowsmangerprotect\protectwindowsmanager.exe','');
TerminateProcessByName('c:\users\user\appdata\local\temp\netab1b.tmp.exe');
QuarantineFile('c:\users\user\appdata\local\temp\netab1b.tmp.exe','');
TerminateProcessByName('c:\users\user\appdata\local\temp\netab19.tmp.exe');
QuarantineFile('c:\users\user\appdata\local\temp\netab19.tmp.exe','');
TerminateProcessByName('c:\users\user\appdata\local\temp\netab11.tmp.exe');
QuarantineFile('c:\users\user\appdata\local\temp\netab11.tmp.exe','');
TerminateProcessByName('C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe');
TerminateProcessByName('c:\windows\temp\advplugin_restartonfail\installafterrebootservice0.exe');
QuarantineFile('c:\windows\temp\advplugin_restartonfail\installafterrebootservice0.exe','');
TerminateProcessByName('c:\program files (x86)\advplugin\basement\extensionupdaterservice.exe');
QuarantineFile('c:\program files (x86)\advplugin\basement\extensionupdaterservice.exe','');
TerminateProcessByName('c:\windows\temp\advplugin_restartonfail_exe\advplugin.exe');
QuarantineFile('c:\windows\temp\advplugin_restartonfail_exe\advplugin.exe','');
DeleteFile('c:\windows\temp\advplugin_restartonfail_exe\advplugin.exe','32');
DeleteFile('c:\program files (x86)\advplugin\basement\extensionupdaterservice.exe','32');
DeleteFile('c:\windows\temp\advplugin_restartonfail\installafterrebootservice0.exe','32');
DeleteFile('C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe','32');
DeleteFile('c:\users\user\appdata\local\temp\netab11.tmp.exe','32');
DeleteFile('c:\users\user\appdata\local\temp\netab19.tmp.exe','32');
DeleteFile('c:\users\user\appdata\local\temp\netab1b.tmp.exe','32');
DeleteFile('c:\programdata\windowsmangerprotect\protectwindowsmanager.exe','32');
DeleteFile('c:\program files (x86)\browser tab search by ask\safetynut\safetynut.exe','32');
DeleteFile('c:\program files (x86)\browser tab search by ask\safetynut\safetynutmanager.exe','32');
DeleteFile('C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\safetycrt.dll','32');
DeleteFile('C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\x64\configmgrc3.cfg','32');
DeleteFile('C:\Program Files (x86)\MyPC Backup\BackupStack.exe','32');
DeleteFile('C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\x64\safetycrt.dll','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','System\CurrentControlSet\Control\Session Manager\AppCertDlls','x86');
RegKeyParamDel('HKEY_LOCAL_MACHINE','System\CurrentControlSet\Control\Session Manager\AppCertDlls','x64');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','GoSearchRemoveAppfirefox');
DeleteFile('C:\Users\user\AppData\Local\Temp\NETAB1~2.EXE','32');
DeleteFile('C:\Users\user\AppData\Local\Temp\NETAB1~3.EXE','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','GoSearchRemoveAppiexplore');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','GoSearch_startsetsearch_chrome');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','GoSearch_startsetsearch_oldopera');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','GoSearch_startsetsearch_opera');
DeleteFile('C:\Users\user\AppData\Roaming\eTranslator\eTranslator.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','eTranslator Update');
DeleteFile('C:\Program Files (x86)\advPlugin\Toolbar32.dll','32');
DeleteFile('C:\Users\user\AppData\Local\Temp\ibalssa.exe','32');
DeleteFile('C:\Windows\system32\Tasks\jufgfnj','64');
DeleteFile('C:\Windows\system32\Tasks\LaunchSignup','64');
DeleteFile('c:\documents and settings\user\appdata\local\temp\88244633.exe','32');
DeleteFile('C:\Users\user\appdata\local\systemdir\setsearchm.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteREpair(9);
RebootWindows(false);
end.
Компьютер перезагрузится.