Код:
procedure DeleteDirectoryF(N: String);
begin
DeleteFileMask(N, '*', true);
DeleteDirectory(N);
end;
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\1\appdata\local\pay-by-ads\yahoo! search\1.3.15.4\dsrsetup.exe','');
QuarantineFile('C:\Users\1\appdata\local\pay-by-ads\yahoo! search\1.3.15.4\dsrlte.exe','');
QuarantineFile('C:\Users\1\appdata\local\pay-by-ads\yahoo! search\1.3.12.4\dsrsetup.exe','');
QuarantineFile('C:\Users\1\appdata\local\pay-by-ads\yahoo! search\1.3.12.4\dsrlte.exe','');
QuarantineFile('C:\Users\1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE','');
QuarantineFile('C:\PROGRA~2\OPERAH~1\OPERA_~1.EXE','');
QuarantineFile('C:\Program Files (x86)\ver3BlockAndSurf\J6BlockAndSurfR79.exe','');
QuarantineFile('C:\Users\1\AppData\Roaming\AGYVV.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaPlus12bV03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-7.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaPlus12bV03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-6.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaPlus12bV03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-5.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaPlus12bV03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-11.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaPlus12bV03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-1-7.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaPlus12bV03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-1-6.exe','');
DelBHO('{37827FC8-C8FF-2CDB-30B4-1D9052361621}');
QuarantineFile('C:\Program Files (x86)\ver3BlockAndSurf\187.dll','');
QuarantineFile('C:\Users\1\AppData\Roaming\Browsers\exe.resworb.bat','');
QuarantineFile('C:\Users\1\AppData\Roaming\Browsers\exe.erolpxei.bat','');
QuarantineFile('C:\Users\1\AppData\Roaming\Browsers\exe.emorhc.bat','');
QuarantineFile('C:\Users\1\AppData\Roaming\Browsers\exe.arepo.bat','');
SetServiceStart('{facdc9f6-60e8-45b2-8807-bf1a7548ccda}Gw64', 4);
DeleteService('{facdc9f6-60e8-45b2-8807-bf1a7548ccda}Gw64');
SetServiceStart('{f65802d2-0721-4106-8bec-2e7deda41572}Gw64', 4);
DeleteService('{f65802d2-0721-4106-8bec-2e7deda41572}Gw64');
SetServiceStart('{edcf0bac-c086-48f5-b577-f09b61095778}Gw64', 4);
DeleteService('{edcf0bac-c086-48f5-b577-f09b61095778}Gw64');
SetServiceStart('{e9ab7dfa-9d2f-4c48-8fd4-5314a020a2b5}Gw64', 4);
DeleteService('{e9ab7dfa-9d2f-4c48-8fd4-5314a020a2b5}Gw64');
SetServiceStart('{ce82773f-55f0-485d-83dd-5b67bdaf13ea}Gw64', 4);
DeleteService('{ce82773f-55f0-485d-83dd-5b67bdaf13ea}Gw64');
SetServiceStart('{bcab086d-ff5f-414f-8509-8e158d248caf}Gw64', 4);
DeleteService('{bcab086d-ff5f-414f-8509-8e158d248caf}Gw64');
SetServiceStart('{ac2b164b-7189-4743-b803-06981a00f9d8}Gw64', 4);
DeleteService('{ac2b164b-7189-4743-b803-06981a00f9d8}Gw64');
SetServiceStart('{9255f1e2-1754-4887-b5d8-8ea035831546}Gw64', 4);
DeleteService('{9255f1e2-1754-4887-b5d8-8ea035831546}Gw64');
SetServiceStart('{8ec359df-296d-4b42-a63e-bf65b4956546}Gw64', 4);
DeleteService('{8ec359df-296d-4b42-a63e-bf65b4956546}Gw64');
SetServiceStart('{8431bbbd-4243-4758-beab-348411cd1e12}Gw64', 4);
DeleteService('{8431bbbd-4243-4758-beab-348411cd1e12}Gw64');
SetServiceStart('{3f7fa6e7-633b-4753-a8aa-90403860bfc7}Gw64', 4);
DeleteService('{3f7fa6e7-633b-4753-a8aa-90403860bfc7}Gw64');
SetServiceStart('webinstrNHKT', 4);
DeleteService('webinstrNHKT');
SetServiceStart('ssnfd', 4);
DeleteService('ssnfd');
SetServiceStart('serversu', 4);
DeleteService('serversu');
SetServiceStart('serverca', 4);
DeleteService('serverca');
QuarantineFile('C:\Windows\system32\drivers\{fef7f75c-f985-4250-96f9-8183cd04238b}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{facdc9f6-60e8-45b2-8807-bf1a7548ccda}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{f65802d2-0721-4106-8bec-2e7deda41572}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{edcf0bac-c086-48f5-b577-f09b61095778}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{e9ab7dfa-9d2f-4c48-8fd4-5314a020a2b5}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{ce82773f-55f0-485d-83dd-5b67bdaf13ea}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{bcab086d-ff5f-414f-8509-8e158d248caf}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{ac2b164b-7189-4743-b803-06981a00f9d8}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{9255f1e2-1754-4887-b5d8-8ea035831546}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{8ec359df-296d-4b42-a63e-bf65b4956546}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{8431bbbd-4243-4758-beab-348411cd1e12}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{3f7fa6e7-633b-4753-a8aa-90403860bfc7}Gw64.sys','');
QuarantineFile('C:\Windows\system32\Drivers\webinstrNHKT.sys','');
QuarantineFile('C:\Windows\system32\drivers\ssnfd.sys','');
QuarantineFile('C:\Users\1\AppData\Local\SmartWeb\swhk.dll','');
TerminateProcessByName('c:\users\1\appdata\local\wincheck\wincheck.exe');
QuarantineFile('c:\users\1\appdata\local\wincheck\wincheck.exe','');
TerminateProcessByName('c:\users\1\appdata\local\gmsd_ru_112\upgmsd_ru_112.exe');
QuarantineFile('c:\users\1\appdata\local\gmsd_ru_112\upgmsd_ru_112.exe','');
TerminateProcessByName('c:\users\1\appdata\roaming\softwareupdater\susrv.exe');
QuarantineFile('c:\users\1\appdata\roaming\softwareupdater\susrv.exe','');
TerminateProcessByName('c:\users\1\appdata\local\smartweb\smartwebhelper.exe');
QuarantineFile('c:\users\1\appdata\local\smartweb\smartwebhelper.exe','');
TerminateProcessByName('c:\users\1\appdata\local\smartweb\smartwebapp.exe');
QuarantineFile('c:\users\1\appdata\local\smartweb\smartwebapp.exe','');
QuarantineFile('c:\progra~2\operah~1\opera_~1.exe','');
TerminateProcessByName('c:\users\1\appdata\local\convertad\casrv.exe');
QuarantineFile('c:\users\1\appdata\local\convertad\casrv.exe','');
TerminateProcessByName('c:\program files (x86)\ver3blockandsurf\blockandsurf.exe');
QuarantineFile('c:\program files (x86)\ver3blockandsurf\blockandsurf.exe','');
TerminateProcessByName('c:\program files (x86)\cinemaplus12bv03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-6.exe');
QuarantineFile('c:\program files (x86)\cinemaplus12bv03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-6.exe','');
TerminateProcessByName('c:\program files (x86)\cinemaplus12bv03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-1-6.exe');
QuarantineFile('c:\program files (x86)\cinemaplus12bv03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-1-6.exe','');
DeleteFile('c:\program files (x86)\cinemaplus12bv03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-1-6.exe','32');
DeleteFile('c:\program files (x86)\cinemaplus12bv03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-6.exe','32');
DeleteFile('c:\program files (x86)\ver3blockandsurf\blockandsurf.exe','32');
DeleteFile('c:\users\1\appdata\local\convertad\casrv.exe','32');
DeleteFile('c:\users\1\appdata\local\smartweb\smartwebapp.exe','32');
DeleteFile('c:\users\1\appdata\local\smartweb\smartwebhelper.exe','32');
DeleteFile('c:\users\1\appdata\roaming\softwareupdater\susrv.exe','32');
DeleteFile('c:\users\1\appdata\local\gmsd_ru_112\upgmsd_ru_112.exe','32');
DeleteFile('c:\users\1\appdata\local\wincheck\wincheck.exe','32');
DeleteFile('C:\Users\1\AppData\Local\SmartWeb\swhk.dll','32');
DeleteFile('C:\Windows\system32\drivers\ssnfd.sys','32');
DeleteFile('C:\Windows\system32\Drivers\webinstrNHKT.sys','32');
DeleteFile('C:\Windows\system32\drivers\{3f7fa6e7-633b-4753-a8aa-90403860bfc7}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{8431bbbd-4243-4758-beab-348411cd1e12}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{8ec359df-296d-4b42-a63e-bf65b4956546}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{9255f1e2-1754-4887-b5d8-8ea035831546}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{ac2b164b-7189-4743-b803-06981a00f9d8}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{bcab086d-ff5f-414f-8509-8e158d248caf}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{ce82773f-55f0-485d-83dd-5b67bdaf13ea}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{e9ab7dfa-9d2f-4c48-8fd4-5314a020a2b5}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{edcf0bac-c086-48f5-b577-f09b61095778}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{f65802d2-0721-4106-8bec-2e7deda41572}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{facdc9f6-60e8-45b2-8807-bf1a7548ccda}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{fef7f75c-f985-4250-96f9-8183cd04238b}Gw64.sys','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','SmartWeb');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','upgmsd_ru_112.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','WinCheck');
DeleteFile('C:\Users\1\AppData\Roaming\Browsers\exe.arepo.bat','32');
DeleteFile('C:\Users\1\AppData\Roaming\Browsers\exe.emorhc.bat','32');
DeleteFile('C:\Users\1\AppData\Roaming\Browsers\exe.erolpxei.bat','32');
DeleteFile('C:\Users\1\AppData\Roaming\Browsers\exe.resworb.bat','32');
DeleteFile('C:\Program Files (x86)\ver3BlockAndSurf\187.dll','32');
DeleteFile('C:\Program Files (x86)\CinemaPlus12bV03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-1-6.exe','32');
DeleteFile('C:\Windows\Tasks\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-1-6.job','64');
DeleteFile('C:\Program Files (x86)\CinemaPlus12bV03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-1-7.exe','32');
DeleteFile('C:\Windows\Tasks\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-1-7.job','64');
DeleteFile('C:\Program Files (x86)\CinemaPlus12bV03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-11.exe','32');
DeleteFile('C:\Windows\Tasks\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-11.job','64');
DeleteFile('C:\Windows\Tasks\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-5.job','64');
DeleteFile('C:\Program Files (x86)\CinemaPlus12bV03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-5.exe','32');
DeleteFile('C:\Windows\Tasks\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-5_user.job','64');
DeleteFile('C:\Program Files (x86)\CinemaPlus12bV03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-6.exe','32');
DeleteFile('C:\Windows\Tasks\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-6.job','64');
DeleteFile('C:\Windows\Tasks\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-7.job','64');
DeleteFile('C:\Program Files (x86)\CinemaPlus12bV03.02\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-7.exe','32');
DeleteFile('C:\Users\1\AppData\Roaming\AGYVV.exe','32');
DeleteFile('C:\Windows\Tasks\AGYVV.job','64');
DeleteFile('C:\Program Files (x86)\ver3BlockAndSurf\J6BlockAndSurfR79.exe','32');
DeleteFile('C:\Windows\Tasks\BlockAndSurf Update.job','64');
DeleteFile('C:\Users\1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE','32');
DeleteFile('C:\Windows\Tasks\UpdaterEX.job','64');
DeleteFile('C:\Windows\system32\Tasks\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-1-6','64');
DeleteFile('C:\Windows\system32\Tasks\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-1-7','64');
DeleteFile('C:\Windows\system32\Tasks\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-11','64');
DeleteFile('C:\Windows\system32\Tasks\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-5','64');
DeleteFile('C:\Windows\system32\Tasks\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-6','64');
DeleteFile('C:\Windows\system32\Tasks\acbcce65-f4f6-4207-a9f4-1aeaa4a617ab-7','64');
DeleteFile('C:\Windows\system32\Tasks\BlockAndSurf Update','64');
DeleteFile('C:\Windows\system32\Tasks\SmartWeb Upgrade Trigger Task','64');
DeleteFile('C:\Users\1\appdata\local\pay-by-ads\yahoo! search\1.3.12.4\dsrlte.exe','32');
DeleteFile('C:\Users\1\appdata\local\pay-by-ads\yahoo! search\1.3.12.4\dsrsetup.exe','32');
DeleteFile('C:\Users\1\appdata\local\pay-by-ads\yahoo! search\1.3.15.4\dsrlte.exe','32');
DeleteFile('C:\Users\1\appdata\local\pay-by-ads\yahoo! search\1.3.15.4\dsrsetup.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Компьютер перезагрузится.