Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Program Files\movies toolbar\datamngr\datamngrcoordinator.exe','');
QuarantineFile('C:\Program Files\movies toolbar\datamngr\iebho.dll','');
QuarantineFile('C:\Users\Сергей\AppData\Roaming\newSI_4396\s_inst.exe','');
QuarantineFile('C:\Users\Сергей\AppData\Roaming\newSI_1008\s_inst.exe','');
QuarantineFile('C:\Program Files\globalUpdate\Update\GoogleUpdate.exe','');
DelBHO('{92780B25-18CC-41C8-B9BE-3C9C571A8263}');
DelBHO('{7CE987D5-11B3-44FC-9C3D-03069360D462}');
DelBHO('{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}');
DelBHO('{1FE48F08-A2AC-44AC-A21C-0556D91C50DA}');
QuarantineFile('C:\Program Files\XTab\SupTab.dll','');
QuarantineFile('C:\Program Files\advPlugin\Toolbar32.dll','');
QuarantineFile('C:\Users\Сергей\AppData\Local\Microsoft\Extensions\safebrowser.exe','');
QuarantineFile('C:\Users\Сергей\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\9521.tmp','');
QuarantineFile('C:\ProgramData\KRB Updater Utility\krbupdater-utility.exe','');
QuarantineFile('C:\Program Files\Kinoroom Browser\kinoroom-browser.exe','');
QuarantineFile('C:\Program Files\Internet Explorer\iexplore.exe.bat','');
QuarantineFile('C:\Windows\TEMP\advPlugin_restartonfail\InstallAfterRebootService0.exe','');
QuarantineFile('C:\Users\Сергей\AppData\Roaming\VOPackage\VOsrv.exe','');
DeleteService('servervo');
SetServiceStart('Rerun service for advPlugin', 4);
DeleteService('Rerun service for advPlugin');
QuarantineFile('C:\Windows\system32\drivers\{bab3007b-75f3-4020-8eee-4c923fdcb91b}Gw.sys','');
QuarantineFile('C:\Windows\system32\drivers\{1a7531da-31ad-48c5-8d60-be70ecfbab93}Gw.sys','');
TerminateProcessByName('c:\windows\temp\advplugin_restartonfail\installafterrebootservice0.exe');
QuarantineFile('c:\windows\temp\advplugin_restartonfail\installafterrebootservice0.exe','');
DeleteFile('c:\windows\temp\advplugin_restartonfail\installafterrebootservice0.exe','32');
DeleteFile('C:\Windows\system32\drivers\{1a7531da-31ad-48c5-8d60-be70ecfbab93}Gw.sys','32');
DeleteFile('C:\Windows\system32\drivers\{bab3007b-75f3-4020-8eee-4c923fdcb91b}Gw.sys','32');
DeleteFile('C:\Users\Сергей\AppData\Roaming\VOPackage\VOsrv.exe','32');
DeleteFile('C:\Windows\TEMP\advPlugin_restartonfail\InstallAfterRebootService0.exe','32');
DeleteFile('C:\Program Files\Internet Explorer\iexplore.exe.bat','32');
DeleteFile('C:\Program Files\Kinoroom Browser\kinoroom-browser.exe','32');
DeleteFile('C:\ProgramData\KRB Updater Utility\krbupdater-utility.exe','32');
DeleteFile('C:\Users\Сергей\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\9521.tmp','32');
DeleteFile('C:\Users\Сергей\AppData\Local\Microsoft\Extensions\safebrowser.exe','32');
DeleteFile('C:\Users\Сергей\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\recovery.bmp','32');
DeleteFile('C:\Program Files\advPlugin\Toolbar32.dll','32');
DeleteFile('C:\Program Files\XTab\SupTab.dll','32');
DeleteFile('C:\Program Files\globalUpdate\Update\GoogleUpdate.exe','32');
DeleteFile('C:\Users\Сергей\AppData\Roaming\newSI_1008\s_inst.exe','32');
DeleteFile('C:\Users\Сергей\AppData\Roaming\newSI_4396\s_inst.exe','32');
DeleteFile('C:\Windows\Tasks\newSI_4396.job','32');
DeleteFile('C:\Windows\Tasks\newSI_1008.job','32');
DeleteFile('C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job','32');
DeleteFile('C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job','32');
DeleteFile('C:\Windows\Tasks\558ff261-2cee-4b71-b7d5-697b18ab8b2f-5_user.job','32');
DeleteFile('C:\Windows\Tasks\558ff261-2cee-4b71-b7d5-697b18ab8b2f-10_user.job','32');
DeleteFile('C:\Windows\Tasks\558ff261-2cee-4b71-b7d5-697b18ab8b2f-1-6.job','32');
DeleteFile('C:\Windows\Tasks\NIUSHY.job','32');
DeleteFile('C:\Windows\Tasks\QATXHKQC.job','32');
DeleteFile('C:\Program Files\RCP\systweakasp.exe','32');
DeleteFile('C:\Windows\system32\Tasks\558ff261-2cee-4b71-b7d5-697b18ab8b2f-1-6','32');
DeleteFile('C:\Windows\system32\Tasks\ASP','32');
DeleteFile('C:\Windows\system32\Tasks\globalUpdateUpdateTaskMachineCore','32');
DeleteFile('C:\Windows\system32\Tasks\globalUpdateUpdateTaskMachineUA','32');
DeleteFile('C:\Windows\system32\Tasks\kbrowser-updater-utility','32');
DeleteFile('C:\Windows\system32\Tasks\KRB Updater Utility','32');
DeleteFile('C:\Windows\system32\Tasks\newSI_1008','32');
DeleteFile('C:\Windows\system32\Tasks\newSI_4396','32');
DeleteFile('C:\Windows\system32\Tasks\Safebrowser','32');
DeleteFile('C:\Users\Сергей\AppData\Roaming\omniboxes\UninstallManager.exe','32');
DeleteFile('C:\Windows\system32\Tasks\{4A6B3E43-7BE6-497E-9C4C-9BB310C5889A}','32');
DeleteFile('C:\Program Files\movies toolbar\datamngr\iebho.dll','32');
DeleteFile('C:\Program Files\movies toolbar\datamngr\datamngrcoordinator.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteREpair(9);
RebootWindows(false);
end.
Компьютер перезагрузится.