Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\Admin\AppData\Roaming\sweet-page\UninstallManager.exe','');
QuarantineFile('C:\PROGRA~2\SupTab\SEARCH~1.DLL','');
QuarantineFile('C:\Users\Admin\AppData\Local\ControlDriverPublic\RgFltX64.sys','');
QuarantineFile('C:\Users\Admin\AppData\Local\GNUGUIText\RegFltrX64.sys','');
DeleteService('RgFltX64');
DeleteService('RegFltrX64');
QuarantineFile('C:\Users\Admin\AppData\Local\scripttwextDrv\scripttwextDrv.exe','');
QuarantineFile('C:\Program Files (x86)\Pirrit\AutoUpdater.exe','');
QuarantineFile('C:\Users\Admin\AppData\Local\PirritSuggestor\PirritService.exe','');
QuarantineFile('C:\Users\Admin\AppData\Local\officepublicx64\officepublicx64.exe','');
QuarantineFile('C:\ProgramData\IePluginService\PluginService.exe','');
QuarantineFile('C:\Users\Admin\AppData\Local\GNUGUIText\GNUGUIText.exe','');
QuarantineFile('C:\Users\Admin\AppData\Local\FunctionRuntimeWin32\FunctionRuntimeWin32.exe','');
QuarantineFile('C:\Users\Admin\AppData\Local\finderjreapi\finderjreapi.exe','');
QuarantineFile('C:\Users\Admin\AppData\Local\DaemonSambaTrash\DaemonSambaTrash.exe','');
QuarantineFile('C:\Users\Admin\AppData\Local\ControlDriverPublic\ControlDriverPublic.exe','');
QuarantineFile('C:\Users\Admin\AppData\Local\CodecIndexKeyboard\CodecIndexKeyboard.exe','');
DeleteService('scripttwextDrv.exe');
DeleteService('PirritUpdater');
DeleteService('PirritDesktop');
DeleteService('officepublicx64.exe');
DeleteService('IePluginService');
DeleteService('GNUGUIText.exe');
DeleteService('FunctionRuntimeWin32.exe');
DeleteService('finderjreapi.exe');
DeleteService('DaemonSambaTrash.exe');
DeleteService('ControlDriverPublic.exe');
DeleteService('CodecIndexKeyboard.exe');
DeleteService('AppRecycleRegister.exe');
DeleteService('AppDaemonFolder.exe');
QuarantineFile('C:\Users\Admin\AppData\Local\2cabcc15d436ce946b4530f0f438043e\AppRecycleRegister.exe','');
QuarantineFile('C:\Users\Admin\AppData\Local\AppDaemonFolder\AppDaemonFolder.exe','');
DeleteService('58498c2def3266a.exe');
QuarantineFile('C:\Users\Admin\AppData\Local\f24df0deae1e53c22cf9fc33b618dd49\58498c2def3266a.exe','');
SetServiceStart('Task Manager Pro', 4);
DeleteService('Task Manager Pro');
QuarantineFile('C:\Users\Admin\AppData\Local\rawrepositorySched\rawrepositorySched.exe','');
SetServiceStart('rawrepositorySched.exe', 4);
DeleteService('rawrepositorySched.exe');
TerminateProcessByName('c:\users\admin\appdata\local\rawrepositorysched\compilefile_86.exe');
TerminateProcessByName('c:\users\admin\appdata\local\rawrepositorysched\rawrepositorysched.exe');
TerminateProcessByName('C:\Windows\taskmgr.exe');
QuarantineFile('C:\Windows\taskmgr.exe','');
QuarantineFile('c:\users\admin\appdata\local\rawrepositorysched\rawrepositorysched.exe','');
QuarantineFile('c:\program files (x86)\popapp\psisrndrehstorgui.exe','');
QuarantineFile('c:\users\admin\appdata\local\rawrepositorysched\compilefile_86.exe','');
TerminateProcessByName('c:\program files (x86)\edealpop\edealpop.exe');
QuarantineFile('c:\program files (x86)\edealpop\edealpop.exe','');
DeleteFile('c:\program files (x86)\edealpop\edealpop.exe','32');
DeleteFile('c:\users\admin\appdata\local\rawrepositorysched\rawrepositorysched.exe','32');
DeleteFile('C:\Windows\taskmgr.exe','32');
DeleteFile('c:\users\admin\appdata\local\rawrepositorysched\compilefile_86.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\rawrepositorySched\rawrepositorySched.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\f24df0deae1e53c22cf9fc33b618dd49\58498c2def3266a.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\AppDaemonFolder\AppDaemonFolder.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\2cabcc15d436ce946b4530f0f438043e\AppRecycleRegister.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\CodecIndexKeyboard\CodecIndexKeyboard.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\ControlDriverPublic\ControlDriverPublic.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\DaemonSambaTrash\DaemonSambaTrash.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\finderjreapi\finderjreapi.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\FunctionRuntimeWin32\FunctionRuntimeWin32.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\GNUGUIText\GNUGUIText.exe','32');
DeleteFile('C:\ProgramData\IePluginService\PluginService.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\officepublicx64\officepublicx64.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\PirritSuggestor\PirritService.exe','32');
DeleteFile('C:\Program Files (x86)\Pirrit\AutoUpdater.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\scripttwextDrv\scripttwextDrv.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\GNUGUIText\RegFltrX64.sys','32');
DeleteFile('C:\Users\Admin\AppData\Local\ControlDriverPublic\RgFltX64.sys','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','eDealPop');
DeleteFile('C:\PROGRA~2\SupTab\SEARCH~1.DLL','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\eDealPop','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\eDealsPop','command');
DeleteFile('C:\Users\Admin\AppData\Roaming\sweet-page\UninstallManager.exe','32');
DeleteFile('C:\windows\system32\Tasks\{FC30987F-8920-42DC-874F-62861406F254}','64');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.