Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
StopService('BAPIDRV');
StopService('QMUdisk');
StopService('sbmntr');
StopService('softaal');
StopService('SSFK');
StopService('tsnethlpx64');
StopService('WajaNetEn Monitor');
StopService('zigipyro');
DeleteService('BAPIDRV');
DeleteService('QMUdisk');
DeleteService('sbmntr');
DeleteService('SSFK');
DeleteService('tsnethlpx64');
DeleteService('WajaNetEn Monitor');
DeleteService('zigipyro');
QuarantineFile('C:\Program Files (x86)\IconRunner\MoneyBot.exe','');
QuarantineFile('C:\Program Files (x86)\ppt\ppt.exe','');
QuarantineFile('C:\Program Files (x86)\ppt\Uninst.exe','');
QuarantineFile('C:\Program Files (x86)\SFK\SSFK.exe','');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17207.222\plugins\FileSmash\QMSoftExt.dll','');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17207.222\QMUdisk64.sys','');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17207.222\softaal64.sys','');
QuarantineFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17207.222\TsNetHlpX64.sys','');
QuarantineFile('C:\Program Files (x86)\Whats my computer doing\QHTM.dll','');
QuarantineFile('c:\program files (x86)\whats my computer doing\whatsmycomputerdoing.exe','');
QuarantineFile('C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe','');
QuarantineFile('C:\Program Files\WajaNetEn\a55a562986518bada6ef48adeac33e6f.exe','');
QuarantineFileF('C:\ProgramData\8WdsM', '*', false,'', 0, 0);
QuarantineFile('C:\ProgramData\Appverifier\AppVerifierService.exe','');
QuarantineFile('C:\PROGRA~2\YTDOWN~1\sbmntr.sys','');
QuarantineFile('C:\Users\User\AppData\Local\3100D6DD-1454711085-44AB-8504-85B6054C0A2C\qnsr839B.tmp','');
QuarantineFile('C:\Users\User\AppData\Roaming\76a72dc0-c209-42ee-a82a-75d9b7cc62f8\76a72dc0-c209-42ee-a82a-75d9b7cc62f8.exe','');
QuarantineFile('C:\Users\User\appdata\roaming\aspackage\uninstall.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\Browsers\exe.resworbcu.bat','');
QuarantineFile('C:\Users\User\Downloads\HimawariBackground-master\HimawariBackground-master\HimawariBackground.exe','');
QuarantineFile('C:\WINDOWS\csrss.exe','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\BAPIDRV64.sys','');
QuarantineFile('E:\Programms\Installed\denwer\denwer\Boot.exe','');
QuarantineFile('ProtectMonitor.sys','');
DeleteFile('C:\Program Files (x86)\ppt\ppt.exe','32');
DeleteFile('C:\Program Files (x86)\ppt\Uninst.exe','32');
DeleteFile('C:\Program Files (x86)\SFK\SSFK.exe','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17207.222\plugins\FileSmash\QMSoftExt.dll','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17207.222\QMUdisk64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17207.222\softaal64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17207.222\TsNetHlpX64.sys','32');
DeleteFile('C:\Program Files\WajaNetEn\a55a562986518bada6ef48adeac33e6f.exe','32');
DeleteFileMask('C:\ProgramData\8Wds', '*', true, ' ');
DeleteDirectory('C:\ProgramData\8Wds');
DeleteFile('C:\PROGRA~2\YTDOWN~1\sbmntr.sys','32');
DeleteFile('C:\Users\User\AppData\Local\3100D6DD-1454711085-44AB-8504-85B6054C0A2C\qnsr839B.tmp','32');
DeleteFile('C:\Users\User\AppData\Roaming\76a72dc0-c209-42ee-a82a-75d9b7cc62f8\76a72dc0-c209-42ee-a82a-75d9b7cc62f8.exe','32');
DeleteFile('C:\Users\User\appdata\roaming\aspackage\uninstall.exe','32');
DeleteFile('C:\Users\User\AppData\Roaming\Browsers\exe.resworbcu.bat','32');
DeleteFile('C:\WINDOWS\csrss.exe','32');
DeleteFile('C:\WINDOWS\system32\DRIVERS\BAPIDRV64.sys','32');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\SystemRestore\76a72dc0-c209-42ee-a82a-75d9b7cc62f8','64');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','apphide');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','Application Restart #12');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','apphide');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','pcmgr');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved','{754DF2CE-51E8-4895-B53C-6381418B84AE}');
RegKeyStrParamWrite('HKCU', 'Control Panel\Desktop', 'WaitToKillAppTimeout', '20000');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Eventlog\Application\WdsManPro,','EventMessageFile');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
После выполнения скрипта компьютер перезагрузится.