Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Program Files (x86)\Common Files\Services\iThemes.dll','');
QuarantineFile('C:\ProgramData\wintools\WintoolUprI.exe','');
QuarantineFile('C:\Users\Дмитрий\AppData\Roaming\SafeWeb\updater.py','');
QuarantineFile('http:\api.mhttxtv.com\crucialxct128m550ssd1_14180c1c3af30c1c3af3.exe','');
QuarantineFile('C:\ProgramData\vCore\VCore.exe','');
QuarantineFile('C:\Program Files (x86)\UCBrowser\Application\update_task.exe','');
QuarantineFile('C:\Program Files (x86)\Grduseqverther System\local64spl.dll','');
QuarantineFile('C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe','');
QuarantineFile('C:\Users\Дмитрий\AppData\Roaming\SafeWeb\ml.py','');
DeleteService('Hotfresh');
DeleteService('gexejeke');
QuarantineFile('C:\ProgramData\Hotfresh\Hotfresh.exe','');
QuarantineFile('C:\Program Files (x86)\d45ebef0-0e6e-4b98-92ce-e2f42fc17e671483909700\knsd45ebef0-0e6e-4b98-92ce-e2f42fc17e67.tmpfs','');
QuarantineFile('c:\programdata\winsapsvc\winsap.dll','');
QuarantineFile('C:\Program Files\l5x4tf1s\{DE244DA7-D9A5-445A-9824-E24AD76CFF91}\0dg04fll.olq','');
DeleteFile('C:\Program Files\l5x4tf1s\{DE244DA7-D9A5-445A-9824-E24AD76CFF91}\0dg04fll.olq','32');
DeleteFile('c:\programdata\winsapsvc\winsap.dll','32');
DeleteFile('C:\Program Files (x86)\d45ebef0-0e6e-4b98-92ce-e2f42fc17e671483909700\knsd45ebef0-0e6e-4b98-92ce-e2f42fc17e67.tmpfs','32');
DeleteFile('C:\ProgramData\Hotfresh\Hotfresh.exe','32');
DeleteFile('C:\Users\Дмитрий\AppData\Roaming\SafeWeb\ml.py','32');
DeleteFile('C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','svchost0');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','SafeWeb');
DeleteFile('C:\Program Files (x86)\Grduseqverther System\local64spl.dll','32');
DeleteFile('C:\Windows\Tasks\UCBrowserUpdater.job','32');
DeleteFile('C:\Windows\Tasks\UCBrowserUpdaterCore.job','32');
DeleteFile('C:\Program Files (x86)\UCBrowser\Application\update_task.exe','32');
DeleteFile('C:\Windows\Tasks\Update Service for Youtube AdBlock.job','32');
DeleteFile('C:\Windows\Tasks\Update Service for Youtube AdBlock2.job','32');
DeleteFile('C:\ProgramData\vCore\VCore.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\Media Center\VCore','64');
DeleteFile('C:\Windows\system32\Tasks\Milimili','64');
DeleteFile('http:\api.mhttxtv.com\crucialxct128m550ssd1_14180c1c3af30c1c3af3.exe','32');
DeleteFile('C:\Windows\system32\Tasks\SafeWeb','64');
DeleteFile('C:\Windows\system32\Tasks\SafeWeb2','64');
DeleteFile('C:\Users\Дмитрий\AppData\Roaming\SafeWeb\updater.py','32');
DeleteFile('C:\Windows\system32\Tasks\SecureUpdater','64');
DeleteFile('C:\Windows\system32\Tasks\UCBrowserUpdater','64');
DeleteFile('C:\Windows\system32\Tasks\UCBrowserUpdaterCore','64');
DeleteFile('C:\Windows\system32\Tasks\Update Service for Youtube AdBlock','64');
DeleteFile('C:\Windows\system32\Tasks\Update Service for Youtube AdBlock2','64');
DeleteFile('C:\Windows\system32\Tasks\WinTOOL','64');
DeleteFile('C:\ProgramData\wintools\WintoolUprI.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.