Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
TerminateProcessByName('c:\program files\manager\manager.exe');
StopService('QMUdisk');
StopService('softaal');
StopService('TcHardWare');
DeleteService('HHandler Service');
DeleteService('QMUdisk');
DeleteService('softaal');
DeleteService('TcHardWare');
QuarantineFile('C:\Program Files\IconRunner\MoneyBot.exe','');
QuarantineFile('C:\Program Files\manager\manager.exe','');
QuarantineFileF('C:\Program Files\manager', '*.exe,*.dll,*.sys, *.pif', false,'', 0, 0);
QuarantineFile('C:\Program Files\Tencent\QQPCMgr\11.7.17744.210\QMUdisk.sys','');
QuarantineFile('C:\Program Files\Tencent\QQPCMgr\11.7.17744.210\QQPCHW.sys','');
QuarantineFile('C:\Program Files\Tencent\QQPCMgr\11.7.17744.210\softaal.sys','');
QuarantineFile('C:\ProgramData\EMbFwmEJc\HDAFHYYN3.bat','');
QuarantineFile('C:\ProgramData\jHaDfePCQuF\DFeKzhItKOMA0.bat','');
QuarantineFile('C:\PROGRA~1\SEARCH~1\Datamngr\datamngr.dll','');
QuarantineFile('C:\PROGRA~1\SEARCH~1\Datamngr\DATAMN~1.EXE','');
QuarantineFile('C:\PROGRA~1\SEARCH~1\Datamngr\IEBHO.dll','');
QuarantineFile('C:\Users\Alegarh\AppData\Roaming\Adobe\Manager.exe','');
DeleteFile('C:\Program Files\IconRunner\MoneyBot.exe','32');
DeleteFile('c:\program files\manager\manager.exe','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\11.7.17744.210\QMUdisk.sys','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\11.7.17744.210\QQPCHW.sys','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\11.7.17744.210\softaal.sys','32');
DeleteFile('C:\ProgramData\EMbFwmEJc\HDAFHYYN3.bat','32');
DeleteFile('C:\ProgramData\jHaDfePCQuF\DFeKzhItKOMA0.bat','32');
DeleteFile('C:\PROGRA~1\SEARCH~1\Datamngr\datamngr.dll','32');
DeleteFile('C:\PROGRA~1\SEARCH~1\Datamngr\DATAMN~1.EXE','32');
DeleteFile('C:\PROGRA~1\SEARCH~1\Datamngr\IEBHO.dll','32');
DeleteFile('C:\Users\Alegarh\AppData\Roaming\Adobe\Manager.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\Multimedia\Manager','32');
DeleteFileMask('C:\ProgramData\EMbFwmEJc', '*', true, ' ');
DeleteDirectory('C:\ProgramData\EMbFwmEJc');
DeleteFileMask('C:\Program Files\Tencent', '*', true, ' ');
DeleteDirectory('C:\Program Files\Tencent');
DeleteFileMask('C:\ProgramData\jHaDfePCQuF', '*', true, ' ');
DeleteDirectory('C:\ProgramData\jHaDfePCQuF');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','IconRunner');
BC_ImportAll;
ExecuteSysClean;
ExecuteRepair(13);
BC_Activate;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
После выполнения скрипта компьютер перезагрузится.