Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
SetServiceStart('UbarPolicyProvider', 4);
StopService('f63471cf44408e192b1d12a41df7a59f');
TerminateProcessByName('c:\users\dima\appdata\roaming\setupsk\python\pythonw.exe');
DeleteService('f63471cf44408e192b1d12a41df7a59f');
QuarantineFile('C:\PROGRA~2\FASTDA~1\FASTDA~1.EXE','');
QuarantineFile('C:\PROGRA~3\354eda3f\5f63ef50.dll','');
QuarantineFile('C:\Program Files (x86)\GXZiGyYLSHyU2\Iwr5Ze3.dll','');
QuarantineFile('C:\Program Files (x86)\thzXuJvjU\3nwXG8v.dll','');
QuarantineFile('C:\Program Files\UBar\UbarService.exe','');
QuarantineFile('C:\Program Files\UBar\ubar.exe','');
QuarantineFile('C:\Program Files\Uninstall Information\58TOP8UAN8LCYTIX4S78DO1M8E\iXQkh+66xP.exe','');
QuarantineFile('C:\Program Files\f63471cf44408e192b1d12a41df7a59f\31781279c3642074ab68378f9a0b4c34.exe','');
QuarantineFile('C:\ProgramData\{7C27B564-CB8C-02CF-3C3A-87180A6BC2C3}\9226E0CB-258D-5760-8121-3E6CFDE2BC16.exe','');
QuarantineFile('C:\Users\Dima\AppData\Local\SearchGo\searchgo.exe','');
QuarantineFile('C:\Users\Dima\AppData\Local\wupdate\wupdate.exe','');
QuarantineFile('C:\Users\Dima\AppData\Roaming\SETUPS~1\ml.py','');
QuarantineFile('C:\Users\Dima\AppData\Roaming\SETUPS~1\python\pythonw.exe','');
QuarantineFile('C:\Users\Dima\AppData\Roaming\setupsk\ml.py','');
QuarantineFile('C:\Users\Dima\AppData\Roaming\setupsk\python\DLLs\_ctypes.pyd','');
QuarantineFile('C:\Users\Dima\AppData\Roaming\setupsk\python\python34.dll','');
QuarantineFile('C:\Users\Dima\AppData\Roaming\setupsk\python\pythonw.exe','');
QuarantineFile('C:\Users\Dima\appdata\roaming\sysmon\sysmon.exe','');
QuarantineFile('c:\users\dima\appdata\roaming\setupsk\python\pythonw.exe','');
DeleteFile('C:\PROGRA~3\354eda3f\5f63ef50.dll','32');
DeleteFile('C:\Program Files (x86)\GXZiGyYLSHyU2\Iwr5Ze3.dll','32');
DeleteFile('C:\Program Files (x86)\thzXuJvjU\3nwXG8v.dll','32');
DeleteFile('C:\Program Files\Uninstall Information\58TOP8UAN8LCYTIX4S78DO1M8E\iXQkh+66xP.exe','32');
DeleteFile('C:\Program Files\f63471cf44408e192b1d12a41df7a59f\31781279c3642074ab68378f9a0b4c34.exe','32');
DeleteFile('C:\Users\Dima\AppData\Local\SearchGo\searchgo.exe','32');
DeleteFile('C:\Users\Dima\AppData\Local\wupdate\wupdate.exe','32');
DeleteFile('C:\Users\Dima\AppData\Roaming\SETUPS~1\ml.py','32');
DeleteFile('C:\Users\Dima\AppData\Roaming\SETUPS~1\python\pythonw.exe','32');
DeleteFile('C:\Users\Dima\AppData\Roaming\setupsk\ml.py','32');
DeleteFile('C:\Users\Dima\AppData\Roaming\setupsk\python\DLLs\_ctypes.pyd','32');
DeleteFile('C:\Users\Dima\AppData\Roaming\setupsk\python\python34.dll','32');
DeleteFile('C:\Users\Dima\AppData\Roaming\setupsk\python\pythonw.exe','32');
DeleteFile('C:\Users\Dima\appdata\roaming\sysmon\sysmon.exe','32');
ExecuteFile('schtasks.exe', '/delete /TN "FastDataX Task" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SearchGo Task" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "TnqpiRJoXWMCwN" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "hdtask" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "uuxHwpnMkRCRpJh2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "wupdate" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{7D0E7F47-0F09-7E0C-0811-080505781109}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{A784F548-102F-42E3-8F48-44EE0EDAE233}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{C2A530B4-499D-52C1-242F-83204E42F658}" /F', 0, 15000, true);
DeleteFile('c:\users\dima\appdata\roaming\setupsk\python\pythonw.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','iXQkh+66xP.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','setupsk');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','setupsk_upd');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
После выполнения скрипта компьютер перезагрузится.