Код:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=50c460bfd0354789f0829df26ef101d4&text={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=50c460bfd0354789f0829df26ef101d4&text={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?o=APN11459&gct=hp&d=488-101&v=a12834-383&t=4
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=50c460bfd0354789f0829df26ef101d4&text=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=50c460bfd0354789f0829df26ef101d4&text=
R3 - URLSearchHook: (no name) - {0633EE93-D776-472f-A0FF-E1416B8B2E3D} - (no file)
O13 - DefaultPrefix: http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=50c460bfd0354789f0829df26ef101d4&text=
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - (no file)
Запускайте AVZ правой кнопкой мыши - "Запуск от имени Администратора".
Код:
begin
ClearQuarantine;
TerminateProcessByName('c:\program files (x86)\browser tab search by ask\safetynut\safetynutmanager.exe');
QuarantineFile('C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe','');
QuarantineFile('C:\Program Files (x86)\PlusHD-V1.9\PlusHD-V1.9-nova.exe','');
QuarantineFile('C:\Program Files (x86)\PlusHD-V1.9\PlusHD-V1.9-novainstaller.exe','');
QuarantineFile('C:\Program Files (x86)\PlusHD-V1.9\e29193b0-b61f-4d86-ada8-6277dd849368-5.exe','');
QuarantineFile('C:\Program Files (x86)\PlusHD-V1.9\e29193b0-b61f-4d86-ada8-6277dd849368-4.exe','');
QuarantineFile('C:\Program Files (x86)\PlusHD-V1.9\e29193b0-b61f-4d86-ada8-6277dd849368-3.exe','');
QuarantineFile('C:\Program Files (x86)\PlusHD-V1.9\e29193b0-b61f-4d86-ada8-6277dd849368-2.exe','');
QuarantineFile('C:\Program Files (x86)\PlusHD-V1.9\e29193b0-b61f-4d86-ada8-6277dd849368-11.exe','');
QuarantineFile('C:\Program Files (x86)\PlusHD-V1.9\PlusHD-V1.9-codedownloader.exe','');
QuarantineFile('C:\Program Files (x86)\PlusHD-V1.9\PlusHD-V1.9-bho.dll','');
QuarantineFile('C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\x64\safetycrt.dll','');
QuarantineFile('C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\safetycrt.dll','');
QuarantineFile('C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\SafetyNutManager.exe','');
QuarantineFile('C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\x64\configmgrc1.cfg','');
QuarantineFile('c:\program files (x86)\browser tab search by ask\safetynut\safetynutmanager.exe','');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
DeleteFile('c:\program files (x86)\browser tab search by ask\safetynut\safetynutmanager.exe','32');
DeleteFile('C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\x64\configmgrc1.cfg','32');
DeleteFile('C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\SafetyNutManager.exe','32');
DeleteFile('C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\safetycrt.dll','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','System\CurrentControlSet\Control\Session Manager\AppCertDlls','x86');
DeleteFile('C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\x64\safetycrt.dll','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','System\CurrentControlSet\Control\Session Manager\AppCertDlls','x64');
DeleteFile('C:\Program Files (x86)\PlusHD-V1.9\PlusHD-V1.9-bho.dll','32');
DeleteFile('C:\Program Files (x86)\PlusHD-V1.9\PlusHD-V1.9-codedownloader.exe','32');
DeleteFile('C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-1.job','64');
DeleteFile('C:\Program Files (x86)\PlusHD-V1.9\e29193b0-b61f-4d86-ada8-6277dd849368-11.exe','32');
DeleteFile('C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-11.job','64');
DeleteFile('C:\Program Files (x86)\PlusHD-V1.9\e29193b0-b61f-4d86-ada8-6277dd849368-2.exe','32');
DeleteFile('C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-2.job','64');
DeleteFile('C:\Program Files (x86)\PlusHD-V1.9\e29193b0-b61f-4d86-ada8-6277dd849368-3.exe','32');
DeleteFile('C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-3.job','64');
DeleteFile('C:\Program Files (x86)\PlusHD-V1.9\e29193b0-b61f-4d86-ada8-6277dd849368-4.exe','32');
DeleteFile('C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-4.job','64');
DeleteFile('C:\Program Files (x86)\PlusHD-V1.9\e29193b0-b61f-4d86-ada8-6277dd849368-5.exe','32');
DeleteFile('C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-5.job','64');
DeleteFile('C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-5_user.job','64');
DeleteFile('C:\Program Files (x86)\PlusHD-V1.9\PlusHD-V1.9-novainstaller.exe','32');
DeleteFile('C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-6.job','64');
DeleteFile('C:\Program Files (x86)\PlusHD-V1.9\PlusHD-V1.9-nova.exe','32');
DeleteFile('C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-7.job','64');
DeleteFile('C:\Windows\system32\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-1','64');
DeleteFile('C:\Windows\system32\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-11','64');
DeleteFile('C:\Windows\system32\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-2','64');
DeleteFile('C:\Windows\system32\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-3','64');
DeleteFile('C:\Windows\system32\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-4','64');
DeleteFile('C:\Windows\system32\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-5','64');
DeleteFile('C:\Windows\system32\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-6','64');
DeleteFile('C:\Windows\system32\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-7','64');
DelBHO('{11111111-1111-1111-1111-110511951170}');
StopService('F06DEFF2-5B9C-490D-910F-35D3A91196222');
StopService('SafetyNutManager');
SetServiceStart('F06DEFF2-5B9C-490D-910F-35D3A91196222', 4);
DeleteService('F06DEFF2-5B9C-490D-910F-35D3A91196222');
DeleteService('SafetyNutManager');
ExecuteSysClean;
ExecuteWizard('TSW',2,2,true);
RebootWindows(true);
end.
Компьютер перезагрузится.