Код:
procedure DeleteDirectoryF(N: String);
begin
DeleteFileMask(N, '*', true);
DeleteDirectory(N);
end;
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\125\AppData\Local\18401\Updater.exe','');
QuarantineFile('C:\Users\Home\AppData\Local\PirritSuggestor\PirritService.exe','');
DeleteService('PirritDesktop');
QuarantineFile('C:\Windows\system32\nethtsrv.exe','');
DeleteService('NetHttpService');
QuarantineFile('C:\Users\125\AppData\Local\dosmshtmlx64\dosmshtmlx64.exe','');
QuarantineFile('C:\Users\Home\AppData\Local\EncondingRecycleUtility\EncondingRecycleUtility.exe','');
DeleteService('EncondingRecycleUtility.exe');
DeleteService('dosmshtmlx64.exe');
QuarantineFile('C:\Users\125\AppData\Local\DefaultDesktopText\DefaultDesktopText.exe','');
QuarantineFile('C:\Users\Home\AppData\Local\DLCInterpreterOS\DLCInterpreterOS.exe','');
QuarantineFile('C:\Users\125\AppData\Local\dosjreBckp\dosjreBckp.exe','');
DeleteService('dosjreBckp.exe');
DeleteService('DLCInterpreterOS.exe');
DeleteService('DefaultDesktopText.exe');
QuarantineFile('C:\Users\125\AppData\Local\CursorDebuggerWinsock\CursorDebuggerWinsock.exe','');
QuarantineFile('C:\Users\125\AppData\Local\CursorFrozenPath\CursorFrozenPath.exe','');
QuarantineFile('C:\Users\125\AppData\Local\dashboardbitsigd32\dashboardbitsigd32.exe','');
DeleteService('dashboardbitsigd32.exe');
DeleteService('CursorFrozenPath.exe');
DeleteService('CursorDebuggerWinsock.exe');
DeleteService('clipboardshdocvwx64.exe');
QuarantineFile('C:\Users\125\AppData\Local\clipboardshdocvwx64\clipboardshdocvwx64.exe','');
QuarantineFile('C:\Users\Home\AppData\Local\72035941a6ebb79f1d4a371d2aff36cc\c39c34460393163.exe','');
QuarantineFile('C:\Users\125\AppData\Local\ClassCompileSprite\ClassCompileSprite.exe','');
QuarantineFile('C:\Users\Home\AppData\Local\ClassKernelSchema\ClassKernelSchema.exe','');
DeleteService('ClassKernelSchema.exe');
DeleteService('ClassCompileSprite.exe');
DeleteService('c39c34460393163.exe');
QuarantineFile('C:\Users\Home\AppData\Local\APIFormatRepository\APIFormatRepository.exe','');
DeleteService('APIFormatRepository.exe');
DeleteService('AddonCronSDK.exe');
QuarantineFile('C:\Users\125\AppData\Local\AddonCronSDK\AddonCronSDK.exe','');
QuarantineFile('C:\Users\125\AppData\Local\AddonClassMacro\AddonClassMacro.exe','');
DeleteService('AddonClassMacro.exe');
SetServiceStart('8d45255d93937ba.exe', 4);
DeleteService('8d45255d93937ba.exe');
SetServiceStart('winsockwysiwygRec.exe', 4);
DeleteService('winsockwysiwygRec.exe');
SetServiceStart('wauctla Service', 4);
DeleteService('wauctla Service');
SetServiceStart('ServiceUpdater', 4);
DeleteService('ServiceUpdater');
SetServiceStart('interpretertooltipapi', 4);
DeleteService('interpretertooltipapi');
TerminateProcessByName('c:\users\125\appdata\local\winsockwysiwygrec\winsockwysiwygrec.exe');
QuarantineFile('c:\users\125\appdata\local\winsockwysiwygrec\winsockwysiwygrec.exe','');
TerminateProcessByName('c:\windows\wauctla.exe');
QuarantineFile('c:\windows\wauctla.exe','');
TerminateProcessByName('c:\windows\system32\netupdsrv.exe');
QuarantineFile('c:\windows\system32\netupdsrv.exe','');
TerminateProcessByName('c:\windows\system32\interpretertooltipapi\interpretertooltipapi.exe');
QuarantineFile('c:\windows\system32\interpretertooltipapi\interpretertooltipapi.exe','');
TerminateProcessByName('c:\program files\edealpop\edealpop.exe');
QuarantineFile('c:\program files\edealpop\edealpop.exe','');
TerminateProcessByName('c:\users\125\appdata\local\winsockwysiwygrec\dosprocessprot.exe');
QuarantineFile('c:\users\125\appdata\local\winsockwysiwygrec\dosprocessprot.exe','');
DeleteFile('c:\users\125\appdata\local\winsockwysiwygrec\dosprocessprot.exe','32');
DeleteFile('c:\program files\edealpop\edealpop.exe','32');
DeleteFile('c:\windows\system32\interpretertooltipapi\interpretertooltipapi.exe','32');
DeleteFile('c:\windows\system32\netupdsrv.exe','32');
DeleteFile('c:\users\125\appdata\local\winsockwysiwygrec\winsockwysiwygrec.exe','32');
DeleteFile('C:\Users\125\AppData\Local\AddonClassMacro\AddonClassMacro.exe','32');
DeleteFile('C:\Users\125\AppData\Local\AddonCronSDK\AddonCronSDK.exe','32');
DeleteFile('C:\Users\Home\AppData\Local\APIFormatRepository\APIFormatRepository.exe','32');
DeleteFile('C:\Users\Home\AppData\Local\ClassKernelSchema\ClassKernelSchema.exe','32');
DeleteFile('C:\Users\125\AppData\Local\ClassCompileSprite\ClassCompileSprite.exe','32');
DeleteFile('C:\Users\Home\AppData\Local\72035941a6ebb79f1d4a371d2aff36cc\c39c34460393163.exe','32');
DeleteFile('C:\Users\125\AppData\Local\clipboardshdocvwx64\clipboardshdocvwx64.exe','32');
DeleteFile('C:\Users\125\AppData\Local\dashboardbitsigd32\dashboardbitsigd32.exe','32');
DeleteFile('C:\Users\125\AppData\Local\CursorFrozenPath\CursorFrozenPath.exe','32');
DeleteFile('C:\Users\125\AppData\Local\CursorDebuggerWinsock\CursorDebuggerWinsock.exe','32');
DeleteFile('C:\Users\125\AppData\Local\dosjreBckp\dosjreBckp.exe','32');
DeleteFile('C:\Users\Home\AppData\Local\DLCInterpreterOS\DLCInterpreterOS.exe','32');
DeleteFile('C:\Users\125\AppData\Local\DefaultDesktopText\DefaultDesktopText.exe','32');
DeleteFile('C:\Users\Home\AppData\Local\EncondingRecycleUtility\EncondingRecycleUtility.exe','32');
DeleteFile('C:\Users\125\AppData\Local\dosmshtmlx64\dosmshtmlx64.exe','32');
DeleteFile('C:\Windows\system32\nethtsrv.exe','32');
DeleteFile('C:\Users\Home\AppData\Local\PirritSuggestor\PirritService.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','eDealPop');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','eDealsPop');
DeleteFile('C:\Users\125\AppData\Local\18401\Updater.exe','32');
DeleteFile('C:\Windows\system32\Tasks\AmiUpdXp','32');
DeleteFile('C:\Windows\Tasks\AmiUpdXp.job','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Компьютер перезагрузится.