Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Windows\c1.exe','');
QuarantineFile('C:\Users\1\AppData\Local\SwvUpdater\Updater.exe','');
QuarantineFile('c:\progra~3\browse~1\261125~1.80\{16cdf~1\browse~1.dll','');
QuarantineFile('C:\Windows\system32\drivers\esarwbrh.sys','');
QuarantineFile('C:\Windows\system32\drivers\evvjhclk.sys','');
QuarantineFile('C:\Windows\system32\drivers\gvzlvwap.sys','');
QuarantineFile('C:\Windows\system32\drivers\kvpeuosa.sys','');
QuarantineFile('C:\Windows\system32\drivers\kzquqqvl.sys','');
DeleteService('kzquqqvl');
DeleteService('kvpeuosa');
DeleteService('iSafeKrnlBoot');
DeleteService('gvzlvwap');
DeleteService('evvjhclk');
DeleteService('esarwbrh');
SetServiceStart('iSafeNetFilter', 4);
DeleteService('iSafeNetFilter');
SetServiceStart('iSafeKrnlR3', 4);
DeleteService('iSafeKrnlR3');
SetServiceStart('iSafeKrnlMon', 4);
DeleteService('iSafeKrnlMon');
SetServiceStart('iSafeKrnlKit', 4);
DeleteService('iSafeKrnlKit');
SetServiceStart('iSafeKrnl', 4);
DeleteService('iSafeKrnl');
DeleteService('Browser Manager');
QuarantineFile('C:\ProgramData\Browser Manager\2.6.1125.80\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe','');
DeleteService('iSafeService');
TerminateProcessByName('c:\program files (x86)\elex-tech\yac\isafetray.exe');
TerminateProcessByName('c:\program files (x86)\elex-tech\yac\isafesvc2.exe');
TerminateProcessByName('c:\program files (x86)\elex-tech\yac\isafesvc.exe');
DeleteFile('c:\program files (x86)\elex-tech\yac\isafesvc.exe','32');
DeleteFile('c:\program files (x86)\elex-tech\yac\isafesvc2.exe','32');
DeleteFile('c:\program files (x86)\elex-tech\yac\isafetray.exe','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iCommon.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iCommu.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iImportLib.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\ipcproxy.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeAdless.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafebs.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeCheckEngine.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafechlp.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeDisp.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeEngineBase.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlCall.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMonCall.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafemc.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeMon.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafenpf.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafepxy.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isaferpt.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafesopt.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\isafeupbiz.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSvc.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSvc2.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPDesk.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPFloaty.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPMsgCenter.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPNodisturb.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPProtect.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPPush.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPStartupAssist.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iTPVirus.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\libcurl.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\LIBEAY32.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\libpng.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\ouilibx.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\sqlite3.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\SSLEAY32.dll','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\iSafeNetFilter.sys','32');
DeleteFile('C:\ProgramData\Browser Manager\2.6.1125.80\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe','32');
DeleteFile('C:\Windows\system32\drivers\kzquqqvl.sys','32');
DeleteFile('C:\Windows\system32\drivers\kvpeuosa.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\iSafeKrnlBoot.sys','32');
DeleteFile('C:\Windows\system32\drivers\gvzlvwap.sys','32');
DeleteFile('C:\Windows\system32\drivers\evvjhclk.sys','32');
DeleteFile('C:\Windows\system32\drivers\esarwbrh.sys','32');
DeleteFile('C:\Users\1\AppData\Local\Amigo\Application\amigo.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','amigo');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\amigo','command');
DeleteFile('C:\Users\1\AppData\Local\Amigo\Application\ok.exe','32');
DeleteFile('C:\Users\1\AppData\Local\Amigo\Application\vk.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Adobe Flash Player SU');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','C:\Windows\SysWOW64\V0520Ext.ax');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','C:\Windows\system32\V0520Ext.ax');
DeleteFile('c:\progra~3\browse~1\261125~1.80\{16cdf~1\browse~1.dll','32');
DeleteFile('C:\Users\1\AppData\Local\SwvUpdater\Updater.exe','32');
DeleteFile('C:\Windows\Tasks\At1.job','64');
DeleteFile('C:\Windows\Tasks\AmiUpdXp.job','64');
DeleteFile('C:\Windows\system32\Tasks\AmiUpdXp','64');
DeleteFile('C:\Windows\c1.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Компьютер перезагрузится.