Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe','');
DelBHO('{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}');
QuarantineFile('C:\Program Files (x86)\XTab\SupTab.dll','');
QuarantineFile('C:\iexplore.bat','');
QuarantineFile('C:\Users\Probityy\AppData\Local\Kometa\kometaup.exe','');
QuarantineFile('C:\Program Files (x86)\punto.bat','');
QuarantineFile('C:\Program Files (x86)\gmsd_re_253\gmsd_re_253.exe','');
QuarantineFile('C:\Program Files (x86)\Google\chrome.bat','');
DeleteService('kxescore');
SetServiceStart('Util Edu App', 4);
DeleteService('Util Edu App');
SetServiceStart('Update Edu App', 4);
DeleteService('Update Edu App');
SetServiceStart('rewisezu', 4);
DeleteService('rewisezu');
SetServiceStart('pekudyho', 4);
DeleteService('pekudyho');
SetServiceStart('jitijyve', 4);
DeleteService('jitijyve');
SetServiceStart('IHProtect Service', 4);
DeleteService('IHProtect Service');
QuarantineFile('C:\Windows\system32\drivers\{848705a5-8a27-403e-9b59-732d0608bcbc}Gw64.sys','');
QuarantineFile('C:\Program Files (x86)\XTab\IeWatchDog.dll','');
QuarantineFile('C:\Program Files (x86)\Edu App\bin\EduApp.expextdll.dll','');
TerminateProcessByName('c:\program files (x86)\edu app\bin\utileduapp.exe');
QuarantineFile('c:\program files (x86)\edu app\bin\utileduapp.exe','');
TerminateProcessByName('c:\program files (x86)\edu app\updateeduapp.exe');
QuarantineFile('c:\program files (x86)\edu app\updateeduapp.exe','');
TerminateProcessByName('c:\program files (x86)\xtab\protectservice.exe');
QuarantineFile('c:\program files (x86)\xtab\protectservice.exe','');
TerminateProcessByName('c:\users\probityy\appdata\roaming\dbeaaec8-1432665278-7d4c-9db3-60eb69f9763a\nsf6428.tmpfs');
QuarantineFile('c:\users\probityy\appdata\roaming\dbeaaec8-1432665278-7d4c-9db3-60eb69f9763a\nsf6428.tmpfs','');
TerminateProcessByName('c:\users\probityy\appdata\roaming\dbeaaec8-1432665278-7d4c-9db3-60eb69f9763a\jnsl9166.tmp');
QuarantineFile('c:\users\probityy\appdata\roaming\dbeaaec8-1432665278-7d4c-9db3-60eb69f9763a\jnsl9166.tmp','');
TerminateProcessByName('c:\program files (x86)\xtab\hpnotify.exe');
QuarantineFile('c:\program files (x86)\xtab\hpnotify.exe','');
TerminateProcessByName('c:\users\probityy\appdata\roaming\dbeaaec8-1432665278-7d4c-9db3-60eb69f9763a\hnsqa8af.tmp');
QuarantineFile('c:\users\probityy\appdata\roaming\dbeaaec8-1432665278-7d4c-9db3-60eb69f9763a\hnsqa8af.tmp','');
TerminateProcessByName('C:\Program Files (x86)\Edu App\bin\EduApp.PurBrowse64.exe');
QuarantineFile('C:\Program Files (x86)\Edu App\bin\EduApp.PurBrowse64.exe','');
TerminateProcessByName('c:\program files (x86)\edu app\bin\eduapp.expext.exe');
QuarantineFile('c:\program files (x86)\edu app\bin\eduapp.expext.exe','');
TerminateProcessByName('c:\program files (x86)\xtab\cmdshell.exe');
TerminateProcessByName('c:\program files (x86)\crossbrowse\crossbrowse\application\crossbrowse.exe');
QuarantineFile('c:\program files (x86)\crossbrowse\crossbrowse\application\crossbrowse.exe','');
QuarantineFile('c:\program files (x86)\xtab\cmdshell.exe','');
DeleteFile('c:\program files (x86)\xtab\cmdshell.exe','32');
DeleteFile('c:\program files (x86)\crossbrowse\crossbrowse\application\crossbrowse.exe','32');
DeleteFile('c:\program files (x86)\edu app\bin\eduapp.expext.exe','32');
DeleteFile('C:\Program Files (x86)\Edu App\bin\EduApp.PurBrowse64.exe','32');
DeleteFile('c:\users\probityy\appdata\roaming\dbeaaec8-1432665278-7d4c-9db3-60eb69f9763a\hnsqa8af.tmp','32');
DeleteFile('c:\program files (x86)\xtab\hpnotify.exe','32');
DeleteFile('c:\users\probityy\appdata\roaming\dbeaaec8-1432665278-7d4c-9db3-60eb69f9763a\jnsl9166.tmp','32');
DeleteFile('c:\users\probityy\appdata\roaming\dbeaaec8-1432665278-7d4c-9db3-60eb69f9763a\nsf6428.tmpfs','32');
DeleteFile('c:\program files (x86)\xtab\protectservice.exe','32');
DeleteFile('c:\program files (x86)\edu app\updateeduapp.exe','32');
DeleteFile('c:\program files (x86)\edu app\bin\utileduapp.exe','32');
DeleteFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\39.6.2171.95\chrome.dll','32');
DeleteFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\39.6.2171.95\chrome_child.dll','32');
DeleteFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\39.6.2171.95\chrome_elf.dll','32');
DeleteFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\39.6.2171.95\libegl.dll','32');
DeleteFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\39.6.2171.95\libglesv2.dll','32');
DeleteFile('C:\Program Files (x86)\Edu App\bin\EduApp.expextdll.dll','32');
DeleteFile('C:\Program Files (x86)\XTab\IeWatchDog.dll','32');
DeleteFile('C:\Windows\system32\drivers\{848705a5-8a27-403e-9b59-732d0608bcbc}Gw64.sys','32');
DeleteFile('c:\program files (x86)\kingsoft\kingsoft antivirus\kxescore.exe','32');
DeleteFile('C:\Program Files (x86)\Google\chrome.bat','32');
DeleteFile('C:\Program Files (x86)\gmsd_re_253\gmsd_re_253.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gmsd_re_253');
DeleteFile('C:\Program Files (x86)\punto.bat','32');
DeleteFile('C:\Users\Probityy\AppData\Local\Kometa\kometaup.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','kometaup');
DeleteFile('C:\iexplore.bat','32');
DeleteFile('C:\Program Files (x86)\XTab\SupTab.dll','32');
DeleteFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe','32');
DeleteFile('C:\Windows\Tasks\Crossbrowse.job','64');
DeleteFile('C:\Windows\system32\Tasks\Crossbrowse','64');
DeleteFile('C:\Users\Probityy\AppData\Local\Temp\nsgDCD9.tmp\blowfish.dll','32');
DeleteFile('C:\Users\Probityy\AppData\Local\Temp\nsyB3E5.tmp\blowfish.dll','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Компьютер перезагрузится.