Код:
begin
ExecuteAVUpdate;
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
DelBHO('{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}');
DelBHO('{FFCB3198-32F3-4E8B-9539-4324694ED664}');
TerminateProcessByName('C:\Program Files\COMODO\{134-9e-9e-7f417-9b655-ead8-ce029}\9lodmgx&OF.exe');
TerminateProcessByName('c:\programdata\logic cramble\set.exe');
TerminateProcessByName('c:\programdata\zaamla\zaamla.exe');
StopService('backlh');
StopService('surfshieldsrv');
DeleteService('backlh');
DeleteService('surfshieldsrv');
DeleteService('wfpgameprotect');
QuarantineFile('C:\PROGRA~2\IObit\ADVANC~1\SURFIN~1\BROWER~1\ASCPLU~1.DLL','');
QuarantineFile('C:\Program Files (x86)\AIMP\AIMP.exe','');
QuarantineFile('C:\Program Files (x86)\Anujither Monitor\local64spl.dll','');
QuarantineFile('C:\Program Files (x86)\Bihulegroqecult\xqcik.exe','');
QuarantineFile('C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\Adblock\Adblock.dll','');
QuarantineFile('C:\Program Files (x86)\VK OK AdBlockU\tDJhOPL.dll','');
QuarantineFile('C:\Program Files\COMODO\{134-9e-9e-7f417-9b655-ead8-ce029}\9lodmgx&OF.exe','');
QuarantineFile('C:\Program Files\Common Files\Noobzo\GNUpdate\smu.exe','');
QuarantineFile('C:\ProgramData\359E164E947q933\359E164E947q933.dll','');
QuarantineFile('C:\ProgramData\Logic Cramble\set.exe','');
QuarantineFile('C:\ProgramData\RegisterObject\RegisterObject.exe','');
QuarantineFile('C:\ProgramData\SearchModule\smhe.js','');
QuarantineFile('C:\ProgramData\Zaamla\Is-Lux.dll','');
QuarantineFile('C:\ProgramData\Zaamla\Lahold.dll','');
QuarantineFile('C:\Users\Полина\AppData\Local\Temp\toolbar.exe','');
QuarantineFile('C:\Users\Полина\AppData\Local\sysasf.dll','');
QuarantineFile('C:\Users\Полина\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet-Explorer Browser.lnk','');
QuarantineFile('C:\Users\Полина\AppData\Roaming\Vofer2\IQmanager\app.py','');
QuarantineFile('C:\Users\Полина\AppData\Roaming\Vofer2\IQmanager\ml.py','');
QuarantineFile('C:\Users\Полина\AppData\Roaming\Vofer2\ml.py','');
QuarantineFile('C:\Users\Полина\AppData\Roaming\Vofer2\updater.py','');
QuarantineFile('C:\Users\4880~1\AppData\Local\Temp\843E.tmp.sys','');
QuarantineFile('C:\Users\4880~1\AppData\Local\Temp\AppHelper_v3.exe','');
QuarantineFile('C:\Users\4880~1\AppData\Local\Temp\accelerator.exe','');
QuarantineFile('C:\Windows\SysWOW64\SurfShield.exe','');
QuarantineFile('C:\Windows\system32\drivers\flowhlp.dat','');
QuarantineFile('C:\Windows\system32\drivers\kisknl.sys','');
QuarantineFile('C:\Windows\system32\drivers\ksapi64.sys','');
QuarantineFile('c:\programdata\logic cramble\set.exe','');
QuarantineFile('c:\programdata\zaamla\zaamla.exe','');
QuarantineFile('c:\users\полина\appdata\local\sysasf.dll','');
DeleteFile('C:\PROGRA~2\IObit\ADVANC~1\SURFIN~1\BROWER~1\ASCPLU~1.DLL','32');
DeleteFile('C:\Program Files (x86)\AIMP\AIMP.exe','32');
DeleteFile('C:\Program Files (x86)\Anujither Monitor\local64spl.dll','32');
DeleteFile('C:\Program Files (x86)\Bihulegroqecult\xqcik.exe','32');
DeleteFile('C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\Adblock\AdBExtFc.dll','32');
DeleteFile('C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\Adblock\Adblock.dll','32');
DeleteFile('C:\Program Files (x86)\VK OK AdBlockU\tDJhOPL.dll','32');
DeleteFile('C:\Program Files\COMODO\{134-9e-9e-7f417-9b655-ead8-ce029}\9lodmgx&OF.exe','32');
DeleteFile('C:\ProgramData\359E164E947q933\359E164E947q933.dll','32');
DeleteFile('C:\ProgramData\Logic Cramble\set.exe','32');
DeleteFile('C:\ProgramData\RegisterObject\RegisterObject.exe','32');
DeleteFile('C:\ProgramData\SearchModule\smhe.js','32');
DeleteFile('C:\ProgramData\Zaamla\Is-Lux.dll','32');
DeleteFile('C:\ProgramData\Zaamla\Lahold.dll','32');
DeleteFile('C:\Users\Полина\AppData\Local\Temp\toolbar.exe','32');
DeleteFile('C:\Users\Полина\AppData\Local\sysasf.dll','32');
DeleteFile('C:\Users\Полина\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet-Explorer Browser.lnk','32');
DeleteFile('C:\Users\Полина\AppData\Roaming\Vofer2\IQmanager\app.py','32');
DeleteFile('C:\Users\Полина\AppData\Roaming\Vofer2\IQmanager\ml.py','32');
DeleteFile('C:\Users\Полина\AppData\Roaming\Vofer2\ml.py','32');
DeleteFile('C:\Users\Полина\AppData\Roaming\Vofer2\updater.py','32');
DeleteFile('C:\Users\4880~1\AppData\Local\Temp\843E.tmp.sys','32');
DeleteFile('C:\Users\4880~1\AppData\Local\Temp\AppHelper_v3.exe','32');
DeleteFile('C:\Users\4880~1\AppData\Local\Temp\accelerator.exe','32');
DeleteFile('C:\Windows\SysWOW64\SurfShield.exe','32');
DeleteFile('C:\Windows\Tasks\Update Service for VK OK AdBlock.job','32');
DeleteFile('C:\Windows\Tasks\Update Service for VK OK AdBlock2.job','32');
ExecuteFile('schtasks.exe', '/delete /TN "359E164E947q933" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Anujither Monitor" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "IQmanager" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "IQmanager2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Media Center\RegisterObject" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SMW_UpdateTask_Time_313731363737313138372d45372a5a506c41324a345741" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Update Service for VK OK AdBlock" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Update Service for VK OK AdBlock2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Vofer2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Vofer22" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "urlopener" /F', 0, 15000, true);
DeleteFile('c:\programdata\logic cramble\set.exe','32');
DeleteFile('c:\programdata\zaamla\zaamla.exe','32');
DeleteFile('c:\users\полина\appdata\local\sysasf.dll','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','IQmanager');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','SystemScript');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Vofer2');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','sysasf');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
После выполнения скрипта компьютер перезагрузится.