begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla\epstmzb.exe', '');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\GWMRO9Af79dxSAl97rTG.exe', '');
QuarantineFile('C:\DOCUME~1\Admin\APPLIC~1\UPDATE~1\UPDATE~1\UPDATE~1.EXE', '');
QuarantineFile('C:\Program Files\PlusHD_1.02mV09.08\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-5.exe', '');
QuarantineFile('C:\Program Files\PlusHD_1.02mV09.08\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-4.exe', '');
QuarantineFile('C:\Program Files\PlusHD_1.02mV09.08\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-11.exe', '');
QuarantineFile('C:\Program Files\PlusHD_1.02mV09.08\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-10.exe', '');
QuarantineFile('C:\Program Files\PlusHD_1.02mV09.08\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-1-7.exe', '');
QuarantineFile('C:\Program Files\PlusHD_1.02mV09.08\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-1-6.exe', '');
QuarantineFileF('C:\Documents and Settings\Admin\Local Settings\Application Data\SmartWeb', '*', true, '', 0 , 0);
QuarantineFile('C:\Documents and Settings\Admin\Local Settings\Application Data\SmartWeb\SmartWebHelper.exe', '');
QuarantineFile('C:\WINDOWS\system32\drivers\wsafd_1_10_0_19.sys', '');
QuarantineFile('C:\WINDOWS\system32\drivers\ppfd_vt_1_10_0_22.sys', '');
QuarantineFileF('C:\Program Files\PlusHD_1.02mV09.08', '*', true, '', 0 , 0);
QuarantineFile('C:\Documents and Settings\Admin\Local Settings\Application Data\Kometa\Application\kometa.bat', '');
QuarantineFile('C:\Program Files\Yandex\Punto Switcher\punto.bat', '');
QuarantineFile('C:\Program Files\Internet Explorer\IEXPLORE.bat', '');
QuarantineFile('C:\Documents and Settings\Admin\Избранное\Панель закладок\Слава\http csmg.lgmobile.com 9002 csmg b2c client auth_model_check2.js', '');
QuarantineFile('C:\WINDOWS\TEMP\8a22018d-e32f-4dac-823f-18ec0d91dc86\AgileDotNetRT.dll', '');
QuarantineFile('C:\WINDOWS\TEMP\9e8ef525-6395-44e7-ad8b-f1f79dbf42d9\AgileDotNetRT.dll', '');
QuarantineFile('C:\Documents and Settings\All Users\App', '');
DeleteFile('C:\WINDOWS\system32\drivers\ppfd_vt_1_10_0_22.sys', '32');
DeleteFile('C:\WINDOWS\system32\drivers\wsafd_1_10_0_19.sys', '32');
DeleteFile('C:\Documents and Settings\Admin\Local Settings\Application Data\SmartWeb\SmartWebHelper.exe', '32');
DeleteFile('C:\Program Files\PlusHD_1.02mV09.08\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-1-6.exe', '32');
DeleteFile('C:\WINDOWS\Tasks\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-1-6.job', '32');
DeleteFile('C:\Program Files\PlusHD_1.02mV09.08\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-1-7.exe', '32');
DeleteFile('C:\WINDOWS\Tasks\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-1-7.job', '32');
DeleteFile('C:\WINDOWS\Tasks\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-10_user.job', '32');
DeleteFile('C:\Program Files\PlusHD_1.02mV09.08\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-10.exe', '32');
DeleteFile('C:\Program Files\PlusHD_1.02mV09.08\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-11.exe', '32');
DeleteFile('C:\WINDOWS\Tasks\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-11.job', '32');
DeleteFile('C:\WINDOWS\Tasks\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-4.job', '32');
DeleteFile('C:\Program Files\PlusHD_1.02mV09.08\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-4.exe', '32');
DeleteFile('C:\Program Files\PlusHD_1.02mV09.08\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-5.exe', '32');
DeleteFile('C:\WINDOWS\Tasks\59acf12a-3c64-4be8-ad9c-16dd07bba4c4-5.job', '32');
DeleteFile('C:\WINDOWS\Tasks\At1.job', '32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\GWMRO9Af79dxSAl97rTG.exe', '32');
DeleteFile('C:\WINDOWS\Tasks\GWMRO9Af79dxSAl97rTG.job', '32');
DeleteFile('C:\WINDOWS\Tasks\lzrnpqb.job', '32');
DeleteFile('C:\Documents and Settings\Admin\Local Settings\Application Data\Kometa\Application\kometa.bat', '');
DeleteFile('C:\Program Files\Yandex\Punto Switcher\punto.bat', '');
DeleteFile('C:\Program Files\Internet Explorer\IEXPLORE.bat', '');
DeleteFile('C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla\epstmzb.exe', '32');
DeleteFile('C:\WINDOWS\TEMP\8a22018d-e32f-4dac-823f-18ec0d91dc86\AgileDotNetRT.dll');
DeleteFile('C:\WINDOWS\TEMP\9e8ef525-6395-44e7-ad8b-f1f79dbf42d9\AgileDotNetRT.dll');
DeleteFile('C:\Documents and Settings\All Users\App');
DeleteFileMask('C:\Documents and Settings\Admin\Local Settings\Application Data\SmartWeb', '*', true);
DeleteFileMask('C:\Program Files\PlusHD_1.02mV09.08', '*', true);
DeleteDirectory('C:\Documents and Settings\Admin\Local Settings\Application Data\SmartWeb', '');
DeleteDirectory('C:\Program Files\PlusHD_1.02mV09.08', '');
DelBHO('{0633EE93-D776-472f-A0FF-E1416B8B2E3D}');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\Eventlog\Application\WdsManPro', 'EventMessageFile');
BC_ImportALL;
ExecuteSysClean;
ExecuteRepair(2);
ExecuteWizard('SCU', 2, 3, true);
BC_Activate;
RebootWindows(true);
end.