begin
ShowMessage('Внимание!Скрипт так же удалит mail.ru,winzipper,браузер амиго');
TerminateProcessByName('c:\program files\winzipper\winzipersvc.exe');
TerminateProcessByName('c:\documents and settings\Егор\local settings\application data\mail.ru\mailruupdater.exe');
SetServiceStart('F06DEFF2-5B9C-490D-910F-35D3A9119622', 4);
SetServiceStart('winzipersvc', 4);
StopService('F06DEFF2-5B9C-490D-910F-35D3A9119622');
StopService('winzipersvc');
QuarantineFile('C:\Program Files\suptab\loader64.exe', '');
QuarantineFile('C:\Program Files\browser tab search by ask\safetynut\safetynut.exe', '');
QuarantineFile('C:\Program Files\browser tab search by ask\safetynut\safetycrt.dll', '');
QuarantineFile('C:\Documents and Settings\Егор\applic~1\update~1\update~1\update~1.exe', '');
QuarantineFile('C:\DOCUME~1\9DEC~1\APPLIC~1\UPDATE~1\UPDATE~1\UPDATE~1.EXE', '');
QuarantineFile('c:\program files\browser tab search by ask\safetynut\x64\safetycrt.dll', '');
QuarantineFile('C:\Program Files\Internet Explorer\IEXPLORE.EXE http://www.mail.ru/cnt/8136', '');
QuarantineFile('C:\Documents and Settings\Егор\Local Settings\Application Data\Amigo\Application\vk.exe', '');
QuarantineFile('C:\Documents and Settings\Егор\Local Settings\Application Data\Amigo\Application\ok.exe', '');
QuarantineFile('C:\Documents and Settings\Егор\Application Data\Browsers\exe.resworb.bat', '');
QuarantineFile('C:\Documents and Settings\Егор\Application Data\Browsers\exe.resworb.bat', '');
QuarantineFile('C:\Documents and Settings\Егор\Application Data\Browsers\exe.erolpxei.bat', '');
QuarantineFile('C:\Documents and Settings\Егор\Application Data\Browsers\exe.erolpxei.bat', '');
QuarantineFile('C:\Documents and Settings\Егор\Application Data\Browsers\exe.emorhc.bat', '');
QuarantineFile('C:\Documents and Settings\Егор\Application Data\Browsers\exe.emorhc.bat', '');
QuarantineFile('C:\Program Files\Browser Tab Search by Ask\SafetyNut\configmgrc2.cfg', '');
QuarantineFile('C:\Program Files\WinZipper\eshellctx.dll', '');
QuarantineFile('C:\Program Files\WinZipper\sqlite3.dll', '');
QuarantineFile('c:\program files\winzipper\winzipersvc.exe', '');
QuarantineFile('c:\documents and settings\Егор\local settings\application data\mail.ru\mailruupdater.exe', '');
QuarantineFileF('C:\Program Files\WinZipper', '*', true, '', 0 , 0);
QuarantineFileF('C:\Documents and Settings\Егор\Local Settings\Application Data\Mail.Ru', '*', true, '', 0 , 0);
QuarantineFileF('C:\DOCUME~1\9DEC~1\APPLIC~1\UPDATE~1', '*', true, '', 0 , 0);
QuarantineFileF('C:\Program Files\browser tab search by ask', '*', true, '', 0 , 0);
QuarantineFileF('C:\Program Files\suptab', '*', true, '', 0 , 0);
DeleteFile('C:\Documents and Settings\Егор\Application Data\Browsers\exe.emorhc.bat');
DeleteFile('C:\Documents and Settings\Егор\Application Data\Browsers\exe.erolpxei.bat');
DeleteFile('C:\Documents and Settings\Егор\Application Data\Browsers\exe.resworb.bat');
DeleteFile('c:\program files\winzipper\winzipersvc.exe', '32');
DeleteFile('C:\Program Files\WinZipper\sqlite3.dll', '32');
DeleteFile('C:\Program Files\WinZipper\eshellctx.dll', '32');
DeleteFile('C:\Program Files\Browser Tab Search by Ask\SafetyNut\configmgrc2.cfg', '32');
DeleteFile('C:\Documents and Settings\Егор\Application Data\Browsers\exe.emorhc.bat', '32');
DeleteFile('C:\Documents and Settings\Егор\Application Data\Browsers\exe.erolpxei.bat', '32');
DeleteFile('C:\Documents and Settings\Егор\Application Data\Browsers\exe.resworb.bat', '32');
DeleteFile('C:\Documents and Settings\Егор\Local Settings\Application Data\Amigo\Application\ok.exe', '32');
DeleteFile('C:\Documents and Settings\Егор\Local Settings\Application Data\Amigo\Application\vk.exe', '32');
DeleteFile('C:\Documents and Settings\Егор\Local Settings\Application Data\Mail.Ru\MailRuUpdater.exe', '32');
DeleteFile('c:\program files\browser tab search by ask\safetynut\x64\safetycrt.dll', '32');
DeleteFile('C:\DOCUME~1\9DEC~1\APPLIC~1\UPDATE~1\UPDATE~1\UPDATE~1.EXE', '32');
DeleteFile('C:\WINDOWS\Tasks\At1.job', '32');
DeleteFile('C:\Documents and Settings\Егор\applic~1\update~1\update~1\update~1.exe', '32');
DeleteFile('C:\Program Files\browser tab search by ask\safetynut\safetycrt.dll', '32');
DeleteFile('C:\Program Files\browser tab search by ask\safetynut\safetynut.exe', '32');
DeleteFile('C:\Program Files\suptab\loader64.exe', '32');
DeleteService('F06DEFF2-5B9C-490D-910F-35D3A9119622');
DeleteService('winzipersvc');
DeleteFileMask('C:\Program Files\WinZipper', '*', true);
DeleteFileMask('C:\Documents and Settings\Егор\Local Settings\Application Data\Mail.Ru', '*', true);
DeleteFileMask('C:\DOCUME~1\9DEC~1\APPLIC~1\UPDATE~1', '*', true);
DeleteFileMask('C:\Program Files\browser tab search by ask', '*', true);
DeleteFileMask('C:\Program Files\suptab', '*', true);
DeleteDirectory('C:\Program Files\WinZipper', '');
DeleteDirectory('C:\Documents and Settings\Егор\Local Settings\Application Data\Mail.Ru', '');
DeleteDirectory('C:\DOCUME~1\9DEC~1\APPLIC~1\UPDATE~1', '');
DeleteDirectory('C:\Program Files\browser tab search by ask', '');
DeleteDirectory('C:\Program Files\suptab', '');
DelBHO('{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}');
DelBHO('{D5FEC983-01DB-414a-9456-AF95AC9ED7B5}');
DelCLSID('{4F622628-7632-4B28-B184-D7BA0CA3273B}');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices', 'EventMessageFile');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect', 'EventMessageFile');
RegKeyParamDel('HKEY_USERS', '.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce', 'Del4319796');
RegKeyParamDel('HKEY_USERS', 'S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce', 'Del4319796');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'MailRuUpdater');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved', '{4F622628-7632-4B28-B184-D7BA0CA3273B}');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'System\CurrentControlSet\Control\Session Manager\AppCertDlls', 'x64');
BC_ImportALL;
ExecuteSysClean;
ExecuteRepair(9);
ExecuteWizard('SCU', 2, 3, true);
BC_Activate;
RebootWindows(true);
end.