Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\user\appdata\local\systemdir\setsearchm.exe','');
QuarantineFile('C:\Users\user\appdata\roaming\etranslator\etranslator.exe','');
QuarantineFile('C:\Windows\proxy.exe','');
QuarantineFile('C:\Windows\cuda.exe','');
QuarantineFile('C:\Program Files (x86)\ShopperPro\JSDriver\1463.0.0.0\jsdrv.exe','');
QuarantineFile('C:\Users\user\AppData\Local\Microsoft\Windows\system.exe','');
QuarantineFile('C:\PROGRA~1\COMMON~1\System\SysMenu.dll','');
QuarantineFile('C:\Users\user\AppData\Local\SystemDir\nethost.exe','');
QuarantineFile('C:\Program Files (x86)\ShopperPro\ShopperPro.exe','');
QuarantineFile('C:\Program Files (x86)\Sense\a9dfa1be-1a70-4855-a003-7143eb21ad20-7.exe','');
QuarantineFile('C:\Program Files (x86)\Sense\a9dfa1be-1a70-4855-a003-7143eb21ad20-6.exe','');
QuarantineFile('C:\Program Files (x86)\Sense\a9dfa1be-1a70-4855-a003-7143eb21ad20-5.exe','');
QuarantineFile('C:\Program Files (x86)\Sense\a9dfa1be-1a70-4855-a003-7143eb21ad20-2.exe','');
QuarantineFile('C:\Program Files (x86)\Sense\a9dfa1be-1a70-4855-a003-7143eb21ad20-11.exe','');
QuarantineFile('C:\Program Files (x86)\Sense\Sense-codedownloader.exe','');
QuarantineFile('C:\Program Files (x86)\Ge-Force\851c41b7-2424-469b-a553-3a8fe911bab0-7.exe','');
QuarantineFile('C:\Program Files (x86)\Ge-Force\851c41b7-2424-469b-a553-3a8fe911bab0-6.exe','');
QuarantineFile('C:\Program Files (x86)\Ge-Force\851c41b7-2424-469b-a553-3a8fe911bab0-5.exe','');
QuarantineFile('C:\Program Files (x86)\Ge-Force\851c41b7-2424-469b-a553-3a8fe911bab0-2.exe','');
QuarantineFile('C:\Program Files (x86)\Ge-Force\851c41b7-2424-469b-a553-3a8fe911bab0-11.exe','');
QuarantineFile('C:\Program Files (x86)\Ge-Force\Ge-Force-codedownloader.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\80384460-b08a-415d-8639-86143ac146c2-6.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\80384460-b08a-415d-8639-86143ac146c2-7.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\80384460-b08a-415d-8639-86143ac146c2-5.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\80384460-b08a-415d-8639-86143ac146c2-2.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\80384460-b08a-415d-8639-86143ac146c2-11.exe','');
QuarantineFile('C:\iexplore.bat','');
QuarantineFile('C:\Users\user\AppData\Roaming\ZZima\zzima_loader\nloader.exe','');
QuarantineFile('C:\Users\user\AppData\Local\Temp\NETC66~1.EXE','');
QuarantineFile('C:\Users\user\AppData\Local\Temp\InstallDir\chrome.exe','');
QuarantineFile('C:\Program Files (x86)\YTDownloader\YTDownloader.exe','');
DeleteFile('C:\Program Files (x86)\YTDownloader\YTDownloader.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','YTDownloader');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','pcket_x64');
DeleteFile('C:\Program Files\BaiduEx\uninit.exe','32');
DeleteFile('C:\Users\user\AppData\Local\Temp\InstallDir\chrome.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','update');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','update');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','chrome');
DeleteFile('C:\Users\user\AppData\Local\Temp\NETC66~1.EXE','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','GoSearchRemoveAppiexplore');
DeleteFile('C:\iexplore.bat','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','vvytwubmpt');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','jlxkcgldjg');
DeleteFile('C:\Windows\Tasks\80384460-b08a-415d-8639-86143ac146c2-1.job','64');
DeleteFile('C:\Windows\Tasks\80384460-b08a-415d-8639-86143ac146c2-11.job','64');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\80384460-b08a-415d-8639-86143ac146c2-11.exe','32');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\80384460-b08a-415d-8639-86143ac146c2-2.exe','32');
DeleteFile('C:\Windows\Tasks\80384460-b08a-415d-8639-86143ac146c2-2.job','64');
DeleteFile('C:\Windows\Tasks\80384460-b08a-415d-8639-86143ac146c2-5.job','64');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\80384460-b08a-415d-8639-86143ac146c2-5.exe','32');
DeleteFile('C:\Windows\Tasks\80384460-b08a-415d-8639-86143ac146c2-5_user.job','64');
DeleteFile('C:\Windows\Tasks\80384460-b08a-415d-8639-86143ac146c2-6.job','64');
DeleteFile('C:\Windows\Tasks\80384460-b08a-415d-8639-86143ac146c2-7.job','64');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\80384460-b08a-415d-8639-86143ac146c2-7.exe','32');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\80384460-b08a-415d-8639-86143ac146c2-6.exe','32');
DeleteFile('C:\Program Files (x86)\Ge-Force\Ge-Force-codedownloader.exe','32');
DeleteFile('C:\Program Files (x86)\Ge-Force\851c41b7-2424-469b-a553-3a8fe911bab0-11.exe','32');
DeleteFile('C:\Windows\Tasks\851c41b7-2424-469b-a553-3a8fe911bab0-11.job','64');
DeleteFile('C:\Windows\Tasks\851c41b7-2424-469b-a553-3a8fe911bab0-1.job','64');
DeleteFile('C:\Program Files (x86)\Ge-Force\851c41b7-2424-469b-a553-3a8fe911bab0-2.exe','32');
DeleteFile('C:\Program Files (x86)\Ge-Force\851c41b7-2424-469b-a553-3a8fe911bab0-5.exe','32');
DeleteFile('C:\Windows\Tasks\851c41b7-2424-469b-a553-3a8fe911bab0-5_user.job','64');
DeleteFile('C:\Windows\Tasks\851c41b7-2424-469b-a553-3a8fe911bab0-5.job','64');
DeleteFile('C:\Windows\Tasks\851c41b7-2424-469b-a553-3a8fe911bab0-2.job','64');
DeleteFile('C:\Program Files (x86)\Ge-Force\851c41b7-2424-469b-a553-3a8fe911bab0-6.exe','32');
DeleteFile('C:\Windows\Tasks\851c41b7-2424-469b-a553-3a8fe911bab0-6.job','64');
DeleteFile('C:\Windows\Tasks\851c41b7-2424-469b-a553-3a8fe911bab0-7.job','64');
DeleteFile('C:\Program Files (x86)\Ge-Force\851c41b7-2424-469b-a553-3a8fe911bab0-7.exe','32');
DeleteFile('C:\Program Files (x86)\Sense\Sense-codedownloader.exe','32');
DeleteFile('C:\Windows\Tasks\a9dfa1be-1a70-4855-a003-7143eb21ad20-1.job','64');
DeleteFile('C:\Windows\Tasks\a9dfa1be-1a70-4855-a003-7143eb21ad20-11.job','64');
DeleteFile('C:\Program Files (x86)\Sense\a9dfa1be-1a70-4855-a003-7143eb21ad20-11.exe','32');
DeleteFile('C:\Program Files (x86)\Sense\a9dfa1be-1a70-4855-a003-7143eb21ad20-2.exe','32');
DeleteFile('C:\Windows\Tasks\a9dfa1be-1a70-4855-a003-7143eb21ad20-2.job','64');
DeleteFile('C:\Windows\Tasks\a9dfa1be-1a70-4855-a003-7143eb21ad20-5.job','64');
DeleteFile('C:\Windows\Tasks\a9dfa1be-1a70-4855-a003-7143eb21ad20-5_user.job','64');
DeleteFile('C:\Program Files (x86)\Sense\a9dfa1be-1a70-4855-a003-7143eb21ad20-5.exe','32');
DeleteFile('C:\Program Files (x86)\Sense\a9dfa1be-1a70-4855-a003-7143eb21ad20-6.exe','32');
DeleteFile('C:\Program Files (x86)\Sense\a9dfa1be-1a70-4855-a003-7143eb21ad20-7.exe','32');
DeleteFile('C:\Windows\Tasks\a9dfa1be-1a70-4855-a003-7143eb21ad20-7.job','64');
DeleteFile('C:\Windows\Tasks\a9dfa1be-1a70-4855-a003-7143eb21ad20-6.job','64');
DeleteFile('C:\Windows\system32\Tasks\80384460-b08a-415d-8639-86143ac146c2-1','64');
DeleteFile('C:\Windows\system32\Tasks\80384460-b08a-415d-8639-86143ac146c2-11','64');
DeleteFile('C:\Windows\system32\Tasks\80384460-b08a-415d-8639-86143ac146c2-2','64');
DeleteFile('C:\Windows\system32\Tasks\80384460-b08a-415d-8639-86143ac146c2-5','64');
DeleteFile('C:\Windows\system32\Tasks\80384460-b08a-415d-8639-86143ac146c2-5_user','64');
DeleteFile('C:\Windows\system32\Tasks\80384460-b08a-415d-8639-86143ac146c2-6','64');
DeleteFile('C:\Windows\system32\Tasks\80384460-b08a-415d-8639-86143ac146c2-7','64');
DeleteFile('C:\Windows\system32\Tasks\851c41b7-2424-469b-a553-3a8fe911bab0-1','64');
DeleteFile('C:\Windows\system32\Tasks\851c41b7-2424-469b-a553-3a8fe911bab0-11','64');
DeleteFile('C:\Windows\system32\Tasks\851c41b7-2424-469b-a553-3a8fe911bab0-2','64');
DeleteFile('C:\Windows\system32\Tasks\851c41b7-2424-469b-a553-3a8fe911bab0-5','64');
DeleteFile('C:\Windows\system32\Tasks\851c41b7-2424-469b-a553-3a8fe911bab0-5_user','64');
DeleteFile('C:\Windows\system32\Tasks\851c41b7-2424-469b-a553-3a8fe911bab0-6','64');
DeleteFile('C:\Windows\system32\Tasks\851c41b7-2424-469b-a553-3a8fe911bab0-7','64');
DeleteFile('C:\Windows\system32\Tasks\a9dfa1be-1a70-4855-a003-7143eb21ad20-1','64');
DeleteFile('C:\Windows\system32\Tasks\a9dfa1be-1a70-4855-a003-7143eb21ad20-11','64');
DeleteFile('C:\Windows\system32\Tasks\a9dfa1be-1a70-4855-a003-7143eb21ad20-2','64');
DeleteFile('C:\Windows\system32\Tasks\a9dfa1be-1a70-4855-a003-7143eb21ad20-5','64');
DeleteFile('C:\Windows\system32\Tasks\a9dfa1be-1a70-4855-a003-7143eb21ad20-5_user','64');
DeleteFile('C:\Windows\system32\Tasks\a9dfa1be-1a70-4855-a003-7143eb21ad20-6','64');
DeleteFile('C:\Windows\system32\Tasks\a9dfa1be-1a70-4855-a003-7143eb21ad20-7','64');
DeleteFile('C:\Program Files (x86)\ShopperPro\ShopperPro.exe','32');
DeleteFile('C:\Users\user\AppData\Local\SystemDir\nethost.exe','32');
DeleteFile('C:\Windows\system32\Tasks\nethost task','64');
DeleteFile('C:\Windows\system32\Tasks\ShopperPro','64');
DeleteFile('C:\Windows\system32\Tasks\ShopperProJSUpd','64');
DeleteFile('C:\Windows\system32\Tasks\SMupdate1','64');
DeleteFile('C:\PROGRA~1\COMMON~1\System\SysMenu.dll','32');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\Maintenance\SMupdate2','64');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\Multimedia\SMupdate3','64');
DeleteFile('C:\Windows\system32\Tasks\SPDriver','64');
DeleteFile('C:\Windows\system32\Tasks\SystemScript','64');
DeleteFile('C:\Users\user\AppData\Local\Microsoft\Windows\system.exe','32');
DeleteFile('C:\Program Files (x86)\ShopperPro\JSDriver\1463.0.0.0\jsdrv.exe','32');
DeleteFile('C:\Windows\system32\Tasks\YTDownloader','64');
DeleteFile('C:\Windows\system32\Tasks\YTDownloaderUpd','64');
DeleteFile('C:\Windows\cuda.exe','32');
DeleteFile('C:\Windows\proxy.exe','32');
DeleteFile('C:\Users\user\appdata\roaming\etranslator\etranslator.exe','32');
DeleteFile('C:\Users\user\appdata\local\systemdir\setsearchm.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteREpair(9);
ExecuteREpair(16);
RebootWindows(false);
end.
Компьютер перезагрузится.