Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\Пользователь\appdata\local\smartweb\__u.exe','');
QuarantineFile('C:\Users\Пользователь\appdata\local\smartweb\swhk.dll','');
QuarantineFile('C:\Program Files (x86)\WordShark_1.10.0.20\Update\WordSharkAutoUpdateClient.exe','');
QuarantineFile('C:\Program Files (x86)\CiPlus-4.5vV03.07\bc22d9b4-5f74-4593-aaec-a68ece4cee6c-5.exe','');
QuarantineFile('C:\Program Files (x86)\CiPlus-4.5vV03.07\bc22d9b4-5f74-4593-aaec-a68ece4cee6c-10.exe','');
QuarantineFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe','');
QuarantineFile('C:\iexplore.bat','');
QuarantineFile('C:\Program Files (x86)\Internet Explorer\iexplore.bat','');
QuarantineFile('C:\Program Files (x86)\Google\chrome.bat','');
QuarantineFile('C:\Users\Пользователь\AppData\Roaming\cpuminer\sgminer\sgminer.cmd','');
SetServiceStart('innfd_1_10_0_14', 4);
SetServiceStart('iSafeKrnl', 4);
SetServiceStart('iSafeKrnlKit', 4);
SetServiceStart('iSafeKrnlMon', 4);
SetServiceStart('iSafeKrnlR3', 4);
SetServiceStart('iSafeNetFilter', 4);
SetServiceStart('wsfd_vw_1_10_0_20', 4);
DeleteService('iSafeKrnlBoot');
DeleteService('wsfd_vw_1_10_0_20');
DeleteService('iSafeNetFilter');
DeleteService('iSafeKrnlR3');
DeleteService('iSafeKrnlMon');
DeleteService('iSafeKrnlKit');
DeleteService('iSafeKrnl');
DeleteService('innfd_1_10_0_14');
SetServiceStart('cybusyro', 4);
SetServiceStart('dequzody', 4);
SetServiceStart('IHProtect Service', 4);
SetServiceStart('insvc_1.10.0.14', 4);
SetServiceStart('PicexaService', 4);
SetServiceStart('SSFK', 4);
SetServiceStart('wssvc_1.10.0.20', 4);
DeleteService('kevefori');
DeleteService('wssvc_1.10.0.20');
DeleteService('SSFK');
DeleteService('PicexaService');
DeleteService('insvc_1.10.0.14');
DeleteService('IHProtect Service');
DeleteService('dequzody');
DeleteService('cybusyro');
QuarantineFile('C:\Windows\system32\drivers\wsfd_vw_1_10_0_20.sys','');
QuarantineFile('C:\Windows\system32\drivers\innfd_1_10_0_14.sys','');
QuarantineFile('C:\Program Files (x86)\MiuiTab\IeWatchDog.dll','');
TerminateProcessByName('c:\program files (x86)\wordshark_1.10.0.20\service\wssvc.exe');
QuarantineFile('c:\program files (x86)\wordshark_1.10.0.20\service\wssvc.exe','');
TerminateProcessByName('c:\program files (x86)\elex-tech\yac\isafetray.exe');
TerminateProcessByName('c:\users\Пользователь\appdata\roaming\b6f692e0-1433537201-11dd-8d77-5442490244eb\jnsle154.tmp');
TerminateProcessByName('c:\program files (x86)\picexa\picexasvc.exe');
TerminateProcessByName('c:\program files (x86)\miuitab\protectservice.exe');
TerminateProcessByName('c:\users\Пользователь\appdata\local\smartweb\smartwebapp.exe');
QuarantineFile('c:\users\Пользователь\appdata\local\smartweb\smartwebapp.exe','');
QuarantineFile('c:\program files (x86)\miuitab\protectservice.exe','');
QuarantineFile('c:\program files (x86)\picexa\picexasvc.exe','');
QuarantineFile('c:\users\Пользователь\appdata\roaming\b6f692e0-1433537201-11dd-8d77-5442490244eb\jnsle154.tmp','');
QuarantineFile('c:\program files (x86)\elex-tech\yac\isafetray.exe','');
TerminateProcessByName('c:\program files (x86)\miuitab\cmdshell.exe');
TerminateProcessByName('c:\users\Пользователь\appdata\roaming\b6f692e0-1433537201-11dd-8d77-5442490244eb\hnsn199c.tmp');
TerminateProcessByName('c:\program files (x86)\miuitab\hpnotify.exe');
TerminateProcessByName('c:\program files (x86)\infonaut_1.10.0.14\service\insvc.exe');
QuarantineFile('c:\program files (x86)\infonaut_1.10.0.14\service\insvc.exe','');
QuarantineFile('c:\program files (x86)\miuitab\hpnotify.exe','');
QuarantineFile('c:\users\Пользователь\appdata\roaming\b6f692e0-1433537201-11dd-8d77-5442490244eb\hnsn199c.tmp','');
QuarantineFile('c:\program files (x86)\miuitab\cmdshell.exe','');
DeleteFile('c:\program files (x86)\miuitab\cmdshell.exe','32');
DeleteFile('c:\users\Пользователь\appdata\roaming\b6f692e0-1433537201-11dd-8d77-5442490244eb\hnsn199c.tmp','32');
DeleteFile('c:\program files (x86)\miuitab\hpnotify.exe','32');
DeleteFile('c:\program files (x86)\infonaut_1.10.0.14\service\insvc.exe','32');
DeleteFile('c:\program files (x86)\elex-tech\yac\isafetray.exe','32');
DeleteFile('c:\users\Пользователь\appdata\roaming\b6f692e0-1433537201-11dd-8d77-5442490244eb\jnsle154.tmp','32');
DeleteFile('c:\program files (x86)\picexa\picexasvc.exe','32');
DeleteFile('c:\program files (x86)\miuitab\protectservice.exe','32');
DeleteFile('c:\users\Пользователь\appdata\local\smartweb\smartwebapp.exe','32');
DeleteFile('c:\program files (x86)\wordshark_1.10.0.20\service\wssvc.exe','32');
DeleteFile('C:\Program Files (x86)\Picexa\SSLEAY32.dll','32');
DeleteFile('C:\Program Files (x86)\Picexa\zlib1.dll','32');
DeleteFile('C:\Program Files (x86)\Picexa\LIBEAY32.dll','32');
DeleteFile('C:\Program Files (x86)\Picexa\curlpp.dll','32');
DeleteFile('C:\Program Files (x86)\MiuiTab\IeWatchDog.dll','32');
DeleteFile('C:\Program Files (x86)\Picexa\libcurl.dll','32');
DeleteFile('C:\Windows\system32\drivers\innfd_1_10_0_14.sys','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys','32');
DeleteFile('C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\iSafeNetFilter.sys','32');
DeleteFile('C:\Windows\system32\drivers\wsfd_vw_1_10_0_20.sys','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','SmartWeb');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gmsd_ru_005010040');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','GoogleChromeAutoLaunch_1BB8204478EB23873EB78136BAE51D79');
DeleteFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','MailRuUpdater');
DeleteFile('C:\Users\Пользователь\AppData\Roaming\cpuminer\sgminer\sgminer.cmd','32');
DeleteFile('C:\Program Files (x86)\Google\chrome.bat','32');
DeleteFile('C:\Program Files (x86)\Internet Explorer\iexplore.bat','32');
DeleteFile('C:\iexplore.bat','32');
DeleteFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe','32');
DeleteFile('C:\Program Files (x86)\CiPlus-4.5vV03.07\bc22d9b4-5f74-4593-aaec-a68ece4cee6c-10.exe','32');
DeleteFile('C:\Program Files (x86)\CiPlus-4.5vV03.07\bc22d9b4-5f74-4593-aaec-a68ece4cee6c-5.exe','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP1.job','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP2.job','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP3.job','32');
DeleteFile('C:\Windows\Tasks\bc22d9b4-5f74-4593-aaec-a68ece4cee6c-10_user.job','32');
DeleteFile('C:\Windows\Tasks\bc22d9b4-5f74-4593-aaec-a68ece4cee6c-5_user.job','32');
DeleteFile('C:\Windows\Tasks\DKsyI4DFPBFhoXW.job','32');
DeleteFile('C:\Windows\Tasks\t0IlAIfEgs3LHoyplP.job','32');
DeleteFile('C:\Windows\Tasks\XI2He1xf6ArRsUuzs.job','32');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP1','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP2','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP3','64');
DeleteFile('C:\Windows\system32\Tasks\WordShark Auto Updater 1.10.0.20 Core','64');
DeleteFile('C:\Windows\system32\Tasks\WordShark Auto Updater 1.10.0.20 Pending Update','64');
DeleteFile('C:\Program Files (x86)\WordShark_1.10.0.20\Update\WordSharkAutoUpdateClient.exe','32');
DeleteFile('C:\Users\Пользователь\appdata\local\smartweb\swhk.dll','32');
DeleteFile('C:\Users\Пользователь\appdata\local\smartweb\__u.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.