Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
QuarantineFile('C:\Program Files (x86)\SwiftSearch_1.10.0.25\Update\SwiftSearchAutoUpdateClient.exe','');
QuarantineFile('C:\Users\hp1\AppData\Roaming\WindowsUpdater\Updater.exe','');
QuarantineFile('C:\Users\hp1\AppData\Local\Cooking Kit\xBin\CookingKit.dll','');
QuarantineFile('C:\Users\hp1\AppData\Local\Kometa\Application\kometa.exe','');
QuarantineFile('C:\Users\hp1\AppData\Local\coprofit\config.json','');
QuarantineFile('C:\Users\hp1\AppData\Local\coprofit\coprofit_stb.exe','');
SetServiceStart('fipufuwu', 4);
SetServiceStart('punutume', 4);
SetServiceStart('wululynu', 4);
SetServiceStart('zodimeli', 4);
DeleteService('zodimeli');
DeleteService('wululynu');
DeleteService('punutume');
DeleteService('fipufuwu');
TerminateProcessByName('c:\users\hp1\appdata\local\temp\nsc1cea.tmp');
TerminateProcessByName('c:\users\hp1\appdata\local\34444335-1446768100-4b30-3446-3863bba85fb0\snsza6c9.tmp');
TerminateProcessByName('c:\users\hp1\appdata\local\gmsd_ru_005010137\upgmsd_ru_005010137.exe');
QuarantineFile('c:\users\hp1\appdata\local\gmsd_ru_005010137\upgmsd_ru_005010137.exe','');
QuarantineFile('c:\users\hp1\appdata\local\34444335-1446768100-4b30-3446-3863bba85fb0\snsza6c9.tmp','');
QuarantineFile('c:\users\hp1\appdata\local\temp\nsc1cea.tmp','');
TerminateProcessByName('c:\program files (x86)\34444335-1446753640-4b30-3446-3863bba85fb0\jnsxfc00.tmp');
TerminateProcessByName('c:\program files (x86)\34444335-1446753640-4b30-3446-3863bba85fb0\knstcd0a.tmpfs');
QuarantineFile('c:\program files (x86)\34444335-1446753640-4b30-3446-3863bba85fb0\knstcd0a.tmpfs','');
QuarantineFile('c:\program files (x86)\34444335-1446753640-4b30-3446-3863bba85fb0\jnsxfc00.tmp','');
TerminateProcessByName('c:\program files (x86)\gmsd_ru_005010137\gmsd_ru_005010137.exe');
TerminateProcessByName('c:\program files (x86)\34444335-1446753640-4b30-3446-3863bba85fb0\hnsu41c5.tmp');
QuarantineFile('c:\program files (x86)\34444335-1446753640-4b30-3446-3863bba85fb0\hnsu41c5.tmp','');
QuarantineFile('c:\program files (x86)\gmsd_ru_005010137\gmsd_ru_005010137.exe','');
TerminateProcessByName('c:\users\hp1\appdata\local\temp\is-9df4c.tmp\11.tmp');
TerminateProcessByName('c:\users\hp1\appdata\local\temp\is-4m05u.tmp\11.exe');
QuarantineFile('c:\users\hp1\appdata\local\temp\is-9df4c.tmp\11.tmp','');
QuarantineFile('c:\users\hp1\appdata\local\temp\is-4m05u.tmp\11.exe','');
DeleteFile('c:\users\hp1\appdata\local\temp\is-4m05u.tmp\11.exe','32');
DeleteFile('c:\users\hp1\appdata\local\temp\is-9df4c.tmp\11.tmp','32');
DeleteFile('c:\program files (x86)\gmsd_ru_005010137\gmsd_ru_005010137.exe','32');
DeleteFile('c:\program files (x86)\34444335-1446753640-4b30-3446-3863bba85fb0\hnsu41c5.tmp','32');
DeleteFile('c:\program files (x86)\34444335-1446753640-4b30-3446-3863bba85fb0\jnsxfc00.tmp','32');
DeleteFile('c:\program files (x86)\34444335-1446753640-4b30-3446-3863bba85fb0\knstcd0a.tmpfs','32');
DeleteFile('c:\users\hp1\appdata\local\temp\nsc1cea.tmp','32');
DeleteFile('c:\users\hp1\appdata\local\34444335-1446768100-4b30-3446-3863bba85fb0\snsza6c9.tmp','32');
DeleteFile('c:\users\hp1\appdata\local\gmsd_ru_005010137\upgmsd_ru_005010137.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gmsd_ru_005010137');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','upgmsd_ru_005010137.exe');
DeleteFile('C:\Users\hp1\AppData\Local\coprofit\coprofit_stb.exe','32');
DeleteFile('C:\Users\hp1\AppData\Local\coprofit\config.json','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','coprofit');
DeleteFile('C:\Users\hp1\AppData\Local\Kometa\Application\kometa.exe','32');
DeleteFile('C:\Users\hp1\AppData\Roaming\WindowsUpdater\Updater.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\WindowsUpdater','64');
DeleteFile('C:\Program Files (x86)\SwiftSearch_1.10.0.25\Update\SwiftSearchAutoUpdateClient.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\SwiftSearch Auto Updater 1.10.0.25 Core','64');
DeleteFile('C:\WINDOWS\system32\Tasks\SwiftSearch Auto Updater 1.10.0.25 Pending Update','64');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.