Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\Евгений\appdata\roaming\aspackage\aspackage.exe','');
QuarantineFile('C:\windows\system32\Boshomt.dll','');
QuarantineFile('C:\Program Files (x86)\SwiftSearch_1.10.0.25\Update\SwiftSearchAutoUpdateClient.exe','');
QuarantineFile('C:\PROGRA~1\GROOVE~1\Kupligri.bat','');
QuarantineFile('C:\Users\Евгений\AppData\Local\Buzz Comp\xBin\BuzzComp.dll','');
QuarantineFile('C:\Users\Евгений\AppData\Roaming\newSI_4396\s_inst.exe','');
QuarantineFile('C:\Users\Евгений\AppData\Roaming\newSI_21590\s_inst.exe','');
QuarantineFile('C:\Users\Евгений\AppData\Roaming\newSI_1801\s_inst.exe','');
DelBHO('{4F3C10F8-9B89-4A2E-B523-33F2FB682DC2}');
QuarantineFile('C:\Program Files (x86)\Аудио и видео скачивание\IE\x86\Downloader.dll','');
QuarantineFile('C:\iexplore.bat','');
QuarantineFile('C:\Users\Евгений\AppData\Local\lcoupon\foygnstb.exe','');
QuarantineFile('C:\Users\Евгений\AppData\Local\lcoupon\config.json','');
QuarantineFile('C:\Users\Евгений\AppData\Local\Birds\birds365.exe','');
QuarantineFile('C:\ProgramData\TimeTasks\timetasks.exe','');
QuarantineFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe','');
QuarantineFile('C:\Program Files (x86)\Zaxar\ZaxarGameBrowser.exe','');
QuarantineFile('C:\windows\system32\drivers\cherimoya.sys','');
SetServiceStart('swsedrvr_vt_1_10_0_25', 4);
DeleteService('swsedrvr_vt_1_10_0_25');
SetServiceStart('IhPul', 4);
SetServiceStart('PicexaService', 4);
SetServiceStart('pyzeqewe', 4);
SetServiceStart('SSFK', 4);
SetServiceStart('swsesrvc_1.10.0.25', 4);
SetServiceStart('toniqobe', 4);
SetServiceStart('WdMan', 4);
SetServiceStart('WindowsMangerProtect', 4);
SetServiceStart('zigipyro', 4);
DeleteService('zigipyro');
DeleteService('WindowsMangerProtect');
DeleteService('WdMan');
DeleteService('toniqobe');
DeleteService('swsesrvc_1.10.0.25');
DeleteService('SSFK');
DeleteService('pyzeqewe');
DeleteService('PicexaService');
DeleteService('IhPul');
QuarantineFile('C:\windows\system32\drivers\swsedrvr_vt_1_10_0_25.sys','');
QuarantineFile('C:\windows\system32\DNSAPI.dll','');
TerminateProcessByName('c:\program files (x86)\sfk\ssfk.exe');
TerminateProcessByName('c:\program files (x86)\swiftsearch_1.10.0.25\service\swsesrvc.exe');
TerminateProcessByName('c:\users\Евгений\appdata\roaming\tsv\tsvr.exe');
TerminateProcessByName('c:\users\Евгений\appdata\local\gmsd_ru_005010190\upgmsd_ru_005010190.exe');
TerminateProcessByName('c:\programdata\xwdmx\wdman.exe');
QuarantineFile('c:\programdata\xwdmx\wdman.exe','');
QuarantineFile('c:\users\Евгений\appdata\local\gmsd_ru_005010190\upgmsd_ru_005010190.exe','');
QuarantineFile('c:\users\Евгений\appdata\roaming\tsv\tsvr.exe','');
QuarantineFile('c:\program files (x86)\swiftsearch_1.10.0.25\service\swsesrvc.exe','');
QuarantineFile('c:\program files (x86)\sfk\ssfk.exe','');
TerminateProcessByName('c:\program files (x86)\rec_ru_112\rec_ru_112.exe');
TerminateProcessByName('c:\program files (x86)\rec_ru_130\rec_ru_130.exe');
TerminateProcessByName('c:\program files (x86)\rec_ru_139\rec_ru_139.exe');
TerminateProcessByName('c:\program files (x86)\rec_ru_142\rec_ru_142.exe');
TerminateProcessByName('C:\Program Files (x86)\rec_ru_150\rec_ru_150.exe');
TerminateProcessByName('c:\users\Евгений\appdata\roaming\newsi_21590\s_inst.exe');
TerminateProcessByName('c:\users\Евгений\appdata\local\smartweb\smartwebhelper.exe');
QuarantineFile('c:\users\Евгений\appdata\local\smartweb\smartwebhelper.exe','');
QuarantineFile('c:\users\Евгений\appdata\roaming\newsi_21590\s_inst.exe','');
QuarantineFile('C:\Program Files (x86)\rec_ru_150\rec_ru_150.exe','');
QuarantineFile('c:\program files (x86)\rec_ru_150\rec_ru_150.exe','');
QuarantineFile('c:\program files (x86)\rec_ru_145\rec_ru_145.exe','');
QuarantineFile('c:\program files (x86)\rec_ru_142\rec_ru_142.exe','');
QuarantineFile('c:\program files (x86)\rec_ru_139\rec_ru_139.exe','');
QuarantineFile('c:\program files (x86)\rec_ru_130\rec_ru_130.exe','');
QuarantineFile('c:\program files (x86)\rec_ru_112\rec_ru_112.exe','');
TerminateProcessByName('c:\programdata\tmp0x0x\protectwindowsmanager.exe');
TerminateProcessByName('c:\users\Евгений\appdata\local\00bab880-1451355282-e111-b5a4-b2804f259a6c\qnsgecaa.tmp');
QuarantineFile('c:\users\Евгений\appdata\local\00bab880-1451355282-e111-b5a4-b2804f259a6c\qnsgecaa.tmp','');
QuarantineFile('c:\programdata\tmp0x0x\protectwindowsmanager.exe','');
TerminateProcessByName('c:\program files (x86)\feed notifier\notifier.exe');
TerminateProcessByName('c:\program files (x86)\picexa\picexasvc.exe');
QuarantineFile('c:\program files (x86)\picexa\picexasvc.exe','');
QuarantineFile('c:\program files (x86)\feed notifier\notifier.exe','');
TerminateProcessByName('c:\program files (x86)\00bab880-1447059103-e111-b5a4-b2804f259a6c\hnsw79dd.tmp');
TerminateProcessByName('c:\program files (x86)\00bab880-1447059103-e111-b5a4-b2804f259a6c\jnsb62d2.tmp');
QuarantineFile('c:\program files (x86)\00bab880-1447059103-e111-b5a4-b2804f259a6c\jnsb62d2.tmp','');
QuarantineFile('c:\program files (x86)\00bab880-1447059103-e111-b5a4-b2804f259a6c\hnsw79dd.tmp','');
DeleteFile('c:\program files (x86)\00bab880-1447059103-e111-b5a4-b2804f259a6c\hnsw79dd.tmp','32');
DeleteFile('c:\program files (x86)\00bab880-1447059103-e111-b5a4-b2804f259a6c\jnsb62d2.tmp','32');
DeleteFile('c:\program files (x86)\feed notifier\notifier.exe','32');
DeleteFile('c:\program files (x86)\picexa\picexasvc.exe','32');
DeleteFile('c:\programdata\tmp0x0x\protectwindowsmanager.exe','32');
DeleteFile('c:\users\Евгений\appdata\local\00bab880-1451355282-e111-b5a4-b2804f259a6c\qnsgecaa.tmp','32');
DeleteFile('c:\program files (x86)\rec_ru_112\rec_ru_112.exe','32');
DeleteFile('c:\program files (x86)\rec_ru_130\rec_ru_130.exe','32');
DeleteFile('c:\program files (x86)\rec_ru_139\rec_ru_139.exe','32');
DeleteFile('c:\program files (x86)\rec_ru_142\rec_ru_142.exe','32');
DeleteFile('c:\program files (x86)\rec_ru_145\rec_ru_145.exe','32');
DeleteFile('c:\program files (x86)\rec_ru_150\rec_ru_150.exe','32');
DeleteFile('C:\Program Files (x86)\rec_ru_150\rec_ru_150.exe','32');
DeleteFile('c:\users\Евгений\appdata\roaming\newsi_21590\s_inst.exe','32');
DeleteFile('c:\users\Евгений\appdata\local\smartweb\smartwebhelper.exe','32');
DeleteFile('c:\program files (x86)\sfk\ssfk.exe','32');
DeleteFile('c:\program files (x86)\swiftsearch_1.10.0.25\service\swsesrvc.exe','32');
DeleteFile('c:\users\Евгений\appdata\roaming\tsv\tsvr.exe','32');
DeleteFile('c:\users\Евгений\appdata\local\gmsd_ru_005010190\upgmsd_ru_005010190.exe','32');
DeleteFile('c:\programdata\xwdmx\wdman.exe','32');
DeleteFile('C:\Program Files (x86)\Picexa\curlpp.dll','32');
DeleteFile('C:\Program Files (x86)\Picexa\libcurl.dll','32');
DeleteFile('C:\Program Files (x86)\Picexa\LIBEAY32.dll','32');
DeleteFile('C:\Program Files (x86)\Picexa\SSLEAY32.dll','32');
DeleteFile('C:\Program Files (x86)\Picexa\zlib1.dll','32');
DeleteFile('C:\windows\system32\drivers\swsedrvr_vt_1_10_0_25.sys','32');
DeleteFile('C:\Program Files (x86)\Zaxar\ZaxarGameBrowser.exe','32');
DeleteFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe','32');
DeleteFile('C:\ProgramData\TimeTasks\timetasks.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ZaxarGameBrowser');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ZaxarLoader');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Timestasks');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','SmartWeb');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gmsd_ru_005010142');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ru_112');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ru_130');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ru_139');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ru_142');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ru_145');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gmsd_ru_005010190');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ru_150');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','upgmsd_ru_005010190.exe');
DeleteFile('C:\Users\Евгений\AppData\Local\lcoupon\config.json','32');
DeleteFile('C:\Users\Евгений\AppData\Local\lcoupon\foygnstb.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','lcoupon');
DeleteFile('C:\iexplore.bat','32');
DeleteFile('C:\Program Files (x86)\Аудио и видео скачивание\IE\x86\Downloader.dll','32');
DeleteFile('C:\Users\Евгений\AppData\Roaming\newSI_1801\s_inst.exe','32');
DeleteFile('C:\Users\Евгений\AppData\Roaming\newSI_21590\s_inst.exe','32');
DeleteFile('C:\Users\Евгений\AppData\Roaming\newSI_4396\s_inst.exe','32');
DeleteFile('C:\Users\Евгений\AppData\Local\Buzz Comp\xBin\BuzzComp.dll','32');
DeleteFile('C:\windows\system32\Tasks\Buzz Comp','64');
DeleteFile('C:\windows\Tasks\newSI_4396.job','32');
DeleteFile('C:\windows\Tasks\newSI_21590.job','32');
DeleteFile('C:\windows\Tasks\newSI_1801.job','32');
DeleteFile('C:\PROGRA~1\GROOVE~1\Kupligri.bat','32');
DeleteFile('C:\windows\system32\Tasks\Muituj','64');
DeleteFile('C:\windows\system32\Tasks\newSI_1801','64');
DeleteFile('C:\windows\system32\Tasks\newSI_21590','64');
DeleteFile('C:\windows\system32\Tasks\newSI_4396','64');
DeleteFile('C:\windows\system32\Tasks\SmartWeb Upgrade Trigger Task','64');
DeleteFile('C:\windows\system32\Tasks\SwiftSearch Auto Updater 1.10.0.25 Core','64');
DeleteFile('C:\Program Files (x86)\SwiftSearch_1.10.0.25\Update\SwiftSearchAutoUpdateClient.exe','32');
DeleteFile('C:\windows\system32\Boshomt.dll','32');
DeleteFile('C:\Users\Евгений\appdata\roaming\aspackage\aspackage.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteREpair(15);
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.