Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Program Files\mpc cleaner\uninstdelete.exe','');
QuarantineFile('C:\Users\р\appdata\roaming\aspackage\uninstall.exe','');
QuarantineFile('C:\Users\р\appdata\roaming\aspackage\aspackage.exe','');
QuarantineFile('C:\Program Files\advPlugin\8Z1cz8R.exe.exe','');
QuarantineFile('C:\ProgramData\DRwVZrIzzg\GwBblBv4.bat','');
QuarantineFile('C:\ProgramData\CzJRVw\AkvOUAY5.bat','');
QuarantineFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe','');
QuarantineFile('C:\ProgramData\Windows\csrss.exe','');
QuarantineFile('C:\Users\р\AppData\Local\Blacount\config.json','');
QuarantineFile('C:\Users\р\AppData\Local\Blacount\stub.exe','');
QuarantineFile('C:\Users\р\AppData\Roaming\daemon2.exe','');
QuarantineFile('C:\Users\р\AppData\Local\Ukmedia\xyzSE.dll','');
QuarantineFile('C:\Users\р\AppData\Roaming\ASPackage\ASPackage.exe','');
DeleteService('QMUdisk');
DeleteService('softaal');
DeleteService('tsnethlp');
DeleteService('TSSK');
SetServiceStart('MPCBase', 4);
SetServiceStart('MPCKpt', 4);
DeleteService('MPCKpt');
DeleteService('MPCBase');
DeleteService('zutuzuni');
DeleteService('wucotusy');
DeleteService('SSFK');
QuarantineFile('C:\Program Files\57D8045B-1454175777-DE11-B982-705AB64DEF5D\jnsvADBD.tmp','');
QuarantineFile('C:\Program Files\57D8045B-1454175777-DE11-B982-705AB64DEF5D\hnsv51.tmp','');
QuarantineFile('C:\Program Files\SFK\SSFK.exe','');
SetServiceStart('zigipyro', 4);
DeleteService('zigipyro');
SetServiceStart('WdMan', 4);
DeleteService('WdMan');
SetServiceStart('HSystem', 4);
SetServiceStart('rowugoqo', 4);
SetServiceStart('UbarPolicyProvider', 4);
DeleteService('UbarPolicyProvider');
DeleteService('rowugoqo');
DeleteService('HSystem');
QuarantineFile('C:\Program Files\UBar\UbarDriver.sys','');
QuarantineFile('C:\Windows\system32\DRIVERS\MPCKpt.sys','');
QuarantineFile('C:\Windows\System32\drivers\MPCBase.sys','');
QuarantineFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.dll','');
TerminateProcessByName('c:\program files\wedsoft\zxfwwd.exe');
QuarantineFile('c:\program files\wedsoft\zxfwwd.exe','');
TerminateProcessByName('c:\programdata\5wdm5\wdman.exe');
QuarantineFile('c:\programdata\5wdm5\wdman.exe','');
TerminateProcessByName('c:\program files\ubar\ubarservice.exe');
QuarantineFile('c:\program files\ubar\ubarservice.exe','');
TerminateProcessByName('c:\program files\ubar\ubar.exe');
QuarantineFile('c:\program files\ubar\ubar.exe','');
TerminateProcessByName('c:\users\р\appdata\local\57d8045b-1454190373-de11-b982-705ab64def5d\snsg58cc.tmp');
QuarantineFile('c:\users\р\appdata\local\57d8045b-1454190373-de11-b982-705ab64def5d\snsg58cc.tmp','');
TerminateProcessByName('c:\users\р\appdata\local\57d8045b-1454361673-de11-b982-705ab64def5d\qnsr694f.tmp');
TerminateProcessByName('c:\program files\mpc cleaner\mpcautoclean.exe');
QuarantineFile('c:\program files\mpc cleaner\mpcautoclean.exe','');
TerminateProcessByName('c:\program files\mpc cleaner\mpcnews.exe');
QuarantineFile('c:\program files\mpc cleaner\mpcnews.exe','');
TerminateProcessByName('c:\program files\57d8045b-1454175777-de11-b982-705ab64def5d\knsx2ead.tmp');
QuarantineFile('c:\program files\57d8045b-1454175777-de11-b982-705ab64def5d\knsx2ead.tmp','');
DeleteFile('c:\program files\57d8045b-1454175777-de11-b982-705ab64def5d\knsx2ead.tmp','32');
DeleteFile('c:\program files\mpc cleaner\mpcnews.exe','32');
DeleteFile('c:\program files\mpc cleaner\mpcautoclean.exe','32');
DeleteFile('c:\users\р\appdata\local\57d8045b-1454361673-de11-b982-705ab64def5d\qnsr694f.tmp','32');
DeleteFile('c:\users\р\appdata\local\57d8045b-1454190373-de11-b982-705ab64def5d\snsg58cc.tmp','32');
DeleteFile('c:\program files\ubar\ubar.exe','32');
DeleteFile('c:\programdata\5wdm5\wdman.exe','32');
DeleteFile('c:\program files\wedsoft\zxfwwd.exe','32');
DeleteFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.dll','32');
DeleteFile('C:\Windows\System32\drivers\MPCBase.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\MPCKpt.sys','32');
DeleteFile('C:\Program Files\UBar\UbarDriver.sys','32');
DeleteFile('C:\Program Files\SFK\SSFK.exe','32');
DeleteFile('C:\Program Files\57D8045B-1454175777-DE11-B982-705AB64DEF5D\hnsv51.tmp','32');
DeleteFile('C:\Program Files\57D8045B-1454175777-DE11-B982-705AB64DEF5D\jnsvADBD.tmp','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\11.3.17207.222\QMUdisk.sys','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\11.3.17207.222\softaal.sys','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\11.3.17207.222\TsNetHlp.sys','32');
DeleteFile('C:\Windows\system32\tssk.sys','32');
DeleteFile('C:\Users\р\AppData\Roaming\ASPackage\ASPackage.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Erption');
DeleteFile('C:\Users\р\AppData\Local\Ukmedia\xyzSE.dll','32');
DeleteFile('C:\Users\р\AppData\Roaming\daemon2.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Daemon');
DeleteFile('C:\Users\р\AppData\Local\Blacount\stub.exe','32');
DeleteFile('C:\Users\р\AppData\Local\Blacount\config.json','32');
DeleteFile('C:\ProgramData\Windows\csrss.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Client Server Runtime Subsystem','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Blacount','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\apphide','command');
DeleteFile('C:\Program Files\ppt\Uninst.exe','32');
DeleteFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SpaceSoundPro','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\pcmgr','command');
DeleteFile('C:\ProgramData\wSAbUC\sewvGlk0.bat','32');
DeleteFile('C:\ProgramData\CzJRVw\AkvOUAY5.bat','32');
DeleteFile('C:\ProgramData\DRwVZrIzzg\GwBblBv4.bat','32');
DeleteFile('C:\Program Files\advPlugin\8Z1cz8R.exe.exe','32');
DeleteFile('C:\Windows\Tasks\Update Service for advPlugin2.job','32');
DeleteFile('C:\Windows\Tasks\Update Service for advPlugin.job','32');
DeleteFile('C:\Windows\Tasks\Update Service for VK Downloader.job','32');
DeleteFile('C:\Windows\Tasks\Update Service for VK Downloader2.job','32');
DeleteFile('C:\Windows\system32\Tasks\Update Service for advPlugin','32');
DeleteFile('C:\Windows\system32\Tasks\Update Service for advPlugin2','32');
DeleteFile('C:\Windows\system32\Tasks\Update Service for VK Downloader','32');
DeleteFile('C:\Windows\system32\Tasks\Update Service for VK Downloader2','32');
DeleteFile('C:\Windows\system32\Tasks\{354F1DDF-D2CC-4133-A916-5FCA71BB6BAB}','32');
DeleteFile('C:\Windows\system32\Tasks\{5BF92A6F-9591-4369-9F98-6288162823A8}','32');
DeleteFile('C:\Users\р\AppData\Local\Temp\nscF612.tmp\blowfish.dll','32');
DeleteFile('C:\Users\р\appdata\roaming\aspackage\aspackage.exe','32');
DeleteFile('C:\Users\р\appdata\roaming\aspackage\uninstall.exe','32');
DeleteFile('C:\Program Files\mpc cleaner\uninstdelete.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.