Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\ProgramData\Hotfresh\Itgofresh.reg','');
QuarantineFile('C:\ProgramData\Hotfresh\FunTom.reg','');
QuarantineFile('C:\ProgramData\Hotfresh\Zimfan.reg','');
QuarantineFile('C:\Program Files (x86)\Fughlaserther\ralition.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\WinSnare\WinSnare.dll','');
QuarantineFile('C:\ProgramData\Microsoft\Phone Tools\CoreCon\12.0\3082\NonSDKAddonLangVer.dll','');
QuarantineFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe','');
QuarantineFile('C:\Program Files\3Z1OHZD0EB\3Z1OHZD0E.exe','');
QuarantineFile('C:\Program Files\YWPEUF3BBU\YWPEUF3BB.exe','');
QuarantineFile('C:\Program Files\B3WH0CT236\B3WH0CT23.exe','');
QuarantineFile('C:\Program Files\WG5GGMA19I\WG5GGMA19.exe','');
QuarantineFile('C:\Program Files\V9BDWKTI1S\V9BDWKTI1.exe','');
QuarantineFile('C:\Program Files\DTI7MXLIT8\DTI7MXLIT.exe','');
QuarantineFile('C:\Program Files\2JMJKAQOCU\2JMJKAQOC.exe','');
QuarantineFile('C:\Program Files (x86)\BestCleaner\IPWPOYVMJO.exe','');
QuarantineFile('C:\Program Files\EFJQH5AK8T\EFJQH5AK8.exe','');
QuarantineFile('C:\Program Files\41S9V63KG0\41S9V63KG.exe','');
QuarantineFile('C:\Users\User\AppData\Local\Temp\__Samsung_Update\SBIOSIO64.sys','');
QuarantineFile('C:\Program Files (x86)\Common Files\Services\iThemes.dll','');
QuarantineFile('C:\Users\User\AppData\Local\Temp\BCAB2D9A-1E8739EA-502F06A0-BE4A4174\53af4541.sys','');
QuarantineFile('c:\programdata\winsapsvc\winsap.dll','');
QuarantineFile('c:\program files (x86)\winarcher\archer.dll','');
QuarantineFile('c:\program files (x86)\gubed\gubedzl.dll','');
DeleteFile('c:\program files (x86)\gubed\gubedzl.dll','32');
DeleteFile('c:\program files (x86)\winarcher\archer.dll','32');
DeleteFile('C:\Users\User\AppData\Local\Temp\BCAB2D9A-1E8739EA-502F06A0-BE4A4174\53af4541.sys','32');
DeleteFile('C:\Program Files\41S9V63KG0\41S9V63KG.exe','32');
DeleteFile('C:\Program Files\EFJQH5AK8T\EFJQH5AK8.exe','32');
DeleteFile('C:\Program Files (x86)\BestCleaner\IPWPOYVMJO.exe','32');
DeleteFile('C:\Program Files\2JMJKAQOCU\2JMJKAQOC.exe','32');
DeleteFile('C:\Program Files\DTI7MXLIT8\DTI7MXLIT.exe','32');
DeleteFile('C:\Program Files\V9BDWKTI1S\V9BDWKTI1.exe','32');
DeleteFile('C:\Program Files\WG5GGMA19I\WG5GGMA19.exe','32');
DeleteFile('C:\Program Files\B3WH0CT236\B3WH0CT23.exe','32');
DeleteFile('C:\Program Files\YWPEUF3BBU\YWPEUF3BB.exe','32');
DeleteFile('C:\Program Files\3Z1OHZD0EB\3Z1OHZD0E.exe','32');
DeleteFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Zaxar');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','HMYXWZ34X9');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','PCZ97QLI0T');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','PTJ770BMZ9');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','5YHBS2Y50Y');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','A0M9RB4N3N');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','S9LYBZ7DS4');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','4AIW1C6JCU');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','H45X58AIRV');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','EGM2PAURIY');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','FGNAYD7F89');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Archer\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\GubedZL\Parameters','ServiceDll');
DeleteFile('C:\Users\User\AppData\Roaming\WinSnare\WinSnare.dll','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\WinSnare\Parameters','ServiceDll');
DeleteFile('C:\Program Files (x86)\Fughlaserther\ralition.exe','32');
DeleteFile('C:\ProgramData\Hotfresh\Zimfan.reg','32');
DeleteFile('C:\ProgramData\Hotfresh\FunTom.reg','32');
DeleteFile('C:\ProgramData\Hotfresh\Itgofresh.reg','32');
DeleteFile('C:\Windows\system32\Tasks\psv_Ozerhome','64');
DeleteFile('C:\Windows\system32\Tasks\psv_Rephase','64');
DeleteFile('C:\Windows\system32\Tasks\psv_Zumnix','64');
DeleteFile('C:\Windows\system32\Tasks\Stofynedent Reports','64');
DeleteFile('C:\Windows\system32\Tasks\TaskSched','64');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.