Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\User\appdata\local\filterstart\filterstart.exe','');
QuarantineFile('C:\Windows\Manager.exe','');
QuarantineFile('C:\ProgramData\VideoMemoryDiagnostic\vmdiag.exe','');
QuarantineFile('C:\Program Files\GimigaBook Magic\GimigaBook Magic.dll','');
QuarantineFile('C:\Program Files (x86)\Shufward\yaupdcache.exe','');
QuarantineFile('C:\Program Files (x86)\Nomitain Adapter\local64spl.dll','');
DelBHO('{E3605470-291B-44EB-8648-745EE356599A}');
DelBHO('{526FF2DD-4F5A-03EC-8FFC-BD6B1CF42BBD}');
QuarantineFile('C:\Program Files (x86)\v01PassShow\174.dll','');
QuarantineFile('C:\Users\User\AppData\Roaming\gplyra\gplyra\start.cmd','');
QuarantineFile('C:\Windows\SysWow64\Auhardwaregl.dll','');
QuarantineFile('C:\WINDOWS\system32\drivers\Uefochubsrv.sys','');
SetServiceStart('Uefochubsrv', 4);
DeleteService('Uefochubsrv');
SetServiceStart('mwescontroller', 4);
SetServiceStart('LanmaMaster', 4);
DeleteService('LanmaMaster');
DeleteService('mwescontroller');
QuarantineFile('C:\WINDOWS\system32\drivers\lanmamaster.sys','');
SetServiceStart('0f7084c208ac7ccf70c142d6fa3b90d3', 4);
SetServiceStart('JszipProtect', 4);
DeleteService('JszipProtect');
DeleteService('0f7084c208ac7ccf70c142d6fa3b90d3');
SetServiceStart('mweshield', 4);
SetServiceStart('mweshieldup', 4);
DeleteService('mweshieldup');
DeleteService('mweshield');
SetServiceStart('JszipService', 4);
SetServiceStart('MaskitService', 4);
DeleteService('MaskitService');
DeleteService('JszipService');
SetServiceStart('AVPlayerUpdater', 4);
DeleteService('AVPlayerUpdater');
SetServiceStart('ab4f45ff424da6b099946551446f52bd', 4);
DeleteService('ab4f45ff424da6b099946551446f52bd');
QuarantineFile('C:\Program Files (x86)\v01PassShow\v01PassShowjK174.dll','');
QuarantineFile('C:\Program Files (x86)\YoutubeAdBlockIE\kpvIj5G.dll','');
QuarantineFile('C:\Program Files (x86)\YoutubeAdBlockIE\StzT8Uj.dll','');
QuarantineFile('C:\Program Files (x86)\Maoha\JiSuZip\zipUpdater\ZipUpdate.dll','');
QuarantineFile('C:\Program Files (x86)\Maoha\JiSuZip\zipSubmit\ZipSubmit.dll','');
QuarantineFile('C:\Program Files (x86)\Maoha\JiSuZip\ZipPlug.dll','');
QuarantineFile('C:\Program Files (x86)\Maoha\JiSuZip\tipsdll.dll','');
QuarantineFile('C:\Program Files (x86)\Maoha\JiSuZip\substatEx.dll','');
QuarantineFile('C:\Program Files (x86)\Maoha\JiSuZip\substat.dll','');
QuarantineFile('C:\Program Files (x86)\Maoha\JiSuZip\CheckUpdate.dll','');
TerminateProcessByName('c:\program files (x86)\zaxar\zaxarloader.exe');
TerminateProcessByName('c:\program files (x86)\zaxar\zaxargamebrowser.exe');
TerminateProcessByName('c:\program files (x86)\yeadesktop\yeadesktop.exe');
TerminateProcessByName('C:\Program Files\YBLH0K6AQD\YBLH0K6AQ.exe');
TerminateProcessByName('C:\Program Files\R33F7KO6OF\Y7R17NLQI.exe');
TerminateProcessByName('c:\program files (x86)\v01passshow\v01passshowjk174.exe');
TerminateProcessByName('C:\Program Files\UIG6KUB3GX\UIG6KUB3G.exe');
QuarantineFile('c:\program files (x86)\zaxar\zaxarloader.exe','');
QuarantineFile('c:\program files (x86)\zaxar\zaxargamebrowser.exe','');
QuarantineFile('c:\program files (x86)\yeadesktop\yeadesktop.exe','');
QuarantineFile('C:\Program Files\YBLH0K6AQD\YBLH0K6AQ.exe','');
QuarantineFile('C:\Program Files\R33F7KO6OF\Y7R17NLQI.exe','');
QuarantineFile('c:\program files (x86)\v01passshow\v01passshowjk174.exe','');
QuarantineFile('C:\Program Files\UIG6KUB3GX\UIG6KUB3G.exe','');
TerminateProcessByName('c:\program files (x86)\plantronics\spokes3g\spokesupdateservice.exe');
TerminateProcessByName('c:\users\user\appdata\local\temp\is-ge5ek.tmp\oxrrufdad.tmp');
QuarantineFile('c:\program files (x86)\plantronics\spokes3g\spokesupdateservice.exe','');
QuarantineFile('c:\users\user\appdata\local\temp\is-ge5ek.tmp\oxrrufdad.tmp','');
TerminateProcessByName('C:\Program Files\OAZ7IMXGJI\OAZ7IMXGJ.exe');
TerminateProcessByName('c:\users\user\appdata\local\temp\y8nf8zuem\oxrrufdad.exe');
QuarantineFile('C:\Program Files\OAZ7IMXGJI\OAZ7IMXGJ.exe','');
QuarantineFile('c:\users\user\appdata\local\temp\y8nf8zuem\oxrrufdad.exe','');
TerminateProcessByName('C:\Program Files\My Web Shield\mweshieldup.exe');
TerminateProcessByName('C:\Program Files\My Web Shield\mweshield.exe');
QuarantineFile('C:\Program Files\My Web Shield\mweshieldup.exe','');
QuarantineFile('C:\Program Files\My Web Shield\mweshield.exe','');
QuarantineFile('c:\program files (x86)\mail.ru\update service\mrupdsrv.exe','');
TerminateProcessByName('c:\program files (x86)\youtubeadblockie\mqj_yy6m.exe');
TerminateProcessByName('C:\Program Files (x86)\Maskit\MaskitService.exe');
TerminateProcessByName('C:\Program Files (x86)\Maskit\Maskit.exe');
QuarantineFile('c:\program files (x86)\youtubeadblockie\mqj_yy6m.exe','');
QuarantineFile('C:\Program Files (x86)\Maskit\MaskitService.exe','');
QuarantineFile('C:\Program Files (x86)\Maskit\Maskit.exe','');
TerminateProcessByName('C:\Program Files\CHWKLEMG2F\KKK6LHIZW.exe');
TerminateProcessByName('c:\program files (x86)\maoha\jisuzip\jszipsvc.exe');
TerminateProcessByName('C:\Program Files (x86)\uh0mlcevq3m\JSXI0RHSL9BSWFE.exe');
TerminateProcessByName('C:\Program Files\J7D6KKKSS9\J7D6KKKSS.exe');
TerminateProcessByName('C:\Program Files\GU543V5PC2\GU543V5PC.exe');
TerminateProcessByName('c:\users\user\appdata\roaming\gplyra\gplyra\gplyra.exe');
QuarantineFile('C:\Program Files\J7D6KKKSS9\J7D6KKKSS.exe','');
QuarantineFile('C:\Program Files (x86)\uh0mlcevq3m\JSXI0RHSL9BSWFE.exe','');
QuarantineFile('c:\program files (x86)\maoha\jisuzip\jszipsvc.exe','');
QuarantineFile('C:\Program Files\CHWKLEMG2F\KKK6LHIZW.exe','');
QuarantineFile('C:\Program Files\GU543V5PC2\GU543V5PC.exe','');
QuarantineFile('c:\users\user\appdata\roaming\gplyra\gplyra\gplyra.exe','');
TerminateProcessByName('C:\Windows\Temp\gCF19.tmp.exe');
TerminateProcessByName('C:\Windows\Temp\gA0D3.tmp.exe');
QuarantineFile('C:\Windows\Temp\gCF19.tmp.exe','');
QuarantineFile('C:\Windows\Temp\gA0D3.tmp.exe','');
TerminateProcessByName('C:\Windows\Temp\g1185.tmp.exe');
QuarantineFile('C:\Windows\Temp\g1185.tmp.exe','');
TerminateProcessByName('C:\Users\User\AppData\Local\Temp\UVKM4JDFL2\DimaMawjoudin.exe');
QuarantineFile('C:\Users\User\AppData\Local\Temp\UVKM4JDFL2\DimaMawjoudin.exe','');
TerminateProcessByName('C:\Program Files\NYOVL4Y7S7\DC1P13A9R.exe');
QuarantineFile('C:\Program Files\NYOVL4Y7S7\DC1P13A9R.exe','');
TerminateProcessByName('C:\Program Files\C1VV0ZLUWE\C1VV0ZLUW.exe');
QuarantineFile('C:\Program Files\C1VV0ZLUWE\C1VV0ZLUW.exe','');
QuarantineFile('c:\program files (x86)\av\avplayer\avplayerupdater.exe','');
TerminateProcessByName('C:\Program Files\4MITE1KBZ6\4MITE1KBZ.exe');
QuarantineFile('C:\Program Files\4MITE1KBZ6\4MITE1KBZ.exe','');
TerminateProcessByName('C:\Program Files\3AHZTULAOA\3AHZTULAO.exe');
QuarantineFile('C:\Program Files\3AHZTULAOA\3AHZTULAO.exe','');
TerminateProcessByName('c:\program files\ab4f45ff424da6b099946551446f52bd\07bfd36faadaf37e76d128589d76b92d.exe');
QuarantineFile('c:\program files\ab4f45ff424da6b099946551446f52bd\07bfd36faadaf37e76d128589d76b92d.exe','');
DeleteFile('c:\program files\ab4f45ff424da6b099946551446f52bd\07bfd36faadaf37e76d128589d76b92d.exe','32');
DeleteFile('C:\Program Files\3AHZTULAOA\3AHZTULAO.exe','32');
DeleteFile('C:\Program Files\4MITE1KBZ6\4MITE1KBZ.exe','32');
DeleteFile('C:\Program Files\C1VV0ZLUWE\C1VV0ZLUW.exe','32');
DeleteFile('C:\Program Files\NYOVL4Y7S7\DC1P13A9R.exe','32');
DeleteFile('C:\Users\User\AppData\Local\Temp\UVKM4JDFL2\DimaMawjoudin.exe','32');
DeleteFile('C:\Windows\Temp\g1185.tmp.exe','32');
DeleteFile('C:\Windows\Temp\gCF19.tmp.exe','32');
DeleteFile('C:\Windows\Temp\gA0D3.tmp.exe','32');
DeleteFile('C:\Program Files\J7D6KKKSS9\J7D6KKKSS.exe','32');
DeleteFile('C:\Program Files (x86)\uh0mlcevq3m\JSXI0RHSL9BSWFE.exe','32');
DeleteFile('c:\program files (x86)\maoha\jisuzip\jszipsvc.exe','32');
DeleteFile('C:\Program Files\CHWKLEMG2F\KKK6LHIZW.exe','32');
DeleteFile('C:\Program Files\GU543V5PC2\GU543V5PC.exe','32');
DeleteFile('c:\users\user\appdata\roaming\gplyra\gplyra\gplyra.exe','32');
DeleteFile('c:\program files (x86)\youtubeadblockie\mqj_yy6m.exe','32');
DeleteFile('C:\Program Files (x86)\Maskit\MaskitService.exe','32');
DeleteFile('C:\Program Files (x86)\Maskit\Maskit.exe','32');
DeleteFile('C:\Program Files\My Web Shield\mweshieldup.exe','32');
DeleteFile('C:\Program Files\My Web Shield\mweshield.exe','32');
DeleteFile('C:\Program Files\OAZ7IMXGJI\OAZ7IMXGJ.exe','32');
DeleteFile('c:\users\user\appdata\local\temp\y8nf8zuem\oxrrufdad.exe','32');
DeleteFile('c:\program files (x86)\plantronics\spokes3g\spokesupdateservice.exe','32');
DeleteFile('c:\users\user\appdata\local\temp\is-ge5ek.tmp\oxrrufdad.tmp','32');
DeleteFile('c:\program files (x86)\zaxar\zaxarloader.exe','32');
DeleteFile('c:\program files (x86)\zaxar\zaxargamebrowser.exe','32');
DeleteFile('c:\program files (x86)\yeadesktop\yeadesktop.exe','32');
DeleteFile('C:\Program Files\YBLH0K6AQD\YBLH0K6AQ.exe','32');
DeleteFile('C:\Program Files\R33F7KO6OF\Y7R17NLQI.exe','32');
DeleteFile('c:\program files (x86)\v01passshow\v01passshowjk174.exe','32');
DeleteFile('C:\Program Files\UIG6KUB3GX\UIG6KUB3G.exe','32');
DeleteFile('C:\Program Files (x86)\Maoha\JiSuZip\CheckUpdate.dll','32');
DeleteFile('C:\Program Files (x86)\Maoha\JiSuZip\substat.dll','32');
DeleteFile('C:\Program Files (x86)\Maoha\JiSuZip\substatEx.dll','32');
DeleteFile('C:\Program Files (x86)\Maoha\JiSuZip\tipsdll.dll','32');
DeleteFile('C:\Program Files (x86)\Maoha\JiSuZip\ZipPlug.dll','32');
DeleteFile('C:\Program Files (x86)\Maoha\JiSuZip\zipSubmit\ZipSubmit.dll','32');
DeleteFile('C:\Program Files (x86)\Maoha\JiSuZip\zipUpdater\ZipUpdate.dll','32');
DeleteFile('C:\Program Files (x86)\YoutubeAdBlockIE\StzT8Uj.dll','32');
DeleteFile('C:\Program Files (x86)\YoutubeAdBlockIE\kpvIj5G.dll','32');
DeleteFile('C:\Program Files (x86)\AV\AVPlayer\AVPlayerUpdater.exe','32');
DeleteFile('C:\WINDOWS\system32\drivers\Uefochubsrv.sys','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','YeaDesktop');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','h3cyiqqlzfv');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','TGOS9HQ3WKD3SL3');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ler4aeewj5v');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','MailRuUpdater');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','lthsuqrqbku');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','NC5UVDHH0ZSAU1E');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','01C93DNIZWKSUDL');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','mgrdrmjbnai');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','1c15l2oei2g');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','GJGN40D5GEKX7OB');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','G24I20C28HPTR0J');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','5kmwtuy4lgj');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','RL334I8WHVCV02S');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','vhqjl0nptaz');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','irnqbcljw1c');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','JBJJUQZEMYSES0L');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','LLIH6G7R8Z3HQPM');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','o5u1p0jjlnm');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','FLDCSXCOIU2CUL5');
DeleteFile('C:\Windows\SysWow64\Auhardwaregl.dll','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Auhardwaregl\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\JszipService\Parameters','ServiceDll');
DeleteFile('C:\Users\User\AppData\Roaming\gplyra\gplyra\start.cmd','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','OMEWPRODUCT_0LOC0');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gplyra');
DeleteFile('C:\Program Files (x86)\v01PassShow\174.dll','32');
DeleteFile('C:\Program Files (x86)\Nomitain Adapter\local64spl.dll','32');
DeleteFile('C:\Program Files (x86)\Shufward\yaupdcache.exe','32');
DeleteFile('C:\Program Files\GimigaBook Magic\GimigaBook Magic.dll','32');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\DeviceSettings\Stsightserqght','64');
DeleteFile('C:\WINDOWS\system32\Tasks\MaskitAutorun','64');
DeleteFile('C:\WINDOWS\system32\Tasks\GimigaBook Magic','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Btickmerjuing Log','64');
DeleteFile('C:\ProgramData\VideoMemoryDiagnostic\vmdiag.exe','32');
DeleteFile('C:\Windows\Manager.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\MemoryDiagnostic\VideoMemoryDiagnostic','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\Multimedia\Manager','64');
DeleteFile('C:\WINDOWS\system32\Tasks\{0D0C0D47-097F-0D7A-7D11-087E08781109}','64');
DeleteFile('C:\WINDOWS\system32\Tasks\{0F8C226D-7E80-45C6-B39B-AF2A29F6EDEE}','64');
DeleteFile('C:\Users\User\appdata\local\filterstart\filterstart.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.