Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\ProgramData\ShopperPro\spbihe.js','');
QuarantineFile('C:\Program Files\iWebar\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-7.exe','');
QuarantineFile('C:\Program Files\iWebar\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-6.exe','');
QuarantineFile('C:\Program Files\iWebar\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-5.exe','');
QuarantineFile('C:\Program Files\iWebar\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-11.exe','');
QuarantineFile('C:\Program Files\iWebar\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-1-7.exe','');
QuarantineFile('C:\Program Files\iWebar\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-1-6.exe','');
QuarantineFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-7.exe','');
QuarantineFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-6.exe','');
QuarantineFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-5.exe','');
QuarantineFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-3.exe','');
QuarantineFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-11.exe','');
QuarantineFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-10.exe','');
QuarantineFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-1-7.exe','');
QuarantineFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-1-6.exe','');
QuarantineFile('C:\Program Files\Object Browser\a539210d-72fb-4df2-b238-1379c6ba9c36-7.exe','');
QuarantineFile('C:\Program Files\Object Browser\a539210d-72fb-4df2-b238-1379c6ba9c36-6.exe','');
QuarantineFile('C:\Program Files\Object Browser\a539210d-72fb-4df2-b238-1379c6ba9c36-5.exe','');
QuarantineFile('C:\Program Files\Object Browser\a539210d-72fb-4df2-b238-1379c6ba9c36-11.exe','');
QuarantineFile('C:\Program Files\Object Browser\a539210d-72fb-4df2-b238-1379c6ba9c36-1-7.exe','');
QuarantineFile('C:\Program Files\Object Browser\a539210d-72fb-4df2-b238-1379c6ba9c36-1-6.exe','');
DelBHO('{14A5E567-034B-471A-89D8-598A6A93B24B}');
DelBHO('{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}');
QuarantineFile('C:\ProgramData\ShopperPro\ShopperPro.dll','');
QuarantineFile('C:\Users\Бирута\AppData\Local\PriceFountain\pricefountainw.exe','');
QuarantineFile('C:\Users\3E78~1\AppData\Roaming\PriceFountain\UpdateProc\bkup.dat','');
QuarantineFile('C:\Users\3E78~1\AppData\Local\Temp\GPUTemp.exe','');
QuarantineFile('C:\Program Files\VLC Player GPU+\GPULog.exe','');
SetServiceStart('sysmon', 4);
DeleteService('sysmon');
SetServiceStart('SPDRIVER_1.42.1.2295', 4);
DeleteService('SPDRIVER_1.42.1.2295');
SetServiceStart('SPBIUpdd', 4);
DeleteService('SPBIUpdd');
SetServiceStart('sbmntr', 4);
DeleteService('sbmntr');
SetServiceStart('rsutils', 4);
DeleteService('rsutils');
SetServiceStart('rsdsys', 4);
DeleteService('rsdsys');
SetServiceStart('kguard', 4);
DeleteService('kguard');
DeleteService('globalUpdatem');
DeleteService('globalUpdate');
SetServiceStart('WindowsMangerProtect', 4);
DeleteService('WindowsMangerProtect');
SetServiceStart('SPBIUpd', 4);
DeleteService('SPBIUpd');
SetServiceStart('RsRavMon', 4);
DeleteService('RsRavMon');
SetServiceStart('RsMgrSvc', 4);
DeleteService('RsMgrSvc');
SetServiceStart('qidyvowo', 4);
DeleteService('qidyvowo');
SetServiceStart('hyverumu', 4);
DeleteService('hyverumu');
SetServiceStart('gopibeko', 4);
SetServiceStart('comyninu', 4);
DeleteService('comyninu');
SetServiceStart('BrsHelper', 4);
DeleteService('BrsHelper');
QuarantineFile('C:\Windows\system32\DRIVERS\sysmon.sys','');
QuarantineFile('C:\Program Files\Common Files\ShopperPro\spbiw.sys','');
QuarantineFile('C:\PROGRA~1\YTDOWN~1\sbmntr.sys','');
QuarantineFile('C:\Program Files\ShopperPro\JSDriver\1.42.1.2295\jsdrv.sys','');
QuarantineFile('C:\Program Files\globalUpdate\Update\1.3.25.0\goopdate.dll','');
TerminateProcessByName('c:\program files\common files\shopperpro\spbiu.exe');
QuarantineFile('c:\program files\common files\shopperpro\spbiu.exe','');
TerminateProcessByName('c:\users\Бирута\appdata\local\03000200-1439567589-0500-0006-000700080009\snsiedaa.tmp');
QuarantineFile('c:\users\Бирута\appdata\local\03000200-1439567589-0500-0006-000700080009\snsiedaa.tmp','');
TerminateProcessByName('c:\program files\rising\rav\rstray.exe');
TerminateProcessByName('c:\program files\rising\rsd\rsmgrsvc.exe');
TerminateProcessByName('c:\program files\rising\rav\ravmond.exe');
TerminateProcessByName('c:\programdata\swinmanpros\protectwindowsmanager.exe');
QuarantineFile('c:\programdata\swinmanpros\protectwindowsmanager.exe','');
TerminateProcessByName('c:\program files\03000200-1439545926-0500-0006-000700080009\knsdfc2.tmpfs');
QuarantineFile('c:\program files\03000200-1439545926-0500-0006-000700080009\knsdfc2.tmpfs','');
TerminateProcessByName('c:\program files\shopperpro\jsdriver\1.42.1.2295\jsdrv.exe');
QuarantineFile('c:\program files\shopperpro\jsdriver\1.42.1.2295\jsdrv.exe','');
TerminateProcessByName('c:\program files\03000200-1439545926-0500-0006-000700080009\jnsd3e66.tmp');
QuarantineFile('c:\program files\03000200-1439545926-0500-0006-000700080009\jnsd3e66.tmp','');
TerminateProcessByName('c:\program files\03000200-1439545926-0500-0006-000700080009\hnss55ed.tmp');
QuarantineFile('c:\program files\03000200-1439545926-0500-0006-000700080009\hnss55ed.tmp','');
TerminateProcessByName('c:\program files\globalupdate\update\globalupdate.exe');
QuarantineFile('c:\program files\globalupdate\update\globalupdate.exe','');
TerminateProcessByName('c:\progra~1\ytdown~1\browse~2.exe');
QuarantineFile('c:\progra~1\ytdown~1\browse~2.exe','');
TerminateProcessByName('c:\progra~1\ytdown~1\browserhelper.exe');
QuarantineFile('c:\progra~1\ytdown~1\browserhelper.exe','');
DeleteFile('c:\progra~1\ytdown~1\browserhelper.exe','32');
DeleteFile('c:\progra~1\ytdown~1\browse~2.exe','32');
DeleteFile('c:\program files\globalupdate\update\globalupdate.exe','32');
DeleteFile('c:\program files\03000200-1439545926-0500-0006-000700080009\hnss55ed.tmp','32');
DeleteFile('c:\program files\03000200-1439545926-0500-0006-000700080009\jnsd3e66.tmp','32');
DeleteFile('c:\program files\shopperpro\jsdriver\1.42.1.2295\jsdrv.exe','32');
DeleteFile('c:\program files\03000200-1439545926-0500-0006-000700080009\knsdfc2.tmpfs','32');
DeleteFile('c:\programdata\swinmanpros\protectwindowsmanager.exe','32');
DeleteFile('c:\program files\rising\rav\ravmond.exe','32');
DeleteFile('c:\program files\rising\rsd\rsmgrsvc.exe','32');
DeleteFile('c:\program files\rising\rav\rstray.exe','32');
DeleteFile('c:\users\Бирута\appdata\local\03000200-1439567589-0500-0006-000700080009\snsiedaa.tmp','32');
DeleteFile('c:\program files\common files\shopperpro\spbiu.exe','32');
DeleteFile('C:\Program Files\globalUpdate\Update\1.3.25.0\goopdate.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\antipromotionmon.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\BACore.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\boottm.dll','32');
DeleteFile('C:\PROGRAM FILES\RISING\RAV\brscan.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\cloudcom.dll','32');
DeleteFile('C:\PROGRAM FILES\RISING\RAV\cloudmp.dll','32');
DeleteFile('C:\PROGRAM FILES\RISING\RAV\cloudmpw.dll','32');
DeleteFile('C:\PROGRAM FILES\RISING\RAV\cloudnotifier.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\cloudqry.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\cloudstore.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\cloudtfc.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\cloudwork.dll','32');
DeleteFile('C:\PROGRAM FILES\RISING\RAV\CMPA.dll','32');
DeleteFile('C:\PROGRAM FILES\RISING\RAV\CMPB.DLL','32');
DeleteFile('C:\PROGRAM FILES\RISING\RAV\CMPCUsb.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\cnt09.dll','32');
DeleteFile('C:\PROGRAM FILES\RISING\RAV\commfunc.dll','32');
DeleteFile('C:\PROGRAM FILES\RISING\RAV\commrout.dll','32');
DeleteFile('C:\PROGRAM FILES\RISING\RAV\ComServ.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\defmon.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\filecent.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\filemon.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\kguard_if.dll','32');
DeleteFile('C:\PROGRAM FILES\RISING\RAV\localopt.dll','32');
DeleteFile('C:\PROGRAM FILES\RISING\RAV\logquery.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\mailmon.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\moncomm.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\mondrv.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\MonRule.dll','32');
DeleteFile('C:\PROGRAM FILES\RISING\RAV\MonTray.dll','32');
DeleteFile('C:\PROGRAM FILES\RISING\RAV\mruleui.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\pearc.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\recomp.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\refs.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\rego\methodex.dll','32');
DeleteFile('C:\Program Files\Rising\RAV\rego\revm.dll','32');
DeleteFile('C:\Windows\system32\DRIVERS\kguard.sys','32');
DeleteFile('C:\Program Files\ShopperPro\JSDriver\1.42.1.2295\jsdrv.sys','32');
DeleteFile('C:\Windows\system32\drivers\protreg.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\rsutils.sys','32');
DeleteFile('C:\PROGRA~1\YTDOWN~1\sbmntr.sys','32');
DeleteFile('C:\Program Files\Common Files\ShopperPro\spbiw.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\sysmon.sys','32');
DeleteFile('C:\Program Files\Rising\RAV\RSTRAY.EXE','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','RavTRAY');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','SPDriver');
DeleteFile('C:\Program Files\VLC Player GPU+\GPULog.exe','32');
DeleteFile('C:\Users\3E78~1\AppData\Local\Temp\GPUTemp.exe','32');
DeleteFile('C:\Users\3E78~1\AppData\Roaming\PriceFountain\UpdateProc\bkup.dat','32');
DeleteFile('C:\Users\Бирута\AppData\Local\PriceFountain\pricefountainw.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\pricefountainw.exe','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PriceFountain','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GPUTemp','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GPULoader','command');
DeleteFile('C:\Program Files\Rising\RAV\rsscrbho.dll','32');
DeleteFile('C:\ProgramData\ShopperPro\ShopperPro.dll','32');
DeleteFile('C:\Program Files\Object Browser\a539210d-72fb-4df2-b238-1379c6ba9c36-1-6.exe','32');
DeleteFile('C:\Program Files\Object Browser\a539210d-72fb-4df2-b238-1379c6ba9c36-1-7.exe','32');
DeleteFile('C:\Program Files\Object Browser\a539210d-72fb-4df2-b238-1379c6ba9c36-11.exe','32');
DeleteFile('C:\Program Files\Object Browser\a539210d-72fb-4df2-b238-1379c6ba9c36-5.exe','32');
DeleteFile('C:\Program Files\Object Browser\a539210d-72fb-4df2-b238-1379c6ba9c36-6.exe','32');
DeleteFile('C:\Program Files\Object Browser\a539210d-72fb-4df2-b238-1379c6ba9c36-7.exe','32');
DeleteFile('C:\Windows\Tasks\a539210d-72fb-4df2-b238-1379c6ba9c36-7.job','32');
DeleteFile('C:\Windows\Tasks\a539210d-72fb-4df2-b238-1379c6ba9c36-6.job','32');
DeleteFile('C:\Windows\Tasks\a539210d-72fb-4df2-b238-1379c6ba9c36-5_user.job','32');
DeleteFile('C:\Windows\Tasks\a539210d-72fb-4df2-b238-1379c6ba9c36-5.job','32');
DeleteFile('C:\Windows\Tasks\a539210d-72fb-4df2-b238-1379c6ba9c36-11.job','32');
DeleteFile('C:\Windows\Tasks\a539210d-72fb-4df2-b238-1379c6ba9c36-1-7.job','32');
DeleteFile('C:\Windows\Tasks\a539210d-72fb-4df2-b238-1379c6ba9c36-1-6.job','32');
DeleteFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-1-6.exe','32');
DeleteFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-1-7.exe','32');
DeleteFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-10.exe','32');
DeleteFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-11.exe','32');
DeleteFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-3.exe','32');
DeleteFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-5.exe','32');
DeleteFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-6.exe','32');
DeleteFile('C:\Program Files\CinemaP-1.9cV14.08\be818199-9f84-451e-b8d9-88604ee38008-7.exe','32');
DeleteFile('C:\Windows\Tasks\be818199-9f84-451e-b8d9-88604ee38008-1-6.job','32');
DeleteFile('C:\Windows\Tasks\be818199-9f84-451e-b8d9-88604ee38008-1-7.job','32');
DeleteFile('C:\Windows\Tasks\be818199-9f84-451e-b8d9-88604ee38008-10_user.job','32');
DeleteFile('C:\Windows\Tasks\be818199-9f84-451e-b8d9-88604ee38008-11.job','32');
DeleteFile('C:\Windows\Tasks\be818199-9f84-451e-b8d9-88604ee38008-3.job','32');
DeleteFile('C:\Windows\Tasks\be818199-9f84-451e-b8d9-88604ee38008-5.job','32');
DeleteFile('C:\Windows\Tasks\be818199-9f84-451e-b8d9-88604ee38008-5_user.job','32');
DeleteFile('C:\Windows\Tasks\be818199-9f84-451e-b8d9-88604ee38008-6.job','32');
DeleteFile('C:\Windows\Tasks\be818199-9f84-451e-b8d9-88604ee38008-7.job','32');
DeleteFile('C:\Program Files\iWebar\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-1-6.exe','32');
DeleteFile('C:\Program Files\iWebar\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-1-7.exe','32');
DeleteFile('C:\Program Files\iWebar\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-11.exe','32');
DeleteFile('C:\Program Files\iWebar\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-5.exe','32');
DeleteFile('C:\Program Files\iWebar\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-6.exe','32');
DeleteFile('C:\Program Files\iWebar\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-7.exe','32');
DeleteFile('C:\Windows\Tasks\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-1-6.job','32');
DeleteFile('C:\Windows\Tasks\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-1-7.job','32');
DeleteFile('C:\Windows\Tasks\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-11.job','32');
DeleteFile('C:\Windows\Tasks\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-5.job','32');
DeleteFile('C:\Windows\Tasks\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-5_user.job','32');
DeleteFile('C:\Windows\Tasks\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-6.job','32');
DeleteFile('C:\Windows\Tasks\f3c5cef1-7f22-4630-8b67-36f3b4d0d640-7.job','32');
DeleteFile('C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore1d0d677ff41cf07.job','32');
DeleteFile('C:\Windows\Tasks\Inst_Rep.job','32');
DeleteFile('C:\Windows\Tasks\Launch 22492.job','32');
DeleteFile('C:\Windows\Tasks\RsDelayLauncher_{8A34248E-7D35-4832-8378-7659E0B0A380}.job','32');
DeleteFile('C:\ProgramData\ShopperPro\spbihe.js','32');
DeleteFile('C:\Windows\Tasks\SPBIW_UpdateTask_Time_323932333530393633392d3437415a556c2a3223346c41.job','32');
DeleteFile('C:\Windows\Tasks\TeYEpPo23y.job','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.