Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
QuarantineFile('C:\Users\Администратор\AppData\Local\Hostinstaller\3691913799_monster.exe','');
QuarantineFile('C:\Users\Администратор\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\123123.exe','');
QuarantineFile('C:\Users\Администратор\AppData\Roaming\RtkNGui.exe','');
QuarantineFile('C:\Program Files\rec_ua_238\rec_ua_238.exe','');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Roaming\ceeaafe.exe','');
QuarantineFile('C:\Users\Администратор\AppData\Local\Temp\4DCC.tmp.exe','');
QuarantineFile('C:\Users\836D~1\AppData\Local\Temp\4DCC.tmp.exe','');
QuarantineFile('C:\Program Files\SpaceSoundPro\idscservice.exe','');
SetServiceStart('iSafeKrnl', 4);
SetServiceStart('iSafeKrnlKit', 4);
SetServiceStart('iSafeKrnlMon', 4);
SetServiceStart('iSafeKrnlR3', 4);
DeleteService('iSafeKrnlBoot');
DeleteService('iSafeKrnlR3');
DeleteService('iSafeKrnlMon');
DeleteService('iSafeKrnlKit');
DeleteService('iSafeKrnl');
SetServiceStart('SSFK', 4);
SetServiceStart('swxjtpgxcky', 4);
SetServiceStart('wbrzbvtbph', 4);
SetServiceStart('WdMan', 4);
SetServiceStart('wocvmjlht', 4);
SetServiceStart('wucotusy', 4);
SetServiceStart('yrmnzzel', 4);
SetServiceStart('zutuzuni', 4);
SetServiceStart('bibyfitizbt', 4);
SetServiceStart('ProtectedStorageayk', 4);
SetServiceStart('SharedAccessips', 4);
DeleteService('SharedAccessips');
DeleteService('ProtectedStorageayk');
DeleteService('bibyfitizbt');
DeleteService('zutuzuni');
DeleteService('yrmnzzel');
DeleteService('wucotusy');
DeleteService('wocvmjlht');
DeleteService('WdMan');
DeleteService('wbrzbvtbph');
DeleteService('swxjtpgxcky');
DeleteService('SSFK');
SetServiceStart('name1', 4);
SetServiceStart('ndlzfeutbuu', 4);
SetServiceStart('nwrjosuq', 4);
SetServiceStart('pbczbsjgpc', 4);
SetServiceStart('plejfwtc', 4);
SetServiceStart('qkseeService', 4);
SetServiceStart('rtkarcxnua', 4);
SetServiceStart('skrlsmj', 4);
DeleteService('skrlsmj');
DeleteService('rtkarcxnua');
DeleteService('qkseeService');
DeleteService('plejfwtc');
DeleteService('pbczbsjgpc');
DeleteService('nwrjosuq');
DeleteService('ndlzfeutbuu');
DeleteService('name1');
SetServiceStart('btjmxiuojv', 4);
SetServiceStart('etdmfhtylb', 4);
SetServiceStart('fmkjkwr', 4);
SetServiceStart('ggdkshzaamn', 4);
SetServiceStart('gyjmmtshk', 4);
SetServiceStart('havvifcype', 4);
SetServiceStart('iitwqms', 4);
SetServiceStart('kiciihipxn', 4);
SetServiceStart('kwgpiem', 4);
DeleteService('kwgpiem');
DeleteService('kiciihipxn');
DeleteService('iitwqms');
DeleteService('havvifcype');
DeleteService('gyjmmtshk');
DeleteService('ggdkshzaamn');
DeleteService('fmkjkwr');
DeleteService('etdmfhtylb');
DeleteService('btjmxiuojv');
QuarantineFile('C:\Program Files\Elex-tech\YAC\iSafeKrnlR3.sys','');
QuarantineFile('C:\Program Files\Elex-tech\YAC\iSafeKrnlMon.sys','');
QuarantineFile('C:\Program Files\Elex-tech\YAC\iSafeKrnlKit.sys','');
QuarantineFile('C:\Program Files\Elex-tech\YAC\iSafeKrnl.sys','');
TerminateProcessByName('c:\users\Администратор\appdata\roaming\div\cfmon.exe');
QuarantineFile('C:\Users\Администратор\AppData\Roaming\Div\AVICAP32.dll','');
TerminateProcessByName('c:\programdata\ywdmy\wdman.exe');
TerminateProcessByName('c:\windows\wocvmjlht.exe');
TerminateProcessByName('c:\users\Администратор\appdata\local\temp\x5otd.exe');
TerminateProcessByName('c:\windows\yrmnzzel.exe');
QuarantineFile('c:\windows\yrmnzzel.exe','');
QuarantineFile('c:\users\Администратор\appdata\local\temp\x5otd.exe','');
QuarantineFile('c:\windows\wocvmjlht.exe','');
QuarantineFile('c:\programdata\ywdmy\wdman.exe','');
TerminateProcessByName('c:\users\Администратор\appdata\roaming\microsoft\windows\start menu\programs\startup\system.pif');
TerminateProcessByName('c:\users\Администратор\appdata\local\gmsd_re_005010233\upgmsd_re_005010233.exe');
TerminateProcessByName('c:\windows\wbrzbvtbph.exe');
QuarantineFile('c:\windows\wbrzbvtbph.exe','');
QuarantineFile('c:\users\Администратор\appdata\local\gmsd_re_005010233\upgmsd_re_005010233.exe','');
QuarantineFile('c:\users\Администратор\appdata\roaming\microsoft\windows\start menu\programs\startup\system.pif','');
TerminateProcessByName('c:\ssyjrv\svchost.exe');
TerminateProcessByName('c:\windows\swxjtpgxcky.exe');
QuarantineFile('c:\windows\swxjtpgxcky.exe','');
QuarantineFile('c:\ssyjrv\svchost.exe','');
TerminateProcessByName('c:\program files\sfk\ssfk.exe');
TerminateProcessByName('c:\windows\skrlsmj.exe');
QuarantineFile('c:\program files\sfk\ssfk.exe','');
QuarantineFile('c:\windows\skrlsmj.exe','');
TerminateProcessByName('c:\program files\rec_ua_228\rec_ua_228.exe');
TerminateProcessByName('c:\program files\rec_ua_229\rec_ua_229.exe');
TerminateProcessByName('c:\program files\rec_ua_231\rec_ua_231.exe');
TerminateProcessByName('c:\program files\rec_ua_237\rec_ua_237.exe');
TerminateProcessByName('c:\program files\rec_ua_238\rec_ua_238.exe');
TerminateProcessByName('c:\windows\rtkarcxnua.exe');
QuarantineFile('c:\windows\rtkarcxnua.exe','');
QuarantineFile('c:\program files\rec_ua_238\rec_ua_238.exe','');
QuarantineFile('c:\program files\rec_ua_237\rec_ua_237.exe','');
QuarantineFile('c:\program files\rec_ua_231\rec_ua_231.exe','');
QuarantineFile('c:\program files\rec_ua_229\rec_ua_229.exe','');
QuarantineFile('c:\program files\rec_ua_228\rec_ua_228.exe','');
TerminateProcessByName('c:\program files\rec_ua_204\rec_ua_204.exe');
TerminateProcessByName('c:\program files\rec_ua_215\rec_ua_215.exe');
TerminateProcessByName('c:\program files\rec_ua_217\rec_ua_217.exe');
TerminateProcessByName('c:\program files\rec_ua_220\rec_ua_220.exe');
TerminateProcessByName('c:\program files\rec_ua_221\rec_ua_221.exe');
TerminateProcessByName('c:\program files\rec_ua_223\rec_ua_223.exe');
TerminateProcessByName('c:\program files\rec_ua_225\rec_ua_225.exe');
TerminateProcessByName('c:\program files\rec_ua_227\rec_ua_227.exe');
QuarantineFile('c:\program files\rec_ua_227\rec_ua_227.exe','');
QuarantineFile('c:\program files\rec_ua_225\rec_ua_225.exe','');
QuarantineFile('c:\program files\rec_ua_223\rec_ua_223.exe','');
QuarantineFile('c:\program files\rec_ua_221\rec_ua_221.exe','');
QuarantineFile('c:\program files\rec_ua_220\rec_ua_220.exe','');
QuarantineFile('c:\program files\rec_ua_217\rec_ua_217.exe','');
QuarantineFile('c:\program files\rec_ua_215\rec_ua_215.exe','');
QuarantineFile('c:\program files\rec_ua_204\rec_ua_204.exe','');
TerminateProcessByName('c:\program files\qksee\qkseesvc.exe');
QuarantineFile('c:\program files\qksee\qkseesvc.exe','');
TerminateProcessByName('c:\windows\ndlzfeutbuu.exe');
TerminateProcessByName('c:\windows\nwrjosuq.exe');
TerminateProcessByName('c:\windows\pbczbsjgpc.exe');
TerminateProcessByName('c:\windows\plejfwtc.exe');
QuarantineFile('c:\windows\plejfwtc.exe','');
QuarantineFile('c:\windows\pbczbsjgpc.exe','');
QuarantineFile('c:\windows\nwrjosuq.exe','');
QuarantineFile('c:\windows\ndlzfeutbuu.exe','');
TerminateProcessByName('c:\windows\kiciihipxn.exe');
TerminateProcessByName('c:\windows\kwgpiem.exe');
TerminateProcessByName('c:\windows\lipvniraco.exe');
QuarantineFile('c:\windows\lipvniraco.exe','');
QuarantineFile('c:\windows\kwgpiem.exe','');
QuarantineFile('c:\windows\kiciihipxn.exe','');
TerminateProcessByName('c:\program files\03000200-1455052437-0500-0006-000700080009\jnszabb5.tmp');
QuarantineFile('c:\program files\03000200-1455052437-0500-0006-000700080009\jnszabb5.tmp','');
TerminateProcessByName('c:\program files\elex-tech\yac\isafetray.exe');
QuarantineFile('c:\program files\elex-tech\yac\isafetray.exe','');
TerminateProcessByName('c:\windows\iitwqms.exe');
QuarantineFile('c:\windows\iitwqms.exe','');
TerminateProcessByName('c:\program files\03000200-1455052437-0500-0006-000700080009\hnsmcb74.tmp');
QuarantineFile('c:\program files\03000200-1455052437-0500-0006-000700080009\hnsmcb74.tmp','');
TerminateProcessByName('c:\program files\gmsd_re_005010233\gmsd_re_005010233.exe');
TerminateProcessByName('c:\windows\gyjmmtshk.exe');
TerminateProcessByName('c:\windows\havvifcype.exe');
QuarantineFile('c:\windows\havvifcype.exe','');
QuarantineFile('c:\windows\gyjmmtshk.exe','');
QuarantineFile('c:\program files\gmsd_re_005010233\gmsd_re_005010233.exe','');
TerminateProcessByName('c:\windows\fmkjkwr.exe');
TerminateProcessByName('c:\windows\ggdkshzaamn.exe');
QuarantineFile('c:\windows\ggdkshzaamn.exe','');
QuarantineFile('c:\windows\fmkjkwr.exe','');
QuarantineFile('c:\users\Администратор\appdata\roaming\div\cfmon.exe','');
TerminateProcessByName('c:\windows\etdmfhtylb.exe');
TerminateProcessByName('c:\windows\dj.exe');
QuarantineFile('c:\windows\dj.exe','');
QuarantineFile('c:\windows\etdmfhtylb.exe','');
TerminateProcessByName('c:\windows\btjmxiuojv.exe');
QuarantineFile('c:\windows\btjmxiuojv.exe','');
TerminateProcessByName('c:\users\Администратор\appdata\roaming\lolclient\local store\cache.exe');
QuarantineFile('c:\users\Администратор\appdata\roaming\lolclient\local store\cache.exe','');
DeleteFile('c:\users\Администратор\appdata\roaming\lolclient\local store\cache.exe','32');
DeleteFile('c:\windows\btjmxiuojv.exe','32');
DeleteFile('c:\windows\etdmfhtylb.exe','32');
DeleteFile('c:\windows\dj.exe','32');
DeleteFile('c:\windows\fmkjkwr.exe','32');
DeleteFile('c:\windows\ggdkshzaamn.exe','32');
DeleteFile('c:\program files\gmsd_re_005010233\gmsd_re_005010233.exe','32');
DeleteFile('c:\windows\gyjmmtshk.exe','32');
DeleteFile('c:\windows\havvifcype.exe','32');
DeleteFile('c:\program files\03000200-1455052437-0500-0006-000700080009\hnsmcb74.tmp','32');
DeleteFile('c:\windows\iitwqms.exe','32');
DeleteFile('c:\program files\elex-tech\yac\isafetray.exe','32');
DeleteFile('c:\program files\03000200-1455052437-0500-0006-000700080009\jnszabb5.tmp','32');
DeleteFile('c:\windows\kiciihipxn.exe','32');
DeleteFile('c:\windows\kwgpiem.exe','32');
DeleteFile('c:\windows\lipvniraco.exe','32');
DeleteFile('c:\windows\ndlzfeutbuu.exe','32');
DeleteFile('c:\windows\nwrjosuq.exe','32');
DeleteFile('c:\windows\pbczbsjgpc.exe','32');
DeleteFile('c:\windows\plejfwtc.exe','32');
DeleteFile('c:\program files\qksee\qkseesvc.exe','32');
DeleteFile('c:\program files\rec_ua_204\rec_ua_204.exe','32');
DeleteFile('c:\program files\rec_ua_215\rec_ua_215.exe','32');
DeleteFile('c:\program files\rec_ua_217\rec_ua_217.exe','32');
DeleteFile('c:\program files\rec_ua_220\rec_ua_220.exe','32');
DeleteFile('c:\program files\rec_ua_221\rec_ua_221.exe','32');
DeleteFile('c:\program files\rec_ua_223\rec_ua_223.exe','32');
DeleteFile('c:\program files\rec_ua_225\rec_ua_225.exe','32');
DeleteFile('c:\program files\rec_ua_227\rec_ua_227.exe','32');
DeleteFile('c:\program files\rec_ua_228\rec_ua_228.exe','32');
DeleteFile('c:\program files\rec_ua_229\rec_ua_229.exe','32');
DeleteFile('c:\program files\rec_ua_231\rec_ua_231.exe','32');
DeleteFile('c:\program files\rec_ua_237\rec_ua_237.exe','32');
DeleteFile('c:\program files\rec_ua_238\rec_ua_238.exe','32');
DeleteFile('c:\windows\rtkarcxnua.exe','32');
DeleteFile('c:\windows\skrlsmj.exe','32');
DeleteFile('c:\program files\sfk\ssfk.exe','32');
DeleteFile('c:\ssyjrv\svchost.exe','32');
DeleteFile('c:\windows\swxjtpgxcky.exe','32');
DeleteFile('c:\users\Администратор\appdata\roaming\microsoft\windows\start menu\programs\startup\system.pif','32');
DeleteFile('c:\users\Администратор\appdata\local\gmsd_re_005010233\upgmsd_re_005010233.exe','32');
DeleteFile('c:\windows\wbrzbvtbph.exe','32');
DeleteFile('c:\programdata\ywdmy\wdman.exe','32');
DeleteFile('c:\windows\wocvmjlht.exe','32');
DeleteFile('c:\users\Администратор\appdata\local\temp\x5otd.exe','32');
DeleteFile('c:\windows\yrmnzzel.exe','32');
DeleteFile('C:\Users\Администратор\AppData\Roaming\Div\AVICAP32.dll','32');
DeleteFile('c:\users\Администратор\appdata\roaming\div\cfmon.exe','32');
DeleteFile('C:\Program Files\qksee\curlpp.dll','32');
DeleteFile('C:\Program Files\qksee\zlib1.dll','32');
DeleteFile('C:\Program Files\Elex-tech\YAC\iSafeKrnl.sys','32');
DeleteFile('C:\Program Files\Elex-tech\YAC\iSafeKrnlKit.sys','32');
DeleteFile('C:\Program Files\Elex-tech\YAC\iSafeKrnlMon.sys','32');
DeleteFile('C:\Program Files\Elex-tech\YAC\iSafeKrnlR3.sys','32');
DeleteFile('C:\Program Files\SpaceSoundPro\idscservice.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','IDSCPRODUCT');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','SpaceSoundPro');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gmsd_re_005010233');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ua_204');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ua_215');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ua_217');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ua_220');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ua_221');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ua_223');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ua_225');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ua_227');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ua_228');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ua_229');
DeleteFile('C:\Users\836D~1\AppData\Local\Temp\4DCC.tmp.exe','32');
DeleteFile('C:\Users\Администратор\AppData\Local\Temp\4DCC.tmp.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','CrashReportVerifyer');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','NetworkUpdater');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ua_231');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ua_237');
DeleteFile('C:\Windows\system32\config\systemprofile\AppData\Roaming\ceeaafe.exe','32');
DeleteFile('C:\Program Files\rec_ua_238\rec_ua_238.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','upgmsd_re_005010233.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rec_ua_238');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ceeaafe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','LOLCache');
DeleteFile('C:\Users\Администратор\AppData\Roaming\RtkNGui.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','svchost.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Realtek HD Audio');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','GNU');
DeleteFile('C:\Users\Администратор\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\123123.exe','32');
DeleteFile('C:\Windows\Tasks\Update Service for Torrent Search.job','32');
DeleteFile('C:\Windows\system32\Tasks\Soft installer','32');
DeleteFile('C:\Users\Администратор\AppData\Local\Hostinstaller\3691913799_monster.exe','32');
DeleteFile('C:\Program Files\elex-tech\yac\bugreport.exe','32');
DeleteFile('C:\Program Files\elex-tech\yac\curlpp.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\feedback.exe','32');
DeleteFile('C:\Program Files\elex-tech\yac\iddmgr.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\idesk.exe','32');
DeleteFile('C:\Program Files\elex-tech\yac\idskdllpatch.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\idskdllpatch64.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\ipcdl.exe','32');
DeleteFile('C:\Program Files\elex-tech\yac\ipcproxy.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafeadfv.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafebase.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafebs.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafebugreport.exe','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafecheckengine.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafeclc.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafeclcv.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafeclean.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafeenginedisp.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafe.exe','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafekrnlcall.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafekrnlkit.sys','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafekrnlmoncall.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafekrnlmon.sys','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafekrnlr3.sys','32');
DeleteFile('C:\Program Files\elex-tech\yac\isafekrnlshell.dll','32');
DeleteFile('C:\Program Files\elex-tech\yac\uninstall.exe','32');
DeleteFile('C:\Program Files\elex-tech\yac\ssleay32.dll','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.