Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\User\appdata\roaming\freevpn\freevpn.exe','');
DelBHO('{96AF5545-BC30-4E5D-8E36-836D000A1455}');
DelBHO('{E4625B55-9401-4B40-B5BA-9134A41BFAA0}');
QuarantineFile('C:\Users\User\AppData\Roaming\System\svchost.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\CurrencyConvertor\ml.py','');
QuarantineFile('C:\Users\User\AppData\Roaming\setupsk\ml.py','');
QuarantineFile('C:\Users\User\AppData\Roaming\SafeWeb\ml.py','');
QuarantineFile('C:\Users\User\AppData\Roaming\vofer\ml.py','');
QuarantineFile('C:\Users\User\AppData\Roaming\ForceUpdateVOF\ml.py','');
QuarantineFile('C:\Users\User\AppData\Roaming\Docat\ml.py','');
QuarantineFile('C:\Users\User\AppData\Roaming\VOF\ml.py','');
QuarantineFile('C:\Users\User\AppData\Roaming\ONSALE~1\ml.py','');
QuarantineFile('C:\Users\User\AppData\Roaming\PBot\launchall.py','');
TerminateProcessByName('c:\users\user\appdata\local\yc\application\yc.exe');
TerminateProcessByName('C:\Windows\Microsoft\svchost.exe.exe');
QuarantineFile('C:\Windows\Microsoft\svchost.exe.exe','');
TerminateProcessByName('c:\windows\microsoft\svchost.exe');
QuarantineFile('c:\windows\microsoft\svchost.exe','');
TerminateProcessByName('c:\users\user\appdata\local\temp\e3a8.tmp.exe');
TerminateProcessByName('c:\users\user\appdata\local\filesystemdriver\filesystemdriver.exe');
TerminateProcessByName('C:\Windows\System32\icacl.exe');
QuarantineFile('C:\Windows\System32\icacl.exe','');
QuarantineFile('c:\users\user\appdata\local\temp\e3a8.tmp.exe','');
QuarantineFile('c:\users\user\appdata\local\filesystemdriver\filesystemdriver.exe','');
TerminateProcessByName('c:\users\user\appdata\local\amigo\application\amigo.exe');
TerminateProcessByName('C:\Users\User\AppData\Local\Temp\49CB.tmp.exe');
QuarantineFile('C:\Users\User\AppData\Local\Temp\49CB.tmp.exe','');
DeleteFile('C:\Users\User\AppData\Local\Temp\49CB.tmp.exe','32');
DeleteFile('c:\users\user\appdata\local\amigo\application\amigo.exe','32');
DeleteFile('c:\users\user\appdata\local\filesystemdriver\filesystemdriver.exe','32');
DeleteFile('c:\users\user\appdata\local\temp\e3a8.tmp.exe','32');
DeleteFile('C:\Windows\System32\icacl.exe','32');
DeleteFile('c:\windows\microsoft\svchost.exe','32');
DeleteFile('C:\Windows\Microsoft\svchost.exe.exe','32');
DeleteFile('c:\users\user\appdata\local\yc\application\yc.exe','32');
DeleteFile('C:\Users\User\AppData\Roaming\PBot\launchall.py','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','PBot');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','jcdunydxst');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','SafeWeb');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ForceUpdateVOF');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','vofer');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','onsaleprofit');
DeleteFile('C:\Users\User\AppData\Roaming\ONSALE~1\ml.py','32');
DeleteFile('C:\Users\User\AppData\Roaming\VOF\ml.py','32');
DeleteFile('C:\Users\User\AppData\Roaming\Docat\ml.py','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Docat');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','VOF');
DeleteFile('C:\Users\User\AppData\Roaming\ForceUpdateVOF\ml.py','32');
DeleteFile('C:\Users\User\AppData\Roaming\vofer\ml.py','32');
DeleteFile('C:\Users\User\AppData\Roaming\SafeWeb\ml.py','32');
DeleteFile('C:\Users\User\AppData\Roaming\setupsk\ml.py','32');
DeleteFile('C:\Users\User\AppData\Roaming\CurrencyConvertor\ml.py','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','amigo');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','CurrencyConvertor');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ycAutoLaunch_E945EC6410C7CE86DF55E29C29AFA8B8');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','setupsk');
DeleteFile('C:\Users\User\AppData\Roaming\System\svchost.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\Browser Updater\Browser Updater','64');
DeleteFile('C:\WINDOWS\Tasks\ASC8_SkipUac_User.job','32');
DeleteFile('C:\WINDOWS\system32\Tasks\curl','64');
DeleteFile('C:\Users\User\AppData\Roaming\curl\curl.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\curls','64');
DeleteFile('C:\WINDOWS\system32\Tasks\CurrencyConvertor','64');
DeleteFile('C:\WINDOWS\system32\Tasks\CurrencyConvertor2','64');
DeleteFile('C:\WINDOWS\system32\Tasks\DuckGo Task','64');
DeleteFile('C:\WINDOWS\system32\Tasks\FileSystemDriver','64');
DeleteFile('C:\Users\User\appdata\roaming\freevpn\freevpn.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.