Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
StopService('4f94fc9976000211');
StopService('4f94f95085abe391');
StopService('4f94c838e7761c91');
StopService('4F947C378448E472');
StopService('46e7dd3aa9a93a91');
StopService('46e7dd39b3702c91');
StopService('46e77e1ec946fb91');
StopService('NzM3ZWNjNWNk');
StopService('Polygen');
StopService('4F96FCC3F7F5D872');
StopService('NGYzZGNjY');
StopService('ODhjODQ3YjNlZ');
DeleteService('ODhjODQ3YjNlZ');
DeleteService('NGYzZGNjY');
DeleteService('4f94fc9976000211');
DeleteService('4F96FCC3F7F5D872');
DeleteService('4f94f95085abe391');
DeleteService('4f94c838e7761c91');
DeleteService('4F947C378448E472');
DeleteService('46e7dd3aa9a93a91');
DeleteService('46e7dd39b3702c91');
DeleteService('46e77e1ec946fb91');
DeleteService('NzM3ZWNjNWNk');
DeleteService('Polygen');
QuarantineFile('C:\Windows\TEMP\31fb222.sys','');
QuarantineFile('C:\Windows\TEMP\336d55d.sys','');
QuarantineFile('C:\Windows\TEMP\3c389eb.sys','');
QuarantineFile('C:\Windows\TEMP\3B02C21.sys','');
QuarantineFile('C:\Users\Lee\appdata\local\temp\csrss\cloudnet.exe','');
QuarantineFile('C:\Users\Lee\AppData\Local\Temp\QWDLQEfXvxWAmuRrS\cVpvxnNrNAGuQkug\EcmHERs.dll','');
QuarantineFile('C:\Program Files (x86)\fgjCMzHQYvabC\MUHihtA.dll','');
QuarantineFile('C:\Program Files (x86)\jZorInLLanAU2\PZiVTyDvRwWqV.dll','');
QuarantineFile('C:\Program Files (x86)\ymquwutTLCSFsEIPnQR\hMDJOoT.dll','');
QuarantineFile('C:\ProgramData\hwwc\oatp.exe','');
QuarantineFile('C:\Program Files (x86)\Common Files\Adobe\OOBA\PDApp\PPAPI\D114348F-CAFF-4F37-8CE9-255D6A45AA95.exe','');
QuarantineFile('C:\Users\Lee\AppData\Local\Temp\QWDLQEfXvxWAmuRrS\AVoaxodYrMizORJQ\MdWNOGd.dll','');
QuarantineFile('C:\Program Files (x86)\ZmyMStEpU\ZVyvwq.dll','');
QuarantineFile('C:\Users\Lee\AppData\Local\Temp\QWDLQEfXvxWAmuRrS\WrAExWnUntzYMZqg\nWiiqQZ.dll','');
QuarantineFile('C:\Users\Lee\AppData\Local\Temp\QWDLQEfXvxWAmuRrS\uezCIfrQjdkvpRgA\TpfCYQG.dll','');
QuarantineFile('C:\ProgramData\FLUHMPFFUhaIYeVB\WimEpiD.wsf','');
QuarantineFile('C:\Users\Lee\AppData\Local\Temp\5oqy4e11.2zc\nuwpqicunde.exe','');
QuarantineFile('C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe','');
QuarantineFile('C:\Program Files (x86)\OneSystemCare\CleanupConsole.exe','');
QuarantineFile('C:\Users\Lee\AppData\Roaming\Microsoft\Windows\gubgreai\wvdhshuc.exe','');
QuarantineFile('C:\Program Files\Bonjour\XERTWACZ\+2neH4uIW.exe','');
QuarantineFile('C:\Users\Lee\AppData\Roaming\AutoHot.exe','');
QuarantineFile('C:\Program Files\WWBLZFJPK7\OA02YS4XW.exe','');
QuarantineFile('C:\Users\Lee\AppData\Roaming\h0vgu4cpfaa\owsdxtai3wj.exe','');
QuarantineFile('C:\Users\Lee\AppData\Roaming\v232gtfd0jl\fvbuc13nxi5.exe','');
QuarantineFile('C:\Users\Lee\AppData\Roaming\mlk4ljpjvck\k2wjeokp01j.exe','');
QuarantineFile('C:\Program Files\THMH068PAM\THMH068PA.exe','');
QuarantineFile('C:\Users\Lee\AppData\Roaming\n0dhmgigb4l\roehmh0te4x.exe','');
QuarantineFile('C:\Users\Lee\AppData\Roaming\iudqrhwcpez\l0zxqgahg2p.exe','');
QuarantineFile('C:\Users\Lee\AppData\Roaming\sfrawdklqqa\aa0hnbsuphg.exe','');
QuarantineFile('C:\Program Files\21CH30XYY3\SFQBJY90X.exe','');
QuarantineFile('C:\Users\Lee\AppData\Roaming\kn1tbtdss24\5aw0whrz14y.exe','');
QuarantineFile('C:\Program Files\6ZKVLCQL6F\6ZKVLCQL6.exe','');
QuarantineFile('C:\Users\Lee\AppData\Roaming\shp2ts3fttk\de2gwcyfeqv.exe','');
QuarantineFile('C:\Program Files (x86)\ShutdownTime\B8SZD.exe','');
QuarantineFile('C:\Windows\rss\csrss.exe','');
QuarantineFile('C:\Program Files\Bonjour\XERTWACZ\G4-7gSmkoC.exe','');
QuarantineFile('C:\Windows\TEMP\5580298.sys','');
QuarantineFile('C:\Windows\TEMP\38f75e1.sys','');
QuarantineFile('C:\Windows\TEMP\10c9c87b.sys','');
QuarantineFile('C:\Windows\TEMP\44b7f64.sys','');
QuarantineFile('C:\ProgramData\Polygen\Polygen.exe','');
QuarantineFile('C:\Windows\hqwkxqxku.hqwk','');
QuarantineFile('C:\Program Files\NGYzZGNjY\M2Q4Yzg5.exe','');
QuarantineFile('C:\Windows\system32\drivers\NzM3ZWNjNWNk','');
DeleteFile('C:\Windows\system32\drivers\NzM3ZWNjNWNk','32');
DeleteFile('C:\Program Files\NGYzZGNjY\M2Q4Yzg5.exe','32');
DeleteFile('C:\Windows\hqwkxqxku.hqwk','32');
DeleteFile('C:\ProgramData\Polygen\Polygen.exe','32');
DeleteFile('C:\Windows\TEMP\31fb222.sys','32');
DeleteFile('C:\Windows\TEMP\3c389eb.sys','32');
DeleteFile('C:\Windows\TEMP\336d55d.sys','32');
DeleteFile('C:\Windows\TEMP\3B02C21.sys','32');
DeleteFile('C:\Windows\TEMP\44b7f64.sys','32');
DeleteFile('C:\Windows\TEMP\10c9c87b.sys','32');
DeleteFile('C:\Windows\TEMP\38f75e1.sys','32');
DeleteFile('C:\Windows\TEMP\5580298.sys','32');
DeleteFile('C:\Program Files\Bonjour\XERTWACZ\G4-7gSmkoC.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','G4-7gSmkoC.exe');
DeleteFile('C:\Windows\rss\csrss.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','DarkSmoke');
DeleteFile('C:\Program Files (x86)\ShutdownTime\B8SZD.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Q80YUA2AXAKRR2X');
DeleteFile('C:\Users\Lee\AppData\Roaming\shp2ts3fttk\de2gwcyfeqv.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','5274991');
DeleteFile('C:\Program Files\6ZKVLCQL6F\6ZKVLCQL6.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','7E2CAC84HNZGZUW');
DeleteFile('C:\Users\Lee\AppData\Roaming\kn1tbtdss24\5aw0whrz14y.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','7095793');
DeleteFile('C:\Program Files\21CH30XYY3\SFQBJY90X.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','EBAAYTID8Y1X8IV');
DeleteFile('C:\Users\Lee\AppData\Roaming\sfrawdklqqa\aa0hnbsuphg.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','1661132');
DeleteFile('C:\Users\Lee\AppData\Roaming\iudqrhwcpez\l0zxqgahg2p.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','7499651');
DeleteFile('C:\Users\Lee\AppData\Roaming\n0dhmgigb4l\roehmh0te4x.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','8924005');
DeleteFile('C:\Program Files\THMH068PAM\THMH068PA.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','SKX3KJHGPGIJS4V');
DeleteFile('C:\Users\Lee\AppData\Roaming\mlk4ljpjvck\k2wjeokp01j.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','6047265');
DeleteFile('C:\Users\Lee\AppData\Roaming\v232gtfd0jl\fvbuc13nxi5.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','7520852');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','6086659');
DeleteFile('C:\Users\Lee\AppData\Roaming\h0vgu4cpfaa\owsdxtai3wj.exe','32');
DeleteFile('C:\Program Files\WWBLZFJPK7\OA02YS4XW.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','M1H594A2FZIRE2Z');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','AutoHot');
DeleteFile('C:\Users\Lee\AppData\Roaming\AutoHot.exe','32');
DeleteFile('C:\Program Files\Bonjour\XERTWACZ\+2neH4uIW.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','OMEWPRODUCT_');
DeleteFile('C:\Users\Lee\AppData\Roaming\Microsoft\Windows\gubgreai\wvdhshuc.exe','32');
DeleteFile('C:\Windows\system32\Tasks\0df3c455-b187-43dd-b00f-a2a81e39980b','64');
DeleteFile('C:\Windows\system32\Tasks\5eac9a62-35d7-45da-b1fb-97ba8a615ec2','64');
DeleteFile('C:\Windows\system32\Tasks\bkuqnscFZylvqmexnhO','64');
DeleteFile('C:\Users\Lee\AppData\Local\Temp\5oqy4e11.2zc\nuwpqicunde.exe','32');
DeleteFile('C:\Windows\system32\Tasks\csrss','64');
DeleteFile('C:\Windows\system32\Tasks\isnTCxiiubcWC2','64');
DeleteFile('C:\ProgramData\FLUHMPFFUhaIYeVB\WimEpiD.wsf','32');
DeleteFile('C:\Users\Lee\AppData\Local\Temp\QWDLQEfXvxWAmuRrS\uezCIfrQjdkvpRgA\TpfCYQG.dll','32');
DeleteFile('C:\Windows\system32\Tasks\KDndQRhvXInxjgs','64');
DeleteFile('C:\Windows\system32\Tasks\kliLCwTXYuNzVgC','64');
DeleteFile('C:\Users\Lee\AppData\Local\Temp\QWDLQEfXvxWAmuRrS\WrAExWnUntzYMZqg\nWiiqQZ.dll','32');
DeleteFile('C:\Windows\system32\Tasks\lJeggdxuwgsvqjY2','64');
DeleteFile('C:\Program Files (x86)\ZmyMStEpU\ZVyvwq.dll','32');
DeleteFile('C:\Users\Lee\AppData\Local\Temp\QWDLQEfXvxWAmuRrS\AVoaxodYrMizORJQ\MdWNOGd.dll','32');
DeleteFile('C:\Windows\system32\Tasks\mbMrtaHyHZVrxOz','64');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\AAFF56502-9185-4D64-BD21-34F75315A4FA','64');
DeleteFile('C:\Program Files (x86)\Common Files\Adobe\OOBA\PDApp\PPAPI\D114348F-CAFF-4F37-8CE9-255D6A45AA95.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Opera scheduled Autoupdate 2796787680','64');
DeleteFile('C:\ProgramData\hwwc\oatp.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Test Task17','64');
DeleteFile('C:\Windows\system32\Tasks\uMCVFMgBPnUfqKhAu2','64');
DeleteFile('C:\Program Files (x86)\ymquwutTLCSFsEIPnQR\hMDJOoT.dll','32');
DeleteFile('C:\Program Files (x86)\jZorInLLanAU2\PZiVTyDvRwWqV.dll','32');
DeleteFile('C:\Windows\system32\Tasks\vQFwkeKiyKCbWN','64');
DeleteFile('C:\Windows\system32\Tasks\wXssEMehiSxnfiwuTsl2','64');
DeleteFile('C:\Program Files (x86)\fgjCMzHQYvabC\MUHihtA.dll','32');
DeleteFile('C:\Users\Lee\AppData\Local\Temp\QWDLQEfXvxWAmuRrS\cVpvxnNrNAGuQkug\EcmHERs.dll','32');
DeleteFile('C:\Windows\system32\Tasks\ZFvgHCXQLqXZUGp','64');
DeleteFile('C:\Windows\system32\Tasks\{1A043F83-62C2-4031-937D-E3121640D8DF}','64');
DeleteFile('C:\Users\Lee\appdata\local\temp\csrss\cloudnet.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(1);
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
После выполнения скрипта компьютер перезагрузится.