Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\дом\AppData\Local\Microsoft\Extensions\safebrowser.exe','');
QuarantineFile('C:\ProgramData\Kbupdater Utility\kbupdater-utility.exe','');
QuarantineFile('C:\Users\дом\AppData\Local\Microsoft\Extensions\extsetup.exe','');
QuarantineFile('C:\Program Files (x86)\Common Files\Distribute Application\downloader.exe','');
QuarantineFile('C:\Program Files (x86)\Common Files\Distribute Application\appdistrib.exe','');
QuarantineFile('C:\Users\дом\AppData\Roaming\SFIQYSD.exe','');
QuarantineFile('C:\Users\дом\AppData\Roaming\OPSN.exe','');
QuarantineFile('C:\Users\дом\AppData\Roaming\CPOKCZF.exe','');
QuarantineFile('C:\Users\дом\AppData\Roaming\extension\ChromeExtensionUpdater.exe','');
QuarantineFile('C:\Users\дом\AppData\Local\screentk\screentoolkit.exe','');
QuarantineFile('C:\Users\дом\AppData\Local\screentk\screentool.exe','');
QuarantineFile('C:\Users\дом\AppData\Local\screentk\screentkup.exe','');
QuarantineFile('C:\Users\дом\AppData\Local\Yandex\browser.bat','');
QuarantineFile('C:\Users\дом\AppData\Local\UpdateChecker\UpdateCheckerApp.exe','');
QuarantineFile('C:\Users\дом\AppData\Local\PriceFountain\pricefountainw.exe','');
QuarantineFile('C:\Users\дом\AppData\Local\Microsoft\Windows\toolbar.exe','');
QuarantineFile('C:\Users\дом\AppData\Local\Kometa\kometaup.exe','');
QuarantineFile('C:\Users\дом\AppData\Local\Kometa\Application\kometa.exe','');
QuarantineFile('C:\ProgramData\Schedule\timetasks.exe','');
QuarantineFile('C:\ProgramData\Program status\scheck.exe','');
QuarantineFile('C:\Program Files (x86)\baidu\windows.exe','');
QuarantineFile('C:\Program Files (x86)\f552dd4c52e3\a7d12b5975b4.exe','');
QuarantineFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe','');
QuarantineFile('C:\Windows\system32\drivers\mwiynzm4ndy1yjz.sys','');
DeleteService('mwiynzm4ndy1yjz');
QuarantineFile('C:\Program Files (x86)\Smwyyntm1ndi1zdz\mwiynzm4ndy1yjz.exe','');
QuarantineFile('C:\Windows\system32\drivers\ssnfd.sys','');
DeleteService('ssnfd');
QuarantineFile('C:\Windows\SysWOW64\lnsecsl.exe','');
DeleteService('Adobe Licensing Console');
DeleteFile('C:\Windows\SysWOW64\lnsecsl.exe','32');
DeleteFile('C:\Windows\system32\drivers\ssnfd.sys','32');
DeleteFile('C:\Program Files (x86)\Smwyyntm1ndi1zdz\mwiynzm4ndy1yjz.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mwyyntm1ndi1zdz','command');
DeleteFile('C:\Windows\system32\drivers\mwiynzm4ndy1yjz.sys','32');
DeleteFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ZaxarLoader','command');
DeleteFile('C:\Program Files (x86)\f552dd4c52e3\a7d12b5975b4.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Salus CrashMon','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\baidu','command');
DeleteFile('C:\Program Files (x86)\baidu\windows.exe','32');
DeleteFile('C:\ProgramData\Program status\scheck.exe','32');
DeleteFile('C:\ProgramData\Schedule\timetasks.exe','32');
DeleteFile('C:\Users\дом\AppData\Local\Kometa\Application\kometa.exe','32');
DeleteFile('C:\Users\дом\AppData\Local\Kometa\kometaup.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\kometaup','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KometaAutoLaunch_7038B7ABC7B5262932B15131A14C98DD','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Schedule','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\sCloudStatusCheck','command');
DeleteFile('C:\Users\дом\AppData\Local\Microsoft\Windows\toolbar.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SystemScript','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Yahoo! Search','command');
DeleteFile('C:\Users\дом\AppData\Local\PriceFountain\pricefountainw.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\pricefountainw.exe','command');
DeleteFile('C:\Users\дом\AppData\Local\UpdateChecker\UpdateCheckerApp.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UpdateChecker','command');
DeleteFile('C:\Users\дом\AppData\Local\Yandex\browser.bat','32');
DeleteFile('C:\Users\дом\AppData\Local\screentk\screentkup.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\screentkUpdater','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\screentk','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\screentoolkit.exe','command');
DeleteFile('C:\Users\дом\AppData\Local\screentk\screentool.exe','32');
DeleteFile('C:\Users\дом\AppData\Local\screentk\screentoolkit.exe','32');
DeleteFile('C:\Users\дом\AppData\Roaming\extension\ChromeExtensionUpdater.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ChromeExtensionUpdater','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\hvhodxweqp','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CMD','command');
DeleteFile('C:\Users\дом\AppData\Roaming\CPOKCZF.exe','32');
DeleteFile('C:\Users\дом\AppData\Roaming\OPSN.exe','32');
DeleteFile('C:\Users\дом\AppData\Roaming\SFIQYSD.exe','32');
DeleteFile('C:\Windows\Tasks\SFIQYSD.job','64');
DeleteFile('C:\Windows\Tasks\OPSN.job','64');
DeleteFile('C:\Windows\Tasks\CPOKCZF.job','64');
DeleteFile('C:\Windows\system32\Tasks\DoctorPC_Popup','64');
DeleteFile('C:\Windows\system32\Tasks\DoctorPC_Start','64');
DeleteFile('C:\Windows\system32\Tasks\extsetup','64');
DeleteFile('C:\Users\дом\AppData\Local\Microsoft\Extensions\extsetup.exe','32');
DeleteFile('C:\ProgramData\Kbupdater Utility\kbupdater-utility.exe','32');
DeleteFile('C:\Users\дом\AppData\Local\Microsoft\Extensions\safebrowser.exe','32');
DeleteFile('C:\Windows\system32\Tasks\{C53FEB43-E318-4347-BC5F-15BD51DF66F0}','64');
DeleteFile('C:\Windows\system32\Tasks\Safebrowser','64');
DeleteFile('C:\Windows\system32\Tasks\SystemScript','64');
DeleteFile('C:\Windows\system32\Tasks\Kbupdater Utility','64');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.