Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\Admin\AppData\Local\FilesFrog Update Checker\update_checker.exe','');
QuarantineFile('C:\Program Files\CiPlus-4.5vV05.07\f87135f9-99e5-442e-87bd-a2848bdd7e3a-5.exe','');
QuarantineFile('C:\Program Files\CiPlus-4.5vV05.07\f87135f9-99e5-442e-87bd-a2848bdd7e3a-4.exe','');
QuarantineFile('C:\Program Files\CiPlus-4.5vV05.07\f87135f9-99e5-442e-87bd-a2848bdd7e3a-11.exe','');
QuarantineFile('C:\Program Files\CiPlus-4.5vV05.07\f87135f9-99e5-442e-87bd-a2848bdd7e3a-10.exe','');
QuarantineFile('C:\Program Files\CiPlus-4.5vV05.07\f87135f9-99e5-442e-87bd-a2848bdd7e3a-1-7.exe','');
QuarantineFile('C:\Program Files\CiPlus-4.5vV05.07\f87135f9-99e5-442e-87bd-a2848bdd7e3a-1-6.exe','');
QuarantineFile('C:\Program Files\Crossbrowse\Crossbrowse\Application\utility.exe','');
QuarantineFile('C:\Program Files\App Lid\5e105666-3823-4b38-84bd-65c2ffd59c30-5.exe','');
QuarantineFile('C:\Program Files\App Lid\5e105666-3823-4b38-84bd-65c2ffd59c30-4.exe','');
QuarantineFile('C:\Program Files\App Lid\5e105666-3823-4b38-84bd-65c2ffd59c30-11.exe','');
QuarantineFile('C:\Program Files\App Lid\5e105666-3823-4b38-84bd-65c2ffd59c30-10.exe','');
QuarantineFile('C:\Program Files\App Lid\5e105666-3823-4b38-84bd-65c2ffd59c30-1-7.exe','');
QuarantineFile('C:\Program Files\App Lid\5e105666-3823-4b38-84bd-65c2ffd59c30-1-6.exe','');
DelBHO('{03AE1B7B-A9E7-4D5A-9D34-89999C31B659}');
QuarantineFile('C:\Program Files\Torrent Search\IEEF\zTjk3cypEp.dll','');
QuarantineFile('C:\Users\Admin\AppData\Roaming\cpuminer\sgminer\sgminer.cmd','');
QuarantineFile('C:\Users\Admin\AppData\Local\SmartWeb\SmartWebHelper.exe','');
QuarantineFile('C:\ProgramData\TimeTasks\timetasks.exe','');
QuarantineFile('C:\Program Files\skinapp\skinapp.exe','');
QuarantineFile('C:\Program Files\Zaxar\ZaxarLoader.exe','');
QuarantineFile('C:\Program Files\Zaxar\ZaxarGameBrowser.exe','');
SetServiceStart('skinapp', 4);
DeleteService('skinapp');
QuarantineFile('C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe','');
DeleteService('WindowsMangerProtect');
QuarantineFile('C:\Windows\skinapp.sys','');
TerminateProcessByName('c:\program files\skinapp\skinapp.exe');
QuarantineFile('c:\program files\skinapp\skinapp.exe','');
TerminateProcessByName('c:\program files\crossbrowse\crossbrowse\application\crossbrowse.exe');
QuarantineFile('c:\program files\crossbrowse\crossbrowse\application\crossbrowse.exe','');
TerminateProcessByName('c:\users\admin\appdata\local\amigo\application\amigo.exe');
DeleteFile('c:\users\admin\appdata\local\amigo\application\amigo.exe','32');
DeleteFile('c:\program files\crossbrowse\crossbrowse\application\crossbrowse.exe','32');
DeleteFile('c:\program files\skinapp\skinapp.exe','32');
DeleteFile('C:\Program Files\skinapp\LIBEAY32.dll','32');
DeleteFile('C:\Program Files\skinapp\nfapi.dll','32');
DeleteFile('C:\Program Files\skinapp\ProtocolFilters.dll','32');
DeleteFile('C:\Users\Admin\AppData\Local\Amigo\Application\32.0.1725.115\chrome.dll','32');
DeleteFile('C:\Users\Admin\AppData\Local\Amigo\Application\32.0.1725.115\chrome_child.dll','32');
DeleteFile('C:\Users\Admin\AppData\Local\Amigo\Application\32.0.1725.115\ffmpegsumo.dll','32');
DeleteFile('C:\Users\Admin\AppData\Local\Amigo\Application\32.0.1725.115\icudt.dll','32');
DeleteFile('C:\Users\Admin\AppData\Local\Amigo\Application\32.0.1725.115\libegl.dll','32');
DeleteFile('C:\Users\Admin\AppData\Local\Amigo\Application\32.0.1725.115\libglesv2.dll','32');
DeleteFile('C:\Users\Admin\AppData\Local\Amigo\Application\32.0.1725.115\ppGoogleNaClPluginChrome.dll','32');
DeleteFile('C:\Windows\skinapp.sys','32');
DeleteFile('C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe','32');
DeleteFile('C:\Program Files\Zaxar\ZaxarGameBrowser.exe','32');
DeleteFile('C:\Program Files\Zaxar\ZaxarLoader.exe','32');
DeleteFile('C:\Program Files\skinapp\skinapp.exe','32');
DeleteFile('C:\ProgramData\TimeTasks\timetasks.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','amigo');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Timestasks');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','skinapp');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ZaxarLoader');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ZaxarGameBrowser');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','GoogleChromeAutoLaunch_3C42015D2638AD59A9C14E09DD1E3050');
DeleteFile('C:\Users\Admin\AppData\Local\SmartWeb\SmartWebHelper.exe','32');
DeleteFile('C:\Users\Admin\AppData\Roaming\cpuminer\sgminer\sgminer.cmd','32');
DeleteFile('C:\Program Files\Torrent Search\IEEF\zTjk3cypEp.dll','32');
DeleteFile('C:\Program Files\App Lid\5e105666-3823-4b38-84bd-65c2ffd59c30-1-6.exe','32');
DeleteFile('C:\Windows\Tasks\5e105666-3823-4b38-84bd-65c2ffd59c30-1-6.job','32');
DeleteFile('C:\Program Files\App Lid\5e105666-3823-4b38-84bd-65c2ffd59c30-1-7.exe','32');
DeleteFile('C:\Windows\Tasks\5e105666-3823-4b38-84bd-65c2ffd59c30-1-7.job','32');
DeleteFile('C:\Program Files\App Lid\5e105666-3823-4b38-84bd-65c2ffd59c30-10.exe','32');
DeleteFile('C:\Windows\Tasks\5e105666-3823-4b38-84bd-65c2ffd59c30-10_user.job','32');
DeleteFile('C:\Program Files\App Lid\5e105666-3823-4b38-84bd-65c2ffd59c30-11.exe','32');
DeleteFile('C:\Windows\Tasks\5e105666-3823-4b38-84bd-65c2ffd59c30-11.job','32');
DeleteFile('C:\Program Files\App Lid\5e105666-3823-4b38-84bd-65c2ffd59c30-4.exe','32');
DeleteFile('C:\Windows\Tasks\5e105666-3823-4b38-84bd-65c2ffd59c30-4.job','32');
DeleteFile('C:\Program Files\App Lid\5e105666-3823-4b38-84bd-65c2ffd59c30-5.exe','32');
DeleteFile('C:\Windows\Tasks\5e105666-3823-4b38-84bd-65c2ffd59c30-5.job','32');
DeleteFile('C:\Windows\Tasks\5e105666-3823-4b38-84bd-65c2ffd59c30-5_user.job','32');
DeleteFile('C:\Program Files\AnyProtectEx\AnyProtect.exe','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP1.job','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP2.job','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP3.job','32');
DeleteFile('C:\Users\Admin\AppData\Roaming\BwKvCPOYHKbUxMs1vmR.exe','32');
DeleteFile('C:\Windows\Tasks\BwKvCPOYHKbUxMs1vmR.job','32');
DeleteFile('C:\Program Files\Crossbrowse\Crossbrowse\Application\utility.exe','32');
DeleteFile('C:\Windows\Tasks\Crossbrowse.job','32');
DeleteFile('C:\Windows\Tasks\f87135f9-99e5-442e-87bd-a2848bdd7e3a-1-6.job','32');
DeleteFile('C:\Program Files\CiPlus-4.5vV05.07\f87135f9-99e5-442e-87bd-a2848bdd7e3a-1-6.exe','32');
DeleteFile('C:\Program Files\CiPlus-4.5vV05.07\f87135f9-99e5-442e-87bd-a2848bdd7e3a-1-7.exe','32');
DeleteFile('C:\Windows\Tasks\f87135f9-99e5-442e-87bd-a2848bdd7e3a-1-7.job','32');
DeleteFile('C:\Program Files\CiPlus-4.5vV05.07\f87135f9-99e5-442e-87bd-a2848bdd7e3a-10.exe','32');
DeleteFile('C:\Windows\Tasks\f87135f9-99e5-442e-87bd-a2848bdd7e3a-10_user.job','32');
DeleteFile('C:\Program Files\CiPlus-4.5vV05.07\f87135f9-99e5-442e-87bd-a2848bdd7e3a-11.exe','32');
DeleteFile('C:\Windows\Tasks\f87135f9-99e5-442e-87bd-a2848bdd7e3a-11.job','32');
DeleteFile('C:\Program Files\CiPlus-4.5vV05.07\f87135f9-99e5-442e-87bd-a2848bdd7e3a-4.exe','32');
DeleteFile('C:\Program Files\CiPlus-4.5vV05.07\f87135f9-99e5-442e-87bd-a2848bdd7e3a-5.exe','32');
DeleteFile('C:\Windows\Tasks\f87135f9-99e5-442e-87bd-a2848bdd7e3a-4.job','32');
DeleteFile('C:\Windows\Tasks\f87135f9-99e5-442e-87bd-a2848bdd7e3a-5.job','32');
DeleteFile('C:\Windows\system32\Tasks\5e105666-3823-4b38-84bd-65c2ffd59c30-1-6','32');
DeleteFile('C:\Windows\system32\Tasks\5e105666-3823-4b38-84bd-65c2ffd59c30-1-7','32');
DeleteFile('C:\Windows\system32\Tasks\5e105666-3823-4b38-84bd-65c2ffd59c30-11','32');
DeleteFile('C:\Windows\system32\Tasks\5e105666-3823-4b38-84bd-65c2ffd59c30-4','32');
DeleteFile('C:\Windows\system32\Tasks\5e105666-3823-4b38-84bd-65c2ffd59c30-5','32');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP1','32');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP2','32');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP3','32');
DeleteFile('C:\Windows\system32\Tasks\f87135f9-99e5-442e-87bd-a2848bdd7e3a-1-6','32');
DeleteFile('C:\Windows\system32\Tasks\f87135f9-99e5-442e-87bd-a2848bdd7e3a-1-7','32');
DeleteFile('C:\Windows\system32\Tasks\f87135f9-99e5-442e-87bd-a2848bdd7e3a-11','32');
DeleteFile('C:\Windows\system32\Tasks\f87135f9-99e5-442e-87bd-a2848bdd7e3a-4','32');
DeleteFile('C:\Windows\system32\Tasks\f87135f9-99e5-442e-87bd-a2848bdd7e3a-5','32');
DeleteFile('C:\Windows\system32\Tasks\SmartWeb Upgrade Trigger Task','32');
DeleteFile('C:\Windows\system32\Tasks\SomotoUpdateCheckerAutoStart','32');
DeleteFile('C:\Users\Admin\AppData\Local\FilesFrog Update Checker\update_checker.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\Temp\nsx7C22.tmp\blowfish.dll','32');
DeleteFile('C:\Program Files\anyprotectex\anyprotect.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.