Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\homesonya\AppData\Roaming\mystartsearch\UninstallManager.exe','');
QuarantineFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\Crossbrowse.exe','');
QuarantineFile('C:\Users\homesonya\AppData\Roaming\newSI_4667\s_inst.exe','');
QuarantineFile('C:\Users\homesonya\AppData\Roaming\newSI_23\s_inst.exe','');
QuarantineFile('C:\Users\homesonya\AppData\Roaming\newSI_21\s_inst.exe','');
QuarantineFile('C:\Users\homesonya\AppData\Roaming\9eY8zGH1BN.exe','');
QuarantineFile('C:\Users\homesonya\AppData\Roaming\9el1HXoZzZSlcEcB655odp.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-7.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-6.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-5.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-3.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-11.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-10.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-1-7.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-1-6.exe','');
DelCLSID('{63332668-8CE1-445D-A5EE-25929176714E}');
DelBHO('{FB4F6285-4C32-49F2-950F-A5998F9CEC6C}');
QuarantineFile('C:\IQIYI Video\Common\Accelerator\IEHelper.dll','');
SetServiceStart('TSSKX64', 4);
DeleteService('TSSKX64');
SetServiceStart('TSSysKit', 4);
DeleteService('TSSysKit');
SetServiceStart('TSDefenseBt', 4);
DeleteService('TSDefenseBt');
SetServiceStart('TS888x64', 4);
DeleteService('TS888x64');
SetServiceStart('TFsFlt', 4);
DeleteService('TFsFlt');
SetServiceStart('TAOKernelDriver', 4);
DeleteService('TAOKernelDriver');
SetServiceStart('TAOAccelerator', 4);
DeleteService('TAOAccelerator');
SetServiceStart('sysmon', 4);
DeleteService('sysmon');
SetServiceStart('rsutils', 4);
DeleteService('rsutils');
SetServiceStart('QQSysMonX64', 4);
DeleteService('QQSysMonX64');
SetServiceStart('QMUdisk', 4);
DeleteService('QMUdisk');
SetServiceStart('QQPCRTP', 4);
DeleteService('QQPCRTP');
SetServiceStart('RsRavMon', 4);
SetServiceStart('RsMgrSvc', 4);
DeleteService('RsMgrSvc');
DeleteService('RsRavMon');
SetServiceStart('viqihuqu', 4);
DeleteService('viqihuqu');
DeleteService('TAOFrame');
TerminateProcessByName('c:\program files (x86)\rising\rav\rstray.exe');
TerminateProcessByName('c:\program files (x86)\rising\rsd\rsmgrsvc.exe');
TerminateProcessByName('c:\program files (x86)\rising\rav\ravmond.exe');
TerminateProcessByName('c:\program files (x86)\tencent\qqpcmgr\10.10.16443.223\qqpcrtp.exe');
TerminateProcessByName('c:\programdata\hwinmanproh\protectwindowsmanager.exe');
QuarantineFile('c:\programdata\hwinmanproh\protectwindowsmanager.exe','');
TerminateProcessByName('c:\program files (x86)\0f534c80-1439105723-11e0-8955-f0bf975aebf5\knse4f55.tmp');
QuarantineFile('c:\program files (x86)\0f534c80-1439105723-11e0-8955-f0bf975aebf5\knse4f55.tmp','');
DeleteFile('c:\program files (x86)\0f534c80-1439105723-11e0-8955-f0bf975aebf5\knse4f55.tmp','32');
DeleteFile('c:\programdata\hwinmanproh\protectwindowsmanager.exe','32');
DeleteFile('c:\program files (x86)\tencent\qqpcmgr\10.10.16443.223\qqpcrtp.exe','32');
DeleteFile('c:\program files (x86)\rising\rav\ravmond.exe','32');
DeleteFile('c:\program files (x86)\rising\rsd\rsmgrsvc.exe','32');
DeleteFile('c:\program files (x86)\rising\rav\rstray.exe','32');
DeleteFile('C:\Program Files (x86)\Rising\RAV\antipromotionmon.dll','32');
DeleteFile('C:\Program Files (x86)\Rising\RAV\BACore.dll','32');
DeleteFile('C:\Program Files (x86)\Rising\RAV\boottm.dll','32');
DeleteFile('C:\PROGRAM FILES (X86)\RISING\RAV\brscan.dll','32');
DeleteFile('C:\Program Files (x86)\Rising\RAV\cloudcom.dll','32');
DeleteFile('C:\PROGRAM FILES (X86)\RISING\RAV\cloudmp.dll','32');
DeleteFile('C:\PROGRAM FILES (X86)\RISING\RAV\cloudmpw.dll','32');
DeleteFile('C:\PROGRAM FILES (X86)\RISING\RAV\cloudnotifier.dll','32');
DeleteFile('C:\Program Files (x86)\Rising\RAV\cloudqry.dll','32');
DeleteFile('C:\Program Files (x86)\Rising\RAV\cloudstore.dll','32');
DeleteFile('C:\Program Files (x86)\Rising\RAV\cloudtfc.dll','32');
DeleteFile('C:\Program Files (x86)\Rising\RAV\cloudwork.dll','32');
DeleteFile('C:\Program Files (x86)\Rising\RAV\cnt09.dll','32');
DeleteFile('C:\Program Files (x86)\Rising\RAV\recomp.dll','32');
DeleteFile('C:\PROGRAM FILES (X86)\RISING\RAV\mruleui.dll','32');
DeleteFile('C:\Program Files (x86)\Rising\RAV\rego\methodex.dll','32');
DeleteFile('C:\Program Files (x86)\Rising\RAV\rego\revm.dll','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\dr.dll','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\oDayProtect.dll','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\plugins\QMBDScanner.dat','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\plugins\QMCloudInter\QMCloudInter.dll','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\plugins\QMCpm.dll','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\plugins\QMHips.dll','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\plugins\QMHipsEngine.dll','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\plugins\qmiemalrtpplugin\qmiemalrtpplugin.dll','32');
DeleteFile('C:\ProgramData\Tencent\TSVulFw\TSVulFW.DAT','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\QMUdisk64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\QQSysMonX64.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\rsutils.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\sysmon.sys','32');
DeleteFile('C:\Windows\system32\Drivers\TAOAccelerator64.sys','32');
DeleteFile('C:\Windows\System32\Drivers\TAOKernel64.sys','32');
DeleteFile('C:\Windows\system32\Drivers\TFsFltX64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\TS888x64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\tscpm64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\TSDefenseBT64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\TSSysKit64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\QQPCRTP.exe','32');
DeleteFile('C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe','32');
DeleteFile('C:\Program Files (x86)\Rising\RAV\ravmond.exe','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\TAOFrame.exe','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\QMContextScan.dll','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\QMContextScan64.dll','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\QMContextUninstall64.dll','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\10.10.16443.223\QQPCTray.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','QQPCTray');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved','{CBDECEF7-7A29-4cbf-A009-2673D82C7BF9}');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved','{63332668-8CE1-445D-A5EE-25929176714E}');
DeleteFile('C:\IQIYI Video\Common\Accelerator\IEHelper.dll','32');
DeleteFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-1-6.exe','32');
DeleteFile('C:\Windows\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-1-6.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-1-7.exe','32');
DeleteFile('C:\Windows\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-1-7.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-10.exe','32');
DeleteFile('C:\Windows\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-10_user.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-11.exe','32');
DeleteFile('C:\Windows\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-11.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-3.exe','32');
DeleteFile('C:\Windows\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-3.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-5.exe','32');
DeleteFile('C:\Windows\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-5.job','64');
DeleteFile('C:\Windows\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-5_user.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-6.exe','32');
DeleteFile('C:\Windows\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-6.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\8f395291-838b-47df-8909-6b88c079a5fc-7.exe','32');
DeleteFile('C:\Windows\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-7.job','64');
DeleteFile('C:\Users\homesonya\AppData\Roaming\9el1HXoZzZSlcEcB655odp.exe','32');
DeleteFile('C:\Windows\Tasks\9el1HXoZzZSlcEcB655odp.job','64');
DeleteFile('C:\Users\homesonya\AppData\Roaming\9eY8zGH1BN.exe','32');
DeleteFile('C:\Windows\Tasks\9eY8zGH1BN.job','64');
DeleteFile('C:\Windows\Tasks\APSnotifierPP1.job','64');
DeleteFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP2.job','64');
DeleteFile('C:\Windows\Tasks\APSnotifierPP3.job','64');
DeleteFile('C:\Users\homesonya\AppData\Roaming\newSI_21\s_inst.exe','32');
DeleteFile('C:\Users\homesonya\AppData\Roaming\newSI_23\s_inst.exe','32');
DeleteFile('C:\Users\homesonya\AppData\Roaming\newSI_4667\s_inst.exe','32');
DeleteFile('C:\Windows\Tasks\newSI_4667.job','64');
DeleteFile('C:\Windows\Tasks\newSI_23.job','64');
DeleteFile('C:\Windows\Tasks\newSI_21.job','64');
DeleteFile('C:\Windows\Tasks\RegClean Pro_DEFAULT.job','64');
DeleteFile('C:\Windows\Tasks\RegClean Pro_UPDATES.job','64');
DeleteFile('C:\Program Files (x86)\RCP\RegCleanPro.exe','32');
DeleteFile('C:\Windows\system32\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-1-6','64');
DeleteFile('C:\Windows\system32\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-1-7','64');
DeleteFile('C:\Windows\system32\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-10_user','64');
DeleteFile('C:\Windows\system32\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-11','64');
DeleteFile('C:\Windows\system32\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-3','64');
DeleteFile('C:\Windows\system32\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-5','64');
DeleteFile('C:\Windows\system32\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-5_user','64');
DeleteFile('C:\Windows\system32\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-6','64');
DeleteFile('C:\Windows\system32\Tasks\8f395291-838b-47df-8909-6b88c079a5fc-7','64');
DeleteFile('C:\Windows\system32\Tasks\9el1HXoZzZSlcEcB655odp','64');
DeleteFile('C:\Windows\system32\Tasks\9eY8zGH1BN','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP1','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP2','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP3','64');
DeleteFile('C:\Windows\system32\Tasks\brbrw_6328','64');
DeleteFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\Crossbrowse.exe','32');
DeleteFile('C:\Windows\system32\Tasks\RegClean Pro','64');
DeleteFile('C:\Windows\system32\Tasks\RegClean Pro_DEFAULT','64');
DeleteFile('C:\Windows\system32\Tasks\RegClean Pro_UPDATES','64');
DeleteFile('C:\Windows\system32\Tasks\RsDelayLauncher_{8A34248E-7D35-4832-8378-7659E0B0A380}','64');
DeleteFile('C:\PROGRAM FILES (X86)\RISING\RAV\rsdelaylauncher.exe','32');
DeleteFile('C:\Users\homesonya\AppData\Roaming\mystartsearch\UninstallManager.exe','32');
DeleteFile('C:\Windows\system32\Tasks\{D8B8AB49-C856-4354-AB0F-DBB95D488C8E}','64');
DeleteFile('C:\Users\homesonya\AppData\Local\Temp\nsh36BA.tmp\blowfish.dll','32');
DeleteFile('C:\Users\homesonya\AppData\Local\Temp\nsi3D4F.tmp\blowfish.dll','32');
DeleteFile('C:\Users\homesonya\AppData\Local\Temp\nsoA44B.tmp\blowfish.dll','32');
DeleteFile('C:\Users\homesonya\AppData\Local\Temp\nsx198A.tmp\blowfish.dll','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.