Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Program Files (x86)\WordWizard_1.10.0.24\Update\WordwizardAutoUpdateClient.exe','');
QuarantineFile('c:\task.vbs','');
QuarantineFile('C:\Users\admin\AppData\Local\SmartWeb\SmartWebHelper.exe','');
QuarantineFile('C:\Users\master\AppData\Local\Temp\Updater.exe','');
QuarantineFile('C:\Users\admin\AppData\Roaming\tRZe9ZS5Yf1irF.exe','');
QuarantineFile('C:\Users\admin\AppData\Roaming\HKlMN804ZukCkiIys.exe','');
QuarantineFile('c:\windows\web\gd.bat','');
QuarantineFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe','');
QuarantineFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-7.exe','');
QuarantineFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-6.exe','');
QuarantineFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-5.exe','');
QuarantineFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-4.exe','');
QuarantineFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-3.exe','');
QuarantineFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-10.exe','');
QuarantineFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-1-7.exe','');
QuarantineFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-1-6.exe','');
QuarantineFile('C:\Program Files (x86)\gmsd_ru_005010086\gmsd_ru_005010086.exe','');
QuarantineFile('C:\Program Files (x86)\gmsd_ru_005010093\gmsd_ru_005010093.exe','');
QuarantineFile('C:\Program Files (x86)\gmsd_ru_005010102\gmsd_ru_005010102.exe','');
QuarantineFile('C:\Users\admin\AppData\Local\Kometa\kometaup.exe','');
QuarantineFile('C:\Users\admin\AppData\Local\likecoupon\stub.exe','');
QuarantineFile('C:\Users\admin\AppData\Local\likecoupon\config.json','');
QuarantineFile('C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe','');
SetServiceStart('wwfd_vt_1_10_0_24', 4);
SetServiceStart('WdsManPro', 4);
SetServiceStart('tunywuzu', 4);
SetServiceStart('SSFK', 4);
DeleteService('SSFK');
DeleteService('tunywuzu');
DeleteService('WdsManPro');
DeleteService('globalUpdate');
DeleteService('globalUpdatem');
DeleteService('wwsvc_1.10.0.24');
DeleteService('wsafd_1_10_0_19');
DeleteService('wwfd_vt_1_10_0_24');
QuarantineFile('C:\Windows\system32\drivers\wsafd_1_10_0_19.sys','');
QuarantineFile('C:\Windows\system32\drivers\wwfd_vt_1_10_0_24.sys','');
TerminateProcessByName('C:\Program Files (x86)\SFK\SFKEX64.exe');
TerminateProcessByName('c:\program files (x86)\sfk\ssfk.exe');
TerminateProcessByName('c:\programdata\rwdsmanpror\wdsmanpro.exe');
QuarantineFile('c:\programdata\rwdsmanpror\wdsmanpro.exe','');
QuarantineFile('c:\program files (x86)\sfk\ssfk.exe','');
QuarantineFile('C:\Program Files (x86)\SFK\SFKEX64.exe','');
TerminateProcessByName('c:\program files (x86)\gmsd_ru_005010105\gmsd_ru_005010105.exe');
TerminateProcessByName('c:\program files (x86)\gmsd_ru_005010107\gmsd_ru_005010107.exe');
TerminateProcessByName('c:\program files (x86)\b37cc580-1441801894-11e1-acd7-30f9edaf8093\knsyf7f0.tmp');
QuarantineFile('c:\program files (x86)\b37cc580-1441801894-11e1-acd7-30f9edaf8093\knsyf7f0.tmp','');
QuarantineFile('c:\program files (x86)\gmsd_ru_005010107\gmsd_ru_005010107.exe','');
QuarantineFile('c:\program files (x86)\gmsd_ru_005010105\gmsd_ru_005010105.exe','');
TerminateProcessByName('c:\program files (x86)\shop and save up\5624f943-9d5c-4e27-962d-63954b897a69-1-6.exe');
TerminateProcessByName('c:\program files (x86)\shop and save up\5624f943-9d5c-4e27-962d-63954b897a69-6.exe');
QuarantineFile('c:\program files (x86)\shop and save up\5624f943-9d5c-4e27-962d-63954b897a69-6.exe','');
QuarantineFile('c:\program files (x86)\shop and save up\5624f943-9d5c-4e27-962d-63954b897a69-1-6.exe','');
DeleteFile('c:\program files (x86)\shop and save up\5624f943-9d5c-4e27-962d-63954b897a69-1-6.exe','32');
DeleteFile('c:\program files (x86)\shop and save up\5624f943-9d5c-4e27-962d-63954b897a69-6.exe','32');
DeleteFile('c:\program files (x86)\gmsd_ru_005010105\gmsd_ru_005010105.exe','32');
DeleteFile('c:\program files (x86)\gmsd_ru_005010107\gmsd_ru_005010107.exe','32');
DeleteFile('c:\program files (x86)\b37cc580-1441801894-11e1-acd7-30f9edaf8093\knsyf7f0.tmp','32');
DeleteFile('C:\Program Files (x86)\SFK\SFKEX64.exe','32');
DeleteFile('c:\program files (x86)\sfk\ssfk.exe','32');
DeleteFile('c:\programdata\rwdsmanpror\wdsmanpro.exe','32');
DeleteFile('C:\Windows\system32\drivers\wwfd_vt_1_10_0_24.sys','32');
DeleteFile('C:\Windows\system32\drivers\wsafd_1_10_0_19.sys','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gmsd_ru_005010105');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gmsd_ru_005010107');
DeleteFile('C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\gmsd_ru_005010086','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\gmsd_ru_005010093','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\gmsd_ru_005010102','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GoogleChromeAutoLaunch_35F47CA955883AC80F45949DB9B0CAE0','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Daemon','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\C','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\kometaup','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\likecoupon','command');
DeleteFile('C:\Users\admin\AppData\Local\likecoupon\config.json','32');
DeleteFile('C:\Users\admin\AppData\Local\likecoupon\stub.exe','32');
DeleteFile('C:\Users\admin\AppData\Local\Kometa\kometaup.exe','32');
DeleteFile('C:\Program Files (x86)\gmsd_ru_005010102\gmsd_ru_005010102.exe','32');
DeleteFile('C:\Program Files (x86)\gmsd_ru_005010093\gmsd_ru_005010093.exe','32');
DeleteFile('C:\Program Files (x86)\gmsd_ru_005010086\gmsd_ru_005010086.exe','32');
DeleteFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-1-6.exe','32');
DeleteFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-1-7.exe','32');
DeleteFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-10.exe','32');
DeleteFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-3.exe','32');
DeleteFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-4.exe','32');
DeleteFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-5.exe','32');
DeleteFile('C:\Windows\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-1-6.job','32');
DeleteFile('C:\Windows\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-1-7.job','32');
DeleteFile('C:\Windows\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-10_user.job','32');
DeleteFile('C:\Windows\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-3.job','32');
DeleteFile('C:\Windows\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-4.job','32');
DeleteFile('C:\Windows\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-5.job','32');
DeleteFile('C:\Windows\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-5_user.job','32');
DeleteFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-6.exe','32');
DeleteFile('C:\Program Files (x86)\Shop and Save Up\5624f943-9d5c-4e27-962d-63954b897a69-7.exe','32');
DeleteFile('C:\Windows\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-7.job','32');
DeleteFile('C:\Windows\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-6.job','32');
DeleteFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP1.job','32');
DeleteFile('C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job','32');
DeleteFile('C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job','32');
DeleteFile('C:\Users\admin\AppData\Roaming\HKlMN804ZukCkiIys.exe','32');
DeleteFile('C:\Windows\Tasks\HKlMN804ZukCkiIys.job','32');
DeleteFile('C:\Windows\Tasks\tRZe9ZS5Yf1irF.job','32');
DeleteFile('C:\Users\admin\AppData\Roaming\tRZe9ZS5Yf1irF.exe','32');
DeleteFile('C:\Windows\system32\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-1-6','64');
DeleteFile('C:\Windows\system32\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-1-7','64');
DeleteFile('C:\Windows\system32\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-10_user','64');
DeleteFile('C:\Windows\system32\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-3','64');
DeleteFile('C:\Windows\system32\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-4','64');
DeleteFile('C:\Windows\system32\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-5','64');
DeleteFile('C:\Windows\system32\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-5_user','64');
DeleteFile('C:\Windows\system32\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-6','64');
DeleteFile('C:\Windows\system32\Tasks\5624f943-9d5c-4e27-962d-63954b897a69-7','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP1','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP2','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP3','64');
DeleteFile('C:\Windows\system32\Tasks\HKlMN804ZukCkiIys','64');
DeleteFile('C:\Windows\system32\Tasks\runTask','64');
DeleteFile('C:\Windows\system32\Tasks\SmartWeb Upgrade Trigger Task','64');
DeleteFile('C:\Users\master\AppData\Local\Temp\Updater.exe','32');
DeleteFile('C:\Users\admin\AppData\Local\SmartWeb\SmartWebHelper.exe','32');
DeleteFile('C:\Windows\system32\Tasks\updateTask','64');
DeleteFile('c:\task.vbs','32');
DeleteFile('C:\Windows\system32\Tasks\WordWizard Auto Updater 1.10.0.24 Core','64');
DeleteFile('C:\Windows\system32\Tasks\WordWizard Auto Updater 1.10.0.24 Pending Update','64');
DeleteFile('C:\Program Files (x86)\WordWizard_1.10.0.24\Update\WordwizardAutoUpdateClient.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.