Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-7.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-6.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-5.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-4.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-3.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-10.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-1-7.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-1-6.exe','');
QuarantineFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe','');
QuarantineFile('C:\Users\Inga\AppData\Roaming\a7hlgQ9S4cO2QEdxchwzJBRzR6.exe','');
QuarantineFile('C:\Users\Inga\AppData\Roaming\Browsers\exe.erolpxei.bat','');
QuarantineFile('C:\Users\Inga\AppData\Roaming\Browsers\exe.emorhc.bat','');
QuarantineFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe','');
QuarantineFile('C:\Program Files (x86)\Zaxar\ZaxarGameBrowser.exe','');
QuarantineFile('C:\Users\Inga\AppData\Local\525FACDF-1435596428-3945-5A46-4250F5867446\bnsxEAE6.exe','');
QuarantineFile('C:\Program Files (x86)\Zaxar\timetasks.exe','');
QuarantineFile('C:\supermegabest\run_setup.bat','');
QuarantineFile('C:\Users\Inga\AppData\Local\SmartWeb\SmartWebHelper.exe','');
QuarantineFile('C:\Program Files (x86)\skinapp\skinapp.exe','');
QuarantineFile('C:\Users\Inga\AppData\Local\Screeny\Screeny.exe','');
QuarantineFile('C:\Users\Inga\AppData\Local\Kometa\kometaup.exe','');
QuarantineFile('C:\Users\Inga\AppData\Roaming\cpuminer\sgminer\sgminer.cmd','');
QuarantineFile('C:\ProgramData\Windows\csrss.exe','');
QuarantineFile('C:\Program Files (x86)\Silver\Radio.exe','');
QuarantineFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe','');
SetServiceStart('BDMWrench_x64', 4);
DeleteService('{e2590817-40ca-4d03-8e1f-67fd8517bae9}Gw64');
DeleteService('{11944e07-3e46-4956-b8c7-7e52c7a44c1d}Gw64');
DeleteService('wsfd_1_10_0_19');
DeleteService('skinapp');
DeleteService('qrnfd_1_10_0_13');
DeleteService('illsmixw');
DeleteService('eecuuicx');
DeleteService('msgyigid');
DeleteService('innfd_1_10_0_14');
DeleteService('BDSafeBrowser');
DeleteService('BDEnhanceBoost');
DeleteService('bd0004');
DeleteService('bd0002');
DeleteService('bd0001');
DeleteService('BDMWrench_x64');
QuarantineFile('C:\Windows\system32\drivers\{e2590817-40ca-4d03-8e1f-67fd8517bae9}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{11944e07-3e46-4956-b8c7-7e52c7a44c1d}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\wsfd_1_10_0_19.sys','');
QuarantineFile('C:\Windows\system32\drivers\qrnfd_1_10_0_13.sys','');
QuarantineFile('C:\Windows\system32\drivers\innfd_1_10_0_14.sys','');
SetServiceStart('zejytose', 4);
DeleteService('zejytose');
DeleteService('buwomyre');
DeleteService('IHProtect Service');
DeleteService('qiqejyse');
DeleteService('soxocusy');
DeleteService('vicoqudu');
QuarantineFile('C:\Users\Inga\AppData\Roaming\525FACDF-1435585581-3945-5A46-4250F5867446\hnsc8E73.tmp','');
QuarantineFile('C:\Users\Inga\AppData\Roaming\525FACDF-1431592022-3945-5A46-4250F5867446\hnsm7E4D.tmp','');
QuarantineFile('C:\Users\Inga\AppData\Roaming\525FACDF-1431592022-3945-5A46-4250F5867446\nsm8E97.tmp','');
QuarantineFile('C:\Program Files (x86)\XTab\ProtectService.exe','');
QuarantineFile('C:\Users\Inga\AppData\Roaming\525FACDF-1431592022-3945-5A46-4250F5867446\jnsg6493.tmp','');
QuarantineFile('C:\Users\Inga\AppData\Roaming\525FACDF-1435585581-3945-5A46-4250F5867446\jnsm747B.tmp','');
TerminateProcessByName('c:\users\inga\appdata\roaming\525facdf-1435585581-3945-5a46-4250f5867446\jnsm747b.tmp');
QuarantineFile('c:\users\inga\appdata\roaming\525facdf-1435585581-3945-5a46-4250f5867446\jnsm747b.tmp','');
DeleteFile('c:\users\inga\appdata\roaming\525facdf-1435585581-3945-5a46-4250f5867446\jnsm747b.tmp','32');
DeleteFile('C:\Users\Inga\AppData\Roaming\525FACDF-1435585581-3945-5A46-4250F5867446\jnsm747B.tmp','32');
DeleteFile('C:\Users\Inga\AppData\Roaming\525FACDF-1431592022-3945-5A46-4250F5867446\jnsg6493.tmp','32');
DeleteFile('C:\Program Files (x86)\XTab\ProtectService.exe','32');
DeleteFile('C:\Users\Inga\AppData\Roaming\525FACDF-1431592022-3945-5A46-4250F5867446\nsm8E97.tmp','32');
DeleteFile('C:\Users\Inga\AppData\Roaming\525FACDF-1431592022-3945-5A46-4250F5867446\hnsm7E4D.tmp','32');
DeleteFile('C:\Users\Inga\AppData\Roaming\525FACDF-1435585581-3945-5A46-4250F5867446\hnsc8E73.tmp','32');
DeleteFile('C:\Windows\system32\drivers\innfd_1_10_0_14.sys','32');
DeleteFile('C:\Windows\system32\drivers\qrnfd_1_10_0_13.sys','32');
DeleteFile('C:\Windows\system32\drivers\wsfd_1_10_0_19.sys','32');
DeleteFile('C:\Windows\system32\drivers\{11944e07-3e46-4956-b8c7-7e52c7a44c1d}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{e2590817-40ca-4d03-8e1f-67fd8517bae9}Gw64.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\bd0001.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\bd0002.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\bd0004.sys','32');
DeleteFile('C:\Windows\system32\drivers\BDEnhanceBoost.sys','32');
DeleteFile('C:\Windows\system32\drivers\BDSafeBrowser.sys','32');
DeleteFile('C:\Windows\system32\DRIVERS\BDMWrench_x64.sys','32');
DeleteFile('C:\Windows\system32\drivers\skinapp.sys','32');
DeleteFile('C:\Windows\system32\drivers\illsmixw.sys','32');
DeleteFile('C:\Windows\system32\drivers\msgyigid.sys','32');
DeleteFile('C:\Windows\system32\drivers\eecuuicx.sys','32');
DeleteFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe','32');
DeleteFile('C:\ProgramData\Windows\csrss.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Client Server Runtime Subsystem');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','GoogleChromeAutoLaunch_F2056C8F5FEB99E0A0ABDBF2FE3B28F3');
DeleteFile('C:\Program Files (x86)\Baidu\BaiduAn\3.0.0.3971\baiduAnTray.exe','32');
DeleteFile('C:\Program Files (x86)\Baidu\BaiduSd\1.8.0.1255\baidusdTray.exe','32');
DeleteFile('C:\Users\Inga\AppData\Roaming\cpuminer\sgminer\sgminer.cmd','32');
DeleteFile('C:\Users\Inga\AppData\Local\Kometa\kometaup.exe','32');
DeleteFile('C:\Users\Inga\AppData\Local\Screeny\Screeny.exe','32');
DeleteFile('C:\Program Files (x86)\skinapp\skinapp.exe','32');
DeleteFile('C:\Users\Inga\AppData\Local\SmartWeb\SmartWebHelper.exe','32');
DeleteFile('C:\supermegabest\run_setup.bat','32');
DeleteFile('C:\Program Files (x86)\Zaxar\timetasks.exe','32');
DeleteFile('C:\Users\Inga\AppData\Local\525FACDF-1435596428-3945-5A46-4250F5867446\bnsxEAE6.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinCheck','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Timestasks','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SuperMegaBest','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SmartWeb','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\skinapp','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Screeny','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\kometaup','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\gpuminer','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\baidusdTray','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\baiduAnTray','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\amigo','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Windesk Winsearch','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\YSetupDel','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ZaxarGameBrowser','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ZaxarLoader','command');
DeleteFile('C:\Program Files (x86)\Zaxar\ZaxarGameBrowser.exe','32');
DeleteFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe','32');
DeleteFile('C:\Users\Inga\AppData\Roaming\Browsers\exe.emorhc.bat','32');
DeleteFile('C:\Users\Inga\AppData\Roaming\Browsers\exe.erolpxei.bat','32');
DeleteFile('C:\Users\Inga\AppData\Roaming\a7hlgQ9S4cO2QEdxchwzJBRzR6.exe','32');
DeleteFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe','32');
DeleteFile('C:\Windows\Tasks\a7hlgQ9S4cO2QEdxchwzJBRzR6.job','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP1.job','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP2.job','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP3.job','32');
DeleteFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-1-6.exe','32');
DeleteFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-1-7.exe','32');
DeleteFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-10.exe','32');
DeleteFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-3.exe','32');
DeleteFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-4.exe','32');
DeleteFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-5.exe','32');
DeleteFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-6.exe','32');
DeleteFile('C:\Program Files (x86)\CinemaPlus-4.5vV29.06\bb78e436-568c-4b08-b806-6f5547cf2f29-7.exe','32');
DeleteFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe','32');
DeleteFile('C:\Windows\Tasks\Crossbrowse.job','32');
DeleteFile('C:\Windows\Tasks\bb78e436-568c-4b08-b806-6f5547cf2f29-7.job','32');
DeleteFile('C:\Windows\Tasks\bb78e436-568c-4b08-b806-6f5547cf2f29-6.job','32');
DeleteFile('C:\Windows\Tasks\bb78e436-568c-4b08-b806-6f5547cf2f29-5_user.job','32');
DeleteFile('C:\Windows\Tasks\bb78e436-568c-4b08-b806-6f5547cf2f29-5.job','32');
DeleteFile('C:\Windows\Tasks\bb78e436-568c-4b08-b806-6f5547cf2f29-4.job','32');
DeleteFile('C:\Windows\Tasks\bb78e436-568c-4b08-b806-6f5547cf2f29-3.job','32');
DeleteFile('C:\Windows\Tasks\bb78e436-568c-4b08-b806-6f5547cf2f29-10_user.job','32');
DeleteFile('C:\Windows\Tasks\bb78e436-568c-4b08-b806-6f5547cf2f29-1-7.job','32');
DeleteFile('C:\Windows\Tasks\bb78e436-568c-4b08-b806-6f5547cf2f29-1-6.job','32');
DeleteFile('C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job','32');
DeleteFile('C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job','32');
DeleteFile('C:\Windows\system32\Tasks\Crossbrowse','64');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.