Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\PROGRA~1\GROOVE~1\Dejrewhi.bat','');
QuarantineFile('C:\ProgramData\RenewalService\Service.exe','');
QuarantineFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe','');
QuarantineFile('C:\Program Files (x86)\Zaxar\ZaxarGameBrowser.exe','');
QuarantineFile('C:\Users\Admin\AppData\Local\gmsd_ru_005010240\upgmsd_ru_005010240.exe','');
QuarantineFile('C:\ProgramData\TimeTasks\timetasks.exe','');
QuarantineFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe','');
QuarantineFile('C:\Program Files\Sound+\Sound+.exe','');
QuarantineFile('C:\Users\Admin\AppData\Roaming\daemon2.exe','');
QuarantineFile('C:\Users\Admin\AppData\Local\Birds\birds365.exe','');
DeleteService('TSSKX64');
DeleteService('tsnethlpx64');
DeleteService('TSDefenseBt');
DeleteService('TS888x64');
DeleteService('TFsFlt');
DeleteService('TAOAccelerator');
DeleteService('softaal');
DeleteService('QQSysMonX64');
DeleteService('QMUdisk');
SetServiceStart('TAOKernelDriver', 4);
DeleteService('TAOKernelDriver');
SetServiceStart('clr_optimization_v1.02', 4);
DeleteService('clr_optimization_v1.02');
SetServiceStart('WajaNetEn Monitor', 4);
DeleteService('WajaNetEn Monitor');
DeleteService('QQPCRTP');
TerminateProcessByName('c:\users\admin\appdata\roaming\nssm.exe');
QuarantineFile('c:\users\admin\appdata\roaming\nssm.exe','');
TerminateProcessByName('c:\program files\wajaneten\47c4d8b86bd87ddda8e0e31861eedeb0.exe');
TerminateProcessByName('C:\Program Files\WajaNetEn\863dc4e18cd542b06e1c5cfe443c2fba.exe');
QuarantineFile('C:\Program Files\WajaNetEn\863dc4e18cd542b06e1c5cfe443c2fba.exe','');
QuarantineFile('c:\program files\wajaneten\47c4d8b86bd87ddda8e0e31861eedeb0.exe','');
DeleteFile('c:\program files\wajaneten\47c4d8b86bd87ddda8e0e31861eedeb0.exe','32');
DeleteFile('C:\Program Files\WajaNetEn\863dc4e18cd542b06e1c5cfe443c2fba.exe','32');
DeleteFile('c:\users\admin\appdata\roaming\nssm.exe','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\QQPCRTP.exe','32');
DeleteFile('C:\Windows\system32\Drivers\TAOKernel64.sys','32');
DeleteFile('C:\Windows\system32\drivers\tsskx64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TsNetHlpX64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TSDefenseBT64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\TS888x64.sys','32');
DeleteFile('C:\Windows\system32\Drivers\TFsFltX64.sys','32');
DeleteFile('C:\Windows\system32\Drivers\TAOAccelerator64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\softaal64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\QQSysMonX64.sys','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\QMUdisk64.sys','32');
DeleteFile('C:\Program Files (x86)\ppt\ppt.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\Birds\birds365.exe','32');
DeleteFile('C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17201.218\QQPCTRAY.EXE','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ QQPCTray','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\apphide','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Birds','command');
DeleteFile('C:\Users\Admin\AppData\Roaming\daemon2.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Daemon','command');
DeleteFile('C:\Program Files (x86)\Mobogenie\DaemonProcess.exe','32');
DeleteFile('C:\Program Files (x86)\MTV20160128\MTView.exe','32');
DeleteFile('C:\Program Files (x86)\ppt\Uninst.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\Temp\qq-bundle.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MTview','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\pcmgr','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\qq-bundle','command');
DeleteFile('C:\Program Files\Sound+\Sound+.exe','32');
DeleteFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe','32');
DeleteFile('C:\ProgramData\TimeTasks\timetasks.exe','32');
DeleteFile('C:\Users\Admin\AppData\Local\gmsd_ru_005010240\upgmsd_ru_005010240.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\upgmsd_ru_005010240.exe','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Timestasks','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SpaceSoundPro','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sound+','command');
DeleteFile('C:\Program Files (x86)\Zaxar\ZaxarGameBrowser.exe','32');
DeleteFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ZaxarLoader','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ZaxarGameBrowser','command');
DeleteFile('C:\Users\Admin\AppData\Local\Yandex\YandexBrowser\Application\browser.url','32');
DeleteFile('C:\Users\Admin\AppData\Local\Amigo\Application\amigo.exe','32');
DeleteFile('C:\Program Files (x86)\Twilight Tech\Pretty Search\dummyDlg.exe','32');
DeleteFile('C:\ProgramData\RenewalService\Service.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\Diagnosis\RenewalService','64');
DeleteFile('C:\PROGRA~1\GROOVE~1\Dejrewhi.bat','32');
DeleteFile('C:\Windows\system32\Tasks\Rutso','64');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.