Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
DelBHO('{92780B25-18CC-41C8-B9BE-3C9C571A8263}');
DelBHO('{C0D38E5A-7CF8-4105-8FE8-31B81443A114}');
StopService('71e14eb66e92df602a4d04116259c9a6');
StopService('SvcHost Service Host');
StopService('WinDefender');
StopService('icacl');
TerminateProcessByName('C:\ProgramData\b1cec899715a40009ade88195260d62f\yVEBLWSiJGa.exe');
TerminateProcessByName('C:\Users\Александр\AppData\Local\Temp\2a577cf90e3a4d8aa8c770b4de31b375\ZHMPbqEv.exe');
TerminateProcessByName('C:\Windows\Microsoft\svchost.exe.exe');
TerminateProcessByName('c:\users\8523~1\appdata\roaming\setupsk\python\pythonw.exe');
TerminateProcessByName('c:\windows\microsoft\svchost.exe');
DeleteService('SvcHost Service Host');
DeleteService('WinDefender');
DeleteService('icacl');
QuarantineFile('C:\PROGRA~2\FASTDA~1\FASTDA~1.EXE','');
QuarantineFile('C:\Program Files (x86)\GXZiGyYLSHyU2\3cQOz6E.dll','');
QuarantineFile('C:\Program Files (x86)\QYERbvxRHIE\kEV8xPB.dll','');
QuarantineFile('C:\Program Files (x86)\thzXuJvjU\E8dYN1d.dll','');
QuarantineFile('C:\Program Files\Common Files\FV7ZO9ID\dcI6Pu9ip.exe','');
QuarantineFile('C:\Program Files\Novo\novoopt.exe','');
QuarantineFile('C:\Program Files\Novo\npsvc.exe','');
QuarantineFile('C:\Program Files\Windows Journal\8Z6IFBTFB95Y49UGHQ42J\qrNNRzxEri.exe','');
QuarantineFile('C:\ProgramData\b1cec899715a40009ade88195260d62f\yVEBLWSiJGa.exe','');
QuarantineFile('C:\ProgramData\e6da7161ec8044e1b20e7bd3962b3b93\j8HQ5IogSFp.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\3b60cb8adf68401d8c2c0e2e9a5e989c\4phIGNDOnj757D.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\406e99fe02604493829f1d9bccd8634e\4Mr9Sa5wdU2YA.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Temp\2a577cf90e3a4d8aa8c770b4de31b375\ZHMPbqEv.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Temp\3249b95708d84622a6dcb8d541adcdcb\bfCtUuXQ.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Temp\46ad0451724a4bab97646622acb533bb\EeI64WXUAN.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Temp\4a63300f549a466a9e4f3c9ad3cdcd52\vEQ9qoin.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Temp\4ab10f3f9d7444f78b746dc1e0330057\V8oXsdk.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Temp\4bab0920df0c4d2f96ef109789bc3d49\Xyzz9uRHdWO.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Temp\539a4e218da546a4ab397a34f98198c3\1vnFfU87.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Temp\6b9f9c484cf047d4ac85b4a583931f93\FWapRlD.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Temp\8dbd7f26225346d08f1b083255d2338e\V6cW9na.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Temp\942b321edcd5429c95a0383b679911ce\wldjfsmkyuuGB.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Temp\a936d70023e442189d883a13419faa71\UZc7PziMCDvup.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Temp\b757a1a53a5544c989f4d62ba25988e6\L3KqZhC9.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Temp\d31ba9cbc6d44c13a0c342083696e61f\QWpPtuWQD.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Temp\d35a5a3db1954a7fba9d05db288db9a2\g3EDVlZUJZLc1.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Temp\f9a659fd0e5448b6848303ba9c5f7b20\93bQdRcV.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\c99bf4a303b84f18a74b813894cff5ca\GYqldfL5vHuQg.exe','');
QuarantineFile('C:\Users\Александр\AppData\Roaming\20c737ecd717465dbb14cea14115f6fa\uKUHuToxE6.exe','');
QuarantineFile('C:\Users\Александр\AppData\Roaming\7f9ae6a3f27146389b662d5612140065\LmbRZLlSzR.exe','');
QuarantineFile('C:\Users\Александр\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe','');
QuarantineFile('C:\Users\Александр\AppData\Roaming\Event Monitor\em.exe','');
QuarantineFile('C:\Users\Александр\AppData\Roaming\Event Monitor\isxdl.dll','');
QuarantineFile('C:\Users\Александр\AppData\Roaming\SIVApp\SIVApp.exe','');
QuarantineFile('C:\Users\Александр\AppData\Roaming\aswast\ml.py','');
QuarantineFile('C:\Users\Александр\AppData\Roaming\aswast\python\pythonw.exe','');
QuarantineFile('C:\Users\Александр\AppData\Roaming\d8de72ce3c2e4e47a380c174969dcf8c\69XuaAXVcJ7DC.exe','');
QuarantineFile('C:\Users\Александр\AppData\Roaming\f156e196839e4e7ba17711337c9127d0\h7TitKlCkr.exe','');
QuarantineFile('C:\Users\Александр\AppData\Roaming\gplyra\gplyra.exe','');
QuarantineFile('C:\Users\Александр\appdata\local\temp\b.exe','');
QuarantineFile('C:\Users\Александр\appdata\roaming\sivapp\sivapp.exe','');
QuarantineFile('C:\Users\8523~1\AppData\Roaming\SETUPS~1\ml.py','');
QuarantineFile('C:\Users\8523~1\AppData\Roaming\SETUPS~1\python\pythonw.exe','');
QuarantineFile('C:\Users\8523~1\AppData\Roaming\curl\curl.exe','');
QuarantineFile('C:\Users\8523~1\AppData\Roaming\curl\curl_7_54.exe','');
QuarantineFile('C:\Users\8523~1\AppData\Roaming\setupsk\ml.py','');
QuarantineFile('C:\Users\8523~1\AppData\Roaming\setupsk\python\DLLs\_ctypes.pyd','');
QuarantineFile('C:\Users\8523~1\AppData\Roaming\setupsk\python\python34.dll','');
QuarantineFile('C:\Users\8523~1\AppData\Roaming\setupsk\python\pythonw.exe','');
QuarantineFile('C:\Windows\Microsoft\svchost.exe','');
QuarantineFile('C:\Windows\Microsoft\svchost.exe.exe','');
QuarantineFile('C:\Windows\System32\icacl.exe','');
QuarantineFile('C:\Windows\Temp\g3FFC.tmp.exe','');
QuarantineFile('C:\Windows\Temp\g4B70.tmp.exe','');
QuarantineFile('C:\Windows\system32\drivers\eb710bbee7a1753b67b306c392b1c437.sys','');
QuarantineFile('C:\Windows\system32\icacl.exe','');
QuarantineFile('c:\program files (x86)\qyerbvxrhie\ftfuirnlso.exe','');
QuarantineFile('c:\program files\71e14eb66e92df602a4d04116259c9a6\8231a556bf8cda9261345bb8b2d8d0b0.exe','');
QuarantineFile('c:\users\Александр\appdata\roaming\event monitor\em.exe','');
QuarantineFile('c:\users\Александр\appdata\roaming\frostythunder\cloudnet.exe','');
QuarantineFile('c:\windows\microsoft\svchost.exe','');
QuarantineFile('c:\windows\windefender.exe','');
QuarantineFile('C:\Users\Александр\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт.lnk','');
DeleteFile('C:\Users\Александр\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт.lnk','32');
DeleteFile('C:\Program Files (x86)\GXZiGyYLSHyU2\3cQOz6E.dll','32');
DeleteFile('C:\Program Files (x86)\QYERbvxRHIE\kEV8xPB.dll','32');
DeleteFile('C:\Program Files (x86)\thzXuJvjU\E8dYN1d.dll','32');
DeleteFile('C:\Program Files\71e14eb66e92df602a4d04116259c9a6\8231a556bf8cda9261345bb8b2d8d0b0.exe','32');
DeleteFile('C:\Program Files\Common Files\FV7ZO9ID\dcI6Pu9ip.exe','32');
DeleteFile('C:\Program Files\Windows Journal\8Z6IFBTFB95Y49UGHQ42J\qrNNRzxEri.exe','32');
DeleteFile('C:\ProgramData\b1cec899715a40009ade88195260d62f\yVEBLWSiJGa.exe','32');
DeleteFile('C:\ProgramData\e6da7161ec8044e1b20e7bd3962b3b93\j8HQ5IogSFp.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\3b60cb8adf68401d8c2c0e2e9a5e989c\4phIGNDOnj757D.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\406e99fe02604493829f1d9bccd8634e\4Mr9Sa5wdU2YA.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\2a577cf90e3a4d8aa8c770b4de31b375\ZHMPbqEv.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\3249b95708d84622a6dcb8d541adcdcb\bfCtUuXQ.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\46ad0451724a4bab97646622acb533bb\EeI64WXUAN.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\4a63300f549a466a9e4f3c9ad3cdcd52\vEQ9qoin.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\4ab10f3f9d7444f78b746dc1e0330057\V8oXsdk.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\4bab0920df0c4d2f96ef109789bc3d49\Xyzz9uRHdWO.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\539a4e218da546a4ab397a34f98198c3\1vnFfU87.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\6b9f9c484cf047d4ac85b4a583931f93\FWapRlD.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\8dbd7f26225346d08f1b083255d2338e\V6cW9na.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\942b321edcd5429c95a0383b679911ce\wldjfsmkyuuGB.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\a936d70023e442189d883a13419faa71\UZc7PziMCDvup.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\b757a1a53a5544c989f4d62ba25988e6\L3KqZhC9.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\d31ba9cbc6d44c13a0c342083696e61f\QWpPtuWQD.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\d35a5a3db1954a7fba9d05db288db9a2\g3EDVlZUJZLc1.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\f9a659fd0e5448b6848303ba9c5f7b20\93bQdRcV.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\c99bf4a303b84f18a74b813894cff5ca\GYqldfL5vHuQg.exe','32');
DeleteFile('C:\Users\Александр\AppData\Local\wupdate\wupdate.exe','32');
DeleteFile('C:\Users\Александр\AppData\Roaming\20c737ecd717465dbb14cea14115f6fa\uKUHuToxE6.exe','32');
DeleteFile('C:\Users\Александр\AppData\Roaming\7f9ae6a3f27146389b662d5612140065\LmbRZLlSzR.exe','32');
DeleteFile('C:\Users\Александр\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe','32');
DeleteFile('C:\Users\Александр\AppData\Roaming\Event Monitor\em.exe','32');
DeleteFile('C:\Users\Александр\AppData\Roaming\Microsoft\msi.exe','32');
DeleteFile('C:\Users\Александр\AppData\Roaming\SIVApp\SIVApp.exe','32');
DeleteFile('C:\Users\Александр\AppData\Roaming\aswast\ml.py','32');
DeleteFile('C:\Users\Александр\AppData\Roaming\aswast\python\pythonw.exe','32');
DeleteFile('C:\Users\Александр\AppData\Roaming\d8de72ce3c2e4e47a380c174969dcf8c\69XuaAXVcJ7DC.exe','32');
DeleteFile('C:\Users\Александр\AppData\Roaming\f156e196839e4e7ba17711337c9127d0\h7TitKlCkr.exe','32');
DeleteFile('C:\Users\Александр\AppData\Roaming\gplyra\gplyra.exe','32');
DeleteFile('C:\Users\Александр\appdata\local\temp\b.exe','32');
DeleteFile('C:\Users\Александр\appdata\local\wupdate\wupdate.exe','32');
DeleteFile('C:\Users\Александр\appdata\roaming\curl\curl_7_54.exe','32');
DeleteFile('C:\Users\Александр\appdata\roaming\event monitor\em.exe','32');
DeleteFile('C:\Users\Александр\appdata\roaming\event monitor\isxdl.dll','32');
DeleteFile('C:\Users\Александр\appdata\roaming\sivapp\sivapp.exe','32');
DeleteFile('C:\Users\8523~1\AppData\Roaming\SETUPS~1\ml.py','32');
DeleteFile('C:\Users\8523~1\AppData\Roaming\SETUPS~1\python\pythonw.exe','32');
DeleteFile('C:\Users\8523~1\AppData\Roaming\curl\curl.exe','32');
DeleteFile('C:\Users\8523~1\AppData\Roaming\curl\curl_7_54.exe','32');
DeleteFile('C:\Users\8523~1\AppData\Roaming\setupsk\ml.py','32');
DeleteFile('C:\Users\8523~1\AppData\Roaming\setupsk\python\DLLs\_ctypes.pyd','32');
DeleteFile('C:\Users\8523~1\AppData\Roaming\setupsk\python\python34.dll','32');
DeleteFile('C:\Users\8523~1\AppData\Roaming\setupsk\python\pythonw.exe','32');
DeleteFile('C:\Windows\Microsoft\svchost.exe','32');
DeleteFile('C:\Windows\Microsoft\svchost.exe.exe','32');
DeleteFile('C:\Windows\System32\icacl.exe','32');
DeleteFile('C:\Windows\Temp\g3FFC.tmp.exe','32');
DeleteFile('C:\Windows\Temp\g4B70.tmp.exe','32');
DeleteFile('C:\Windows\microsoft\svchost.exe','32');
DeleteFile('C:\Windows\microsoft\svchost.exe.exe','32');
DeleteFile('C:\Windows\system32\Tasks\71e14eb66e92df602a4d04116259c9a6','64');
DeleteFile('C:\Windows\system32\Tasks\FastDataX Task','64');
DeleteFile('C:\Windows\system32\Tasks\MSI','64');
DeleteFile('C:\Windows\system32\Tasks\RunAtStartup','64');
DeleteFile('C:\Windows\system32\Tasks\TnqpiRJoXWMCwN','64');
DeleteFile('C:\Windows\system32\Tasks\curl','64');
DeleteFile('C:\Windows\system32\Tasks\curls','64');
DeleteFile('C:\Windows\system32\Tasks\setupsk','64');
DeleteFile('C:\Windows\system32\Tasks\setupsk_upd','64');
DeleteFile('C:\Windows\system32\Tasks\uuxHwpnMkRCRpJh','64');
DeleteFile('C:\Windows\system32\Tasks\uuxHwpnMkRCRpJh2','64');
DeleteFile('C:\Windows\system32\Tasks\wupdate','64');
DeleteFile('C:\Windows\system32\icacl.exe','32');
DeleteFile('C:\Windows\windefender.exe','32');
DeleteFile('c:\program files (x86)\qyerbvxrhie\ftfuirnlso.exe','32');
DeleteFile('c:\program files\71e14eb66e92df602a4d04116259c9a6\8231a556bf8cda9261345bb8b2d8d0b0.exe','32');
DeleteFile('c:\users\Александр\appdata\roaming\event monitor\em.exe','32');
DeleteFile('c:\users\Александр\appdata\roaming\frostythunder\cloudnet.exe','32');
DeleteFile('c:\users\8523~1\appdata\roaming\setupsk\python\pythonw.exe','32');
DeleteFile('c:\windows\microsoft\svchost.exe','32');
DeleteFile('c:\windows\windefender.exe','32');
DeleteService('71e14eb66e92df602a4d04116259c9a6');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','4Mr9Sa5wdU2YA.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','4phIGNDOnj757D.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','69XuaAXVcJ7DC.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','93bQdRcV.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','EeI64WXUAN.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','FWapRlD.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','GYqldfL5vHuQg.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','L3KqZhC9.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','LmbRZLlSzR.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','QWpPtuWQD.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','SIVApp');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','UZc7PziMCDvup.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','V8oXsdk.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Xyzz9uRHdWO.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ZHMPbqEv.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','bfCtUuXQ.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','cloudnet');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','cmhvissniw');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','g3EDVlZUJZLc1.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','h7TitKlCkr.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','j8HQ5IogSFp.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','qrNNRzxEri.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','setupsk');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','setupsk_upd');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','uKUHuToxE6.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','vEQ9qoin.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','wldjfsmkyuuGB.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','yVEBLWSiJGa.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\aswast','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gplyra');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','АЛЕКСАНДР-ПК');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
После выполнения скрипта компьютер перезагрузится.