Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\1\AppData\Local\Hostinstaller\1685484646_monster.exe','');
DelBHO('{10921475-03CE-4E04-90CE-E2E7EF20C814}');
DelBHO('{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}');
DeleteService('Voyasollam');
QuarantineFile('c:\disk\securedisk.exe','');
QuarantineFile('c:\disk\webservice.exe','');
TerminateProcessByName('c:\users\1\appdata\local\temp\is-3ed4s.tmp\sghmzhlr0gs.tmp');
QuarantineFile('c:\users\1\appdata\local\temp\is-3ed4s.tmp\sghmzhlr0gs.tmp','');
TerminateProcessByName('c:\users\1\appdata\roaming\l2yvsncb53r\sghmzhlr0gs.exe');
QuarantineFile('c:\users\1\appdata\roaming\l2yvsncb53r\sghmzhlr0gs.exe','');
TerminateProcessByName('c:\users\1\appdata\local\temp\is-pjeh1.tmp\lsap4vaj1si.tmp');
QuarantineFile('c:\users\1\appdata\local\temp\is-pjeh1.tmp\lsap4vaj1si.tmp','');
TerminateProcessByName('c:\users\1\appdata\roaming\kpcjn1k4y1o\lsap4vaj1si.exe');
QuarantineFile('c:\users\1\appdata\roaming\kpcjn1k4y1o\lsap4vaj1si.exe','');
TerminateProcessByName('c:\users\1\appdata\local\temp\is-b29mr.tmp\kucxxrcvk34.tmp');
QuarantineFile('c:\users\1\appdata\local\temp\is-b29mr.tmp\kucxxrcvk34.tmp','');
TerminateProcessByName('c:\users\1\appdata\roaming\sh3pibnl3gf\kucxxrcvk34.exe');
QuarantineFile('c:\users\1\appdata\roaming\sh3pibnl3gf\kucxxrcvk34.exe','');
TerminateProcessByName('c:\users\1\appdata\local\temp\is-ck8f3.tmp\iuze513f3ce.tmp');
QuarantineFile('c:\users\1\appdata\local\temp\is-ck8f3.tmp\iuze513f3ce.tmp','');
TerminateProcessByName('c:\users\1\appdata\roaming\t2hp5idvlm0\iuze513f3ce.exe');
QuarantineFile('c:\users\1\appdata\roaming\t2hp5idvlm0\iuze513f3ce.exe','');
TerminateProcessByName('c:\users\1\appdata\local\temp\is-ubdbk.tmp\ioz1dkz20fe.tmp');
QuarantineFile('c:\users\1\appdata\local\temp\is-ubdbk.tmp\ioz1dkz20fe.tmp','');
TerminateProcessByName('c:\users\1\appdata\roaming\54fe34qkmrl\ioz1dkz20fe.exe');
QuarantineFile('c:\users\1\appdata\roaming\54fe34qkmrl\ioz1dkz20fe.exe','');
TerminateProcessByName('c:\users\1\appdata\local\temp\is-tfhbe.tmp\gg0fuixrctf.tmp');
QuarantineFile('c:\users\1\appdata\local\temp\is-tfhbe.tmp\gg0fuixrctf.tmp','');
TerminateProcessByName('c:\users\1\appdata\roaming\ewifmaaymod\gg0fuixrctf.exe');
QuarantineFile('c:\users\1\appdata\roaming\ewifmaaymod\gg0fuixrctf.exe','');
TerminateProcessByName('c:\users\1\appdata\roaming\crmsvc\crmsvc.exe');
QuarantineFile('c:\users\1\appdata\roaming\crmsvc\crmsvc.exe','');
TerminateProcessByName('c:\users\1\appdata\local\temp\is-8elm7.tmp\clmbnfrsfvn.tmp');
QuarantineFile('c:\users\1\appdata\local\temp\is-8elm7.tmp\clmbnfrsfvn.tmp','');
TerminateProcessByName('c:\users\1\appdata\roaming\qyz2dwwguab\clmbnfrsfvn.exe');
QuarantineFile('c:\users\1\appdata\roaming\qyz2dwwguab\clmbnfrsfvn.exe','');
TerminateProcessByName('c:\users\1\appdata\local\temp\is-gf46v.tmp\3irgg15tcq4.tmp');
QuarantineFile('c:\users\1\appdata\local\temp\is-gf46v.tmp\3irgg15tcq4.tmp','');
TerminateProcessByName('c:\users\1\appdata\roaming\jnojbu5twsv\3irgg15tcq4.exe');
QuarantineFile('c:\users\1\appdata\roaming\jnojbu5twsv\3irgg15tcq4.exe','');
TerminateProcessByName('c:\users\1\appdata\local\temp\is-83o5p.tmp\2fmfalmdgmq.tmp');
QuarantineFile('c:\users\1\appdata\local\temp\is-83o5p.tmp\2fmfalmdgmq.tmp','');
TerminateProcessByName('c:\users\1\appdata\roaming\wwd343b03so\2fmfalmdgmq.exe');
QuarantineFile('c:\users\1\appdata\roaming\wwd343b03so\2fmfalmdgmq.exe','');
DeleteFile('c:\users\1\appdata\roaming\wwd343b03so\2fmfalmdgmq.exe','32');
DeleteFile('c:\users\1\appdata\local\temp\is-83o5p.tmp\2fmfalmdgmq.tmp','32');
DeleteFile('c:\users\1\appdata\roaming\jnojbu5twsv\3irgg15tcq4.exe','32');
DeleteFile('c:\users\1\appdata\local\temp\is-gf46v.tmp\3irgg15tcq4.tmp','32');
DeleteFile('c:\users\1\appdata\roaming\qyz2dwwguab\clmbnfrsfvn.exe','32');
DeleteFile('c:\users\1\appdata\local\temp\is-8elm7.tmp\clmbnfrsfvn.tmp','32');
DeleteFile('c:\users\1\appdata\roaming\crmsvc\crmsvc.exe','32');
DeleteFile('c:\users\1\appdata\roaming\ewifmaaymod\gg0fuixrctf.exe','32');
DeleteFile('c:\users\1\appdata\local\temp\is-tfhbe.tmp\gg0fuixrctf.tmp','32');
DeleteFile('c:\users\1\appdata\roaming\54fe34qkmrl\ioz1dkz20fe.exe','32');
DeleteFile('c:\users\1\appdata\local\temp\is-ubdbk.tmp\ioz1dkz20fe.tmp','32');
DeleteFile('c:\users\1\appdata\roaming\t2hp5idvlm0\iuze513f3ce.exe','32');
DeleteFile('c:\users\1\appdata\local\temp\is-ck8f3.tmp\iuze513f3ce.tmp','32');
DeleteFile('c:\users\1\appdata\roaming\sh3pibnl3gf\kucxxrcvk34.exe','32');
DeleteFile('c:\users\1\appdata\local\temp\is-b29mr.tmp\kucxxrcvk34.tmp','32');
DeleteFile('c:\users\1\appdata\roaming\kpcjn1k4y1o\lsap4vaj1si.exe','32');
DeleteFile('c:\users\1\appdata\local\temp\is-pjeh1.tmp\lsap4vaj1si.tmp','32');
DeleteFile('c:\users\1\appdata\roaming\l2yvsncb53r\sghmzhlr0gs.exe','32');
DeleteFile('c:\users\1\appdata\local\temp\is-3ed4s.tmp\sghmzhlr0gs.tmp','32');
DeleteFile('C:\ProgramData\Voyasollam\Voyasollam.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','7532337');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','5727512');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','8441720');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','6978010');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','228496');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','5174461');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','2745928');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','8738491');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','8908990');
DeleteFile('C:\PROGRA~1\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll','32');
DeleteFile('C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll','32');
DeleteFile('C:\Windows\system32\Tasks\hostTask','32');
DeleteFile('C:\Windows\system32\Tasks\Kerish Doctor','32');
DeleteFile('C:\Windows\system32\Tasks\MailRuUpdater','32');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\F13F7548334FA6CFAE7AEC48D4A7D542','32');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\F13F7548334FA6CFAE7AEC48D4A7D542SB','32');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\KRBUUS\KRB Updater Utility Service','32');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\KRBUUS\KRBLNKRUN','32');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\A0E0CFF8C-FC55-449E-8DA7-2EDFE5566184','32');
DeleteFile('C:\ProgramData\Microsoft\Adobe\Flash Player\0E0CFF8C-FC55-449E-8DA7-2EDFE5566184\33C6B7F8-86F7-48CA-9E6D-FEB0CCE8A5E7.exe','32');
DeleteFile('C:\Program Files\Kinoroom Browser\krbrowser.exe','32');
DeleteFile('C:\ProgramData\KRB Updater Utility\krbupdater.exe','32');
DeleteFile('C:\Users\1\AppData\Local\Microsoft\6CB0F9CF6D2A91975DE404CE4D3A1595\A7D5424D84CEA7EAFC6AF43384F13F75.exe','32');
DeleteFile('C:\Program Files\Kerish Doctor\KerishDoctor.exe','32');
DeleteFile('C:\Users\1\AppData\Local\Hostinstaller\1685484646_monster.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Uninstaller_SkipUac_1','32');
DeleteFile('C:\Windows\system32\Tasks\Soft installer','32');
DeleteFile('C:\Windows\system32\Tasks\urlopener','32');
DeleteFile('C:\Users\1\AppData\Local\Amigo\Application\amigo.exe','32');
DeleteFile('C:\Windows\system32\Tasks\{77E5E0D9-4299-49E1-A235-290DB1E6700E}','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.