Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
DelBHO('{C0D38E5A-7CF8-4105-8FE8-31B81443A114}');
TerminateProcessByName('c:\temp\is-im66c.tmp\tvvzhsobcfe.tmp');
TerminateProcessByName('c:\users\ella\appdata\roaming\zhikmyavgli\tvvzhsobcfe.exe');
TerminateProcessByName('c:\users\ella\appdata\local\temp\csrss\proxy\tor.exe');
TerminateProcessByName('c:\users\ella\appdata\local\temp\csrss\proxy\obfs4proxy.exe');
TerminateProcessByName('c:\program files (x86)\ljfujmgehie\iteynryvpe.exe');
TerminateProcessByName('c:\temp\is-1sea6.tmp\bphclph1fjy.tmp');
TerminateProcessByName('c:\users\ella\appdata\roaming\hcoajtgv44b\bphclph1fjy.exe');
TerminateProcessByName('c:\program files\b0985b53bdfcff625e52dae24b8fe992\3c1f09b303ad2b815c9cdabedf989eee.exe');
StopService('3045b926276952b3e4a3ef1fc2c60028');
StopService('Voyasollam');
StopService('TCPSvc');
StopService('b0985b53bdfcff625e52dae24b8fe992');
StopService('7eaca161d1edfc245f341853fb8e1e68');
DeleteService('3045b926276952b3e4a3ef1fc2c60028');
DeleteService('Voyasollam');
DeleteService('TCPSvc');
DeleteService('b0985b53bdfcff625e52dae24b8fe992');
DeleteService('7eaca161d1edfc245f341853fb8e1e68');
QuarantineFile('C:\Windows\system32\EhStorShell.dll','');
QuarantineFile('C:\Program Files (x86)\ijcQGTqqPStU2\kYcWvGcneiuIr.dll','');
QuarantineFile('C:\ProgramData\XjOPTLXDzAynQaVB\dwjOZSz.wsf','');
QuarantineFile('C:\Program Files (x86)\wCCFxMJCsZmzC\RlTFxIu.dll','');
QuarantineFile('C:\Program Files (x86)\SystemHealer\HealerConsole.exe','');
QuarantineFile('C:\Program Files (x86)\EgDGbQEiU\YWGniI.dll','');
QuarantineFile('C:\PROGRA~2\FASTDA~1\FASTDA~1.EXE','');
QuarantineFile('C:\Program Files (x86)\SystemHealer\SystemHealer.exe','');
QuarantineFile('C:\ProgramData\Voyasollam\Xxx-tantrax.dll','');
QuarantineFile('C:\ProgramData\Voyasollam\U-top.dll','');
QuarantineFile('C:\Users\Ella\AppData\Roaming\hcoajtgv44b\bphclph1fjy.exe','');
QuarantineFile('C:\Users\Ella\AppData\Roaming\zhikmyavgli\tvvzhsobcfe.exe','');
QuarantineFile('C:\Windows\System32\drivers\Winmon.sys','');
QuarantineFile('C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe','');
QuarantineFile('C:\ProgramData\Voyasollam\Voyasollam.exe','');
QuarantineFile('C:\Windows\System32\mracsvc.exe','');
QuarantineFile('C:\Users\Ella\AppData\Local\Temp\csrss\proxy\tor.exe','');
QuarantineFile('C:\Program Files\b0985b53bdfcff625e52dae24b8fe992\3c1f09b303ad2b815c9cdabedf989eee.exe','');
QuarantineFile('C:\Windows\iTranslator','');
QuarantineFile('C:\Windows\iNetfilterSvc','');
QuarantineFile('C:\Windows\system32\drivers\3045b926276952b3e4a3ef1fc2c60028.sys','');
QuarantineFile('C:\Windows\iaaclpptmbsklggq.iaac','');
QuarantineFile('C:\Users\Ella\AppData\Local\Temp\qfilXCPnFgThYSRzs\DzQNPNUdCFQTgBxx\bUTGqcAzipPuilyC.dll','');
QuarantineFile('C:\Temp\is-GPP60.tmp\idp.dll','');
QuarantineFile('C:\Temp\is-5K236.tmp\idp.dll','');
QuarantineFile('C:\Program Files (x86)\OxoywZINBbQwrioRGrR\OBGoohf.dll','');
QuarantineFile('C:\Program Files (x86)\lJFUJMGEHIE\r7zQg.dll','');
QuarantineFile('C:\Program Files (x86)\lJFUJMGEHIE\kGzWr4oY.dll','');
QuarantineFile('c:\temp\is-im66c.tmp\tvvzhsobcfe.tmp','');
QuarantineFile('c:\users\ella\appdata\roaming\zhikmyavgli\tvvzhsobcfe.exe','');
QuarantineFile('c:\users\ella\appdata\local\temp\csrss\proxy\tor.exe','');
QuarantineFile('c:\users\ella\appdata\local\temp\csrss\proxy\obfs4proxy.exe','');
QuarantineFile('c:\program files (x86)\ljfujmgehie\iteynryvpe.exe','');
QuarantineFile('c:\temp\is-1sea6.tmp\bphclph1fjy.tmp','');
QuarantineFile('c:\users\ella\appdata\roaming\hcoajtgv44b\bphclph1fjy.exe','');
QuarantineFile('c:\program files\b0985b53bdfcff625e52dae24b8fe992\3c1f09b303ad2b815c9cdabedf989eee.exe','');
DeleteFile('c:\program files\b0985b53bdfcff625e52dae24b8fe992\3c1f09b303ad2b815c9cdabedf989eee.exe','32');
DeleteFile('c:\temp\is-1sea6.tmp\bphclph1fjy.tmp','32');
DeleteFile('c:\program files (x86)\ljfujmgehie\iteynryvpe.exe','32');
DeleteFile('c:\users\ella\appdata\local\temp\csrss\proxy\obfs4proxy.exe','32');
DeleteFile('c:\users\ella\appdata\local\temp\csrss\proxy\tor.exe','32');
DeleteFile('c:\users\ella\appdata\roaming\zhikmyavgli\tvvzhsobcfe.exe','32');
DeleteFile('c:\temp\is-im66c.tmp\tvvzhsobcfe.tmp','32');
DeleteFile('C:\Program Files (x86)\lJFUJMGEHIE\kGzWr4oY.dll','32');
DeleteFile('C:\Program Files (x86)\lJFUJMGEHIE\r7zQg.dll','32');
DeleteFile('C:\Program Files (x86)\OxoywZINBbQwrioRGrR\OBGoohf.dll','32');
DeleteFile('C:\Users\Ella\AppData\Local\Temp\qfilXCPnFgThYSRzs\DzQNPNUdCFQTgBxx\bUTGqcAzipPuilyC.dll','32');
DeleteFile('C:\Windows\iaaclpptmbsklggq.iaac','32');
DeleteFile('C:\Program Files\b0985b53bdfcff625e52dae24b8fe992\3c1f09b303ad2b815c9cdabedf989eee.exe','32');
DeleteFile('C:\Users\Ella\AppData\Local\Temp\csrss\proxy\tor.exe','32');
DeleteFile('C:\ProgramData\Voyasollam\Voyasollam.exe','32');
DeleteFile('C:\Windows\system32\drivers\3045b926276952b3e4a3ef1fc2c60028.sys','32');
DeleteFile('C:\Users\Ella\AppData\Roaming\zhikmyavgli\tvvzhsobcfe.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','3695050');
DeleteFile('C:\Users\Ella\AppData\Roaming\hcoajtgv44b\bphclph1fjy.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','5924914');
DeleteFile('C:\ProgramData\Voyasollam\U-top.dll','32');
DeleteFile('C:\ProgramData\Voyasollam\Xxx-tantrax.dll','32');
DeleteFile('C:\Program Files (x86)\SystemHealer\SystemHealer.exe','32');
DeleteFile('C:\Windows\Tasks\System HealerPeriod.job','32');
DeleteFile('C:\Windows\Tasks\System HealerStartUp.job','32');
DeleteFile('C:\Windows\system32\Tasks\FastDataX Task','64');
DeleteFile('C:\PROGRA~2\FASTDA~1\FASTDA~1.EXE','32');
ExecuteFile('schtasks.exe', '/delete /TN "KnPQHVchzdGfrlHaz2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "rArHIXNWKfbeRtR2" /F', 0, 15000, true);
DeleteFile('C:\Program Files (x86)\EgDGbQEiU\YWGniI.dll','32');
ExecuteFile('schtasks.exe', '/delete /TN "System Healer Delayed" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "System Healer Monitor" /F', 0, 15000, true);
DeleteFile('C:\Program Files (x86)\SystemHealer\HealerConsole.exe','32');
ExecuteFile('schtasks.exe', '/delete /TN "System HealerPeriod" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "System HealerStartUp" /F', 0, 15000, true);
DeleteFile('C:\Windows\system32\Tasks\System HealerStartUp','64');
DeleteFile('C:\Program Files (x86)\wCCFxMJCsZmzC\RlTFxIu.dll','32');
ExecuteFile('schtasks.exe', '/delete /TN "TdqeVjasHzsikvrWtEm2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "WobUIKhuMtTTi2" /F', 0, 15000, true);
DeleteFile('C:\ProgramData\XjOPTLXDzAynQaVB\dwjOZSz.wsf','32');
ExecuteFile('schtasks.exe', '/delete /TN "XLqsfoKFUKuTqG" /F', 0, 15000, true);
DeleteFile('C:\Program Files (x86)\ijcQGTqqPStU2\kYcWvGcneiuIr.dll','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
После выполнения скрипта компьютер перезагрузится.