Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\112121ув\AppData\Roaming\sFTUSNNXYuVn.exe','');
QuarantineFile('C:\Windows\SysWOW64\FQGW.exe','');
QuarantineFile('C:\Users\112121ув\AppData\Local\UYYeCUMhabooU.exe','');
QuarantineFile('C:\Program Files (x86)\ToGynewEQir.exe','');
QuarantineFile('C:\Users\112121ув\AppData\Local\VirtualStore\3467246804_123.exe','');
QuarantineFile('C:\Users\112121ув\AppData\Local\Temp\csrss\scheduled.exe','');
QuarantineFile('C:\ProgramData\Kolnixo\SumLab.dll','');
QuarantineFile('C:\ProgramData\Kolnixo\Konktrax.dll','');
SetServiceStart('WinmonSystemMonitor', 4);
DeleteService('WinmonSystemMonitor');
SetServiceStart('WinmonProcessMonitor', 4);
DeleteService('WinmonProcessMonitor');
SetServiceStart('WinmonFS', 4);
DeleteService('WinmonFS');
SetServiceStart('Winmon', 4);
DeleteService('Winmon');
SetServiceStart('WinDefender', 4);
DeleteService('WinDefender');
SetServiceStart('Nettrans', 4);
DeleteService('Nettrans');
SetServiceStart('Kolnixo', 4);
DeleteService('Kolnixo');
SetServiceStart('CRMSvc', 4);
DeleteService('CRMSvc');
SetServiceStart('backlh', 4);
DeleteService('backlh');
QuarantineFile('C:\Windows\System32\drivers\WinmonSystemMonitor.sys','');
QuarantineFile('C:\Windows\System32\drivers\WinmonProcessMonitor.sys','');
QuarantineFile('C:\Windows\System32\drivers\WinmonFS.sys','');
QuarantineFile('C:\Windows\System32\drivers\Winmon.sys','');
QuarantineFile('C:\Windows\worcpxzudfjgioym.wfrcp','');
TerminateProcessByName('c:\windows\windefender.exe');
QuarantineFile('c:\windows\windefender.exe','');
TerminateProcessByName('c:\programdata\windowsmenu\westat.exe');
QuarantineFile('c:\programdata\windowsmenu\westat.exe','');
TerminateProcessByName('c:\programdata\logic cramble\set.exe');
QuarantineFile('c:\programdata\logic cramble\set.exe','');
QuarantineFile('c:\programdata\prefssecure\nettrans.exe','');
TerminateProcessByName('c:\programdata\kolnixo\kolnixo.exe');
QuarantineFile('c:\programdata\kolnixo\kolnixo.exe','');
TerminateProcessByName('c:\windows\rss\csrss.exe');
QuarantineFile('c:\windows\rss\csrss.exe','');
TerminateProcessByName('C:\Users\112121ув\AppData\Roaming\CRMSvc\CRMSvc.exe');
QuarantineFile('C:\Users\112121ув\AppData\Roaming\CRMSvc\CRMSvc.exe','');
QuarantineFile('c:\programdata\cpafservice\cpafservice.exe','');
TerminateProcessByName('c:\users\112121ув\appdata\local\temp\csrss\cloudnet.exe');
QuarantineFile('c:\users\112121ув\appdata\local\temp\csrss\cloudnet.exe','');
DeleteFile('c:\users\112121ув\appdata\local\temp\csrss\cloudnet.exe','32');
DeleteFile('C:\Users\112121ув\AppData\Roaming\CRMSvc\CRMSvc.exe','32');
DeleteFile('c:\windows\rss\csrss.exe','32');
DeleteFile('c:\programdata\kolnixo\kolnixo.exe','32');
DeleteFile('c:\programdata\logic cramble\set.exe','32');
DeleteFile('c:\programdata\windowsmenu\westat.exe','32');
DeleteFile('c:\windows\windefender.exe','32');
DeleteFile('C:\Windows\worcpxzudfjgioym.wfrcp','32');
DeleteFile('C:\Windows\System32\drivers\Winmon.sys','32');
DeleteFile('C:\Windows\System32\drivers\WinmonFS.sys','32');
DeleteFile('C:\Windows\System32\drivers\WinmonProcessMonitor.sys','32');
DeleteFile('C:\Windows\System32\drivers\WinmonSystemMonitor.sys','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','chrome');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ShyWind');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','CloudNet');
DeleteFile('C:\ProgramData\Kolnixo\Konktrax.dll','32');
DeleteFile('C:\ProgramData\Kolnixo\SumLab.dll','32');
DeleteFile('C:\Windows\system32\Tasks\hdtask','64');
DeleteFile('C:\Windows\system32\Tasks\csrss','64');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\QuickLaunch','64');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\Starter','64');
DeleteFile('C:\Windows\system32\Tasks\ScheduledUpdate','64');
DeleteFile('C:\Users\112121ув\AppData\Local\Temp\csrss\scheduled.exe','32');
DeleteFile('C:\Windows\system32\Tasks\VirtualStore Updater','64');
DeleteFile('C:\Users\112121ув\AppData\Local\VirtualStore\3467246804_123.exe','32');
DeleteFile('C:\Windows\system32\Tasks\{084FC92B-1EE8-03D9-3176-5A85DDF2D070}','64');
DeleteFile('C:\Program Files (x86)\ToGynewEQir.exe','32');
DeleteFile('C:\Users\112121ув\AppData\Local\UYYeCUMhabooU.exe','32');
DeleteFile('C:\Windows\system32\Tasks\{4594B241-6716-4FB8-405F-89E3DCF65F2C}','64');
DeleteFile('C:\Windows\system32\Tasks\{4CD19F27-5FB3-C1FC-E271-D341E71EB7AA}','64');
DeleteFile('C:\Windows\SysWOW64\FQGW.exe','32');
DeleteFile('C:\Users\112121ув\AppData\Roaming\sFTUSNNXYuVn.exe','32');
DeleteFile('C:\Windows\system32\Tasks\{F3A1E84F-5D35-CD2D-E677-6EDB28B54F17}','64');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.