Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\Андрей\AppData\Local\Google\Software Reporter Tool\googledrives.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\Flash Player\Software\update_flashplayer.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\RunnerControl.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\SearchUI.exe','');
QuarantineFile('C:\Users\uuuu\AppData\Local\.IdentityService\RunnerControl.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\RemindersServer.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\Receiver.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\PlacesServer.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\NetworkCaptivePortal.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\MixedRealityPortal.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\MicrosoftPdfReader.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\Microsoft.AsyncTextService.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\WindowsInternal.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\Win32WebViewHost.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\ShellExperienceHost.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\PeopleExperienceHost.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\NetworkConnectionFlow.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\FilePicker.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\FileExplorer.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\BioEnrollment.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\PinningConfirmationDialog.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\CredDialogHost.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\CapturePicker.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\CHXSmartScreen.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\CameraBarcodeScannerPreview.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\BioEnrollmentHost.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\AppResolverUX.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\RemindersShareTargetApp.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\LockApp.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\AssignedAccessLockApp.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\AddSuggestedFoldersToLibraryDialog.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\ActionUriServer.exe','');
QuarantineFile('C:\Users\Андрей\AppData\Local\.IdentityService\AccountsControlHost.exe','');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\AccountsControlHost.exe','32');
DeleteFile('C:\Windows\system32\Tasks\AccountsControlHost','64');
DeleteFile('C:\Windows\system32\Tasks\ActionUriServer','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\ActionUriServer.exe','32');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\AddSuggestedFoldersToLibraryDialog.exe','32');
DeleteFile('C:\Windows\system32\Tasks\AddSuggestedFoldersToLibraryDialog','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\AssignedAccessLockApp.exe','32');
DeleteFile('C:\Windows\system32\Tasks\AppAssignedAccessLock','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\LockApp.exe','32');
DeleteFile('C:\Windows\system32\Tasks\AppLock','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\RemindersShareTargetApp.exe','32');
DeleteFile('C:\Windows\system32\Tasks\AppRemindersShareTarget','64');
DeleteFile('C:\Windows\system32\Tasks\AppResolverUX','64');
DeleteFile('C:\Windows\system32\Tasks\AssignedAccessLockApp','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\AppResolverUX.exe','32');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\BioEnrollmentHost.exe','32');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\CameraBarcodeScannerPreview.exe','32');
DeleteFile('C:\Windows\system32\Tasks\CameraBarcodeScannerPreview','64');
DeleteFile('C:\Windows\system32\Tasks\BioEnrollmentHost','64');
DeleteFile('C:\Windows\system32\Tasks\CapturePicker','64');
DeleteFile('C:\Windows\system32\Tasks\CHXSmartScreen','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\CHXSmartScreen.exe','32');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\CapturePicker.exe','32');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\CredDialogHost.exe','32');
DeleteFile('C:\Windows\system32\Tasks\DialogAddSuggestedFoldersToLibrary','64');
DeleteFile('C:\Windows\system32\Tasks\CredDialogHost','64');
DeleteFile('C:\Windows\system32\Tasks\DialogPinningConfirmation','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\PinningConfirmationDialog.exe','32');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\BioEnrollment.exe','32');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\FileExplorer.exe','32');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\FilePicker.exe','32');
DeleteFile('C:\Windows\system32\Tasks\FilePicker','64');
DeleteFile('C:\Windows\system32\Tasks\FileExplorer','64');
DeleteFile('C:\Windows\system32\Tasks\ExplorerFile','64');
DeleteFile('C:\Windows\system32\Tasks\EnrollmentBio','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\NetworkConnectionFlow.exe','32');
DeleteFile('C:\Windows\system32\Tasks\HostCredDialog','64');
DeleteFile('C:\Windows\system32\Tasks\HostBioEnrollment','64');
DeleteFile('C:\Windows\system32\Tasks\HostAccountsControl','64');
DeleteFile('C:\Windows\system32\Tasks\FlowNetworkConnection','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\PeopleExperienceHost.exe','32');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\ShellExperienceHost.exe','32');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\Win32WebViewHost.exe','32');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\WindowsInternal.exe','32');
DeleteFile('C:\Windows\system32\Tasks\InternalWindows','64');
DeleteFile('C:\Windows\system32\Tasks\HostWin32WebView','64');
DeleteFile('C:\Windows\system32\Tasks\HostShellExperience','64');
DeleteFile('C:\Windows\system32\Tasks\HostPeopleExperience','64');
DeleteFile('C:\Windows\system32\Tasks\LockApp','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\Microsoft.AsyncTextService.exe','32');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\MicrosoftPdfReader.exe','32');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\MixedRealityPortal.exe','32');
DeleteFile('C:\Windows\system32\Tasks\MixedRealityPortal','64');
DeleteFile('C:\Windows\system32\Tasks\MicrosoftPdfReader','64');
DeleteFile('C:\Windows\system32\Tasks\Microsoft.AsyncTextService','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\NetworkCaptivePortal.exe','32');
DeleteFile('C:\Windows\system32\Tasks\NetworkConnectionFlow','64');
DeleteFile('C:\Windows\system32\Tasks\NetworkCaptivePortal','64');
DeleteFile('C:\Windows\system32\Tasks\PeopleExperienceHost','64');
DeleteFile('C:\Windows\system32\Tasks\PickerCapture','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\PlacesServer.exe','32');
DeleteFile('C:\Windows\system32\Tasks\PortalMixedReality','64');
DeleteFile('C:\Windows\system32\Tasks\PlacesServer','64');
DeleteFile('C:\Windows\system32\Tasks\PinningConfirmationDialog','64');
DeleteFile('C:\Windows\system32\Tasks\PickerFile','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\Receiver.exe','32');
DeleteFile('C:\Windows\system32\Tasks\ReaderReceiver','64');
DeleteFile('C:\Windows\system32\Tasks\ReaderMicrosoftPdf','64');
DeleteFile('C:\Windows\system32\Tasks\PreviewCameraBarcodeScanner','64');
DeleteFile('C:\Windows\system32\Tasks\PortalNetworkCaptive','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\RemindersServer.exe','32');
DeleteFile('C:\Users\uuuu\AppData\Local\.IdentityService\RunnerControl.exe','32');
DeleteFile('C:\Windows\system32\Tasks\ScreenCHXSmart','64');
DeleteFile('C:\Windows\system32\Tasks\Runner','64');
DeleteFile('C:\Windows\system32\Tasks\RemindersShareTargetApp','64');
DeleteFile('C:\Windows\system32\Tasks\RemindersServer','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\SearchUI.exe','32');
DeleteFile('C:\Windows\system32\Tasks\ServerReminders','64');
DeleteFile('C:\Windows\system32\Tasks\ServerPlaces','64');
DeleteFile('C:\Windows\system32\Tasks\ServerActionUri','64');
DeleteFile('C:\Windows\system32\Tasks\SearchUI','64');
DeleteFile('C:\Users\Андрей\AppData\Local\.IdentityService\RunnerControl.exe','32');
DeleteFile('C:\Windows\system32\Tasks\UISearch','64');
DeleteFile('C:\Windows\system32\Tasks\SynapNvTm','64');
DeleteFile('C:\Windows\system32\Tasks\ShellExperienceHost','64');
DeleteFile('C:\Windows\system32\Tasks\ServiceMicrosoft.AsyncText','64');
DeleteFile('C:\Users\Андрей\AppData\Local\Flash Player\Software\update_flashplayer.exe','32');
DeleteFile('C:\Users\Андрей\AppData\Local\Google\Software Reporter Tool\googledrives.exe','32');
DeleteFile('C:\Windows\system32\Tasks\WindowsInternal','64');
DeleteFile('C:\Windows\system32\Tasks\Win32WebViewHost','64');
DeleteFile('C:\Windows\system32\Tasks\UXAppResolver','64');
DeleteFile('C:\Windows\system32\Tasks\Update_GoogleDrivers','64');
DeleteFile('C:\Windows\system32\Tasks\Update_FlashPlayer','64');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.