begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
TerminateProcessByName('C:\Users\Токарев\AppData\Local\PNRP32\wmpshell.exe');
TerminateProcessByName('c:\program files (x86)\iobit\iobit uninstaller\uninstallmonitor.exe');
TerminateProcessByName('C:\Windows\Sys\taskmgr.exe');
TerminateProcessByName('c:\programdata\saophase\saophase.exe');
TerminateProcessByName('C:\Program Files\fchk32\packages\62a80007-575d-4582-a208-73a2614d64e5\NixHost.exe');
TerminateProcessByName('c:\program files (x86)\iobit\liveupdate\iobitlauncher.exe');
TerminateProcessByName('C:\Program Files\fchk32\fchk32.exe');
TerminateProcessByName('c:\programdata\saophase\dingtonlax.exe');
SetServiceStart('ExtTag', 4);
SetServiceStart('dinohemo', 4);
SetServiceStart('Saophase', 4);
SetServiceStart('fchk32', 4);
SetServiceStart('C_28597', 4);
StopService('ExtTag');
StopService('dinohemo');
StopService('Saophase');
StopService('fchk32');
StopService('C_28597');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\AdobeFlash\adobe.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\CheckService32\check.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\COMODOChromodo\nsisvc.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\COMODOVirtual\comodo.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\AMOTCFW\dhcp-клиент32.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\DNS15625\dns-клиент.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\MicrosoftNET\evr.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\MicrosoftNET\deviceuxres.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\MicrosoftNET\cttunesvr.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\NewDocument\wmspdmoe.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\QualityWindows\lvco13101216.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\QualityWindows\quality.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\SkypeUpdater32\kbdest.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\WindowsAudio32\korwbrkr.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\igfxrrom.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\dpx.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\32\службы.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\удаленный.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\32\framebuf.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\tscon.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\cryptxml.exe', '');
QuarantineFile('C:\Windows\SysWOW64\guard32.dll', '');
QuarantineFile('C:\Windows\microsoft\sogrmed\media player zupdater.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\vds_ps.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\fxsroute.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\c_1144.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\служба.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\Google\wlanpref.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\Google\glmf32.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\srhelper.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\FNYUKMQ\hccutils.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\kbdinmar.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\32\msftedit.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\OKXSDBF\kbda3.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\atipblag.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\c_864.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\kbdycc.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\модуль.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\модули.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\локатор.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\SNMP\ловушка.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\themecpl.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\диспетчер.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\Windows32\брандмауэр.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\Windows\apisetschema.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\xwtpw32.exe', '');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Local\адаптивная.exe', '');
QuarantineFile('C:\Users\Токарев\AppData\Roaming\mystartsearch\UninstallManager.exe', '');
QuarantineFile('C:\Users\Токарев\AppData\Roaming\istartsurf\UninstallManager.exe', '');
QuarantineFile('C:\Users\Токарев\AppData\Roaming\ZorzjrQipU.exe', '');
QuarantineFile('C:\Users\Токарев\AppData\Roaming\OtVdi00YYfJn.exe', '');
QuarantineFile('C:\Program Files (x86)\Internet Explorer\iexplore.bat', '');
QuarantineFile('C:\ProgramData\ExtTag\iedto40a.dll', '');
QuarantineFile('C:\Windows\Sys\taskmgr.vbs', '');
QuarantineFile('provider\html5locsvc.exe', '');
QuarantineFile('C:\ProgramData\AlterGeo\Update', '');
QuarantineFile('C:\Windows\Microsoft\UpdatingServiceMed\Media Player ZNewVersionDownloader.exe', '');
QuarantineFile('C:\Program Files (x86)\Common Files\1c1e4ef3-a4fe-42a4-a546-08f69e47d2d1\updater.exe', '');
QuarantineFile('C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe', '');
QuarantineFile('C:\ProgramData\ExtTag\ExtTag', '');
QuarantineFile('C:\Program Files (x86)\03000200-1438968807-0500-0006-000700080009\knso7693.tmp', '');
QuarantineFileF('C:\Program Files (x86)\03000200-1438968807-0500-0006-000700080009', '*', true, '', 0 , 0);
QuarantineFile('C:\Program Files\Internet Explorer\iexplore.bat', '');
QuarantineFile('C:\Program Files\Opera x64\opera.bat', '');
QuarantineFile('C:\Users\Токарев\AppData\Roaming\Browsers\exe.arepo.bat', '');
QuarantineFile('C:\Users\Токарев\AppData\Roaming\Browsers\exe.erolpxei.bat', '');
QuarantineFile('C:\Users\Токарев\AppData\Roaming\Browsers\exe.xoferif.bat', '');
QuarantineFile('C:\Users\Токарев\AppData\Local\Kometa\Application\kometa.bat', '');
QuarantineFile('C:\Program Files (x86)\Common Files\LogiShrd\LWSPlugins\LWS\Applets\HelpMain\launchershortcut.bat', '');
QuarantineFile('C:\ProgramData\Saophase\Kinfax.dll', '');
QuarantineFile('C:\Users\Токарев\AppData\Local\PNRP32\wmpshell.exe', '');
QuarantineFile('c:\program files (x86)\iobit\iobit uninstaller\uninstallmonitor.exe', '');
QuarantineFile('C:\Windows\Sys\taskmgr.exe', '');
QuarantineFile('c:\programdata\saophase\saophase.exe', '');
QuarantineFileF('c:\programdata\saophase', '*', true, '', 0 , 0);
QuarantineFile('C:\Program Files\fchk32\packages\62a80007-575d-4582-a208-73a2614d64e5\NixHost.exe', '');
QuarantineFile('c:\program files (x86)\iobit\liveupdate\iobitlauncher.exe', '');
QuarantineFile('C:\Program Files\fchk32\fchk32.exe', '');
QuarantineFile('c:\programdata\saophase\dingtonlax.exe', '');
QuarantineFileF('C:\Program Files\fchk32', '*', true, '', 0 , 0);
QuarantineFileF('c:\program files (x86)\iobit', '*', true, '', 0 , 0);
QuarantineFileF('C:\Users\Токарев\AppData\Local\PNRP32', '*', true, '', 0 , 0);
QuarantineFileF('C:\ProgramData\ExtTag', '*', true, '', 0 , 0);
QuarantineFileF('C:\ProgramData\AlterGeo', '*', true, '', 0 , 0);
DeleteFile('C:\Windows\Sys\taskmgr.exe');
DeleteFile('c:\program files (x86)\03000200-1438968807-0500-0006-000700080009\knso7693.tmp');
DeleteFile('C:\Windows\Sys\taskmgr.vbs');
DeleteFile('C:\Program Files (x86)\Internet Explorer\iexplore.bat');
DeleteFile('C:\Program Files\Internet Explorer\iexplore.bat', '');
DeleteFile('C:\Program Files\Opera x64\opera.bat', '');
DeleteFile('C:\Users\Токарев\AppData\Roaming\Browsers\exe.arepo.bat', '');
DeleteFile('C:\Users\Токарев\AppData\Roaming\Browsers\exe.erolpxei.bat', '');
DeleteFile('C:\Users\Токарев\AppData\Roaming\Browsers\exe.xoferif.bat', '');
DeleteFile('C:\Users\Токарев\AppData\Local\Kometa\Application\kometa.bat', '');
DeleteFile('C:\Program Files (x86)\Common Files\LogiShrd\LWSPlugins\LWS\Applets\HelpMain\launchershortcut.bat', '');
DeleteFile('c:\programdata\saophase\dingtonlax.exe', '32');
DeleteFile('C:\Program Files\fchk32\fchk32.exe', '32');
DeleteFile('c:\program files (x86)\iobit\liveupdate\iobitlauncher.exe', '32');
DeleteFile('C:\Program Files\fchk32\packages\62a80007-575d-4582-a208-73a2614d64e5\NixHost.exe', '32');
DeleteFile('C:\Windows\Sys\taskmgr.exe', '32');
DeleteFile('c:\program files (x86)\iobit\iobit uninstaller\uninstallmonitor.exe', '32');
DeleteFile('C:\Users\Токарев\AppData\Local\PNRP32\wmpshell.exe', '32');
DeleteFile('C:\ProgramData\Saophase\Kinfax.dll', '32');
DeleteFile('C:\ProgramData\Saophase\Saophase.exe', '32');
DeleteFile('C:\Program Files (x86)\03000200-1438968807-0500-0006-000700080009\knso7693.tmp', '32');
DeleteFile('C:\ProgramData\ExtTag\ExtTag', '32');
DeleteFile('C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe', '32');
DeleteFile('C:\Program Files (x86)\Common Files\1c1e4ef3-a4fe-42a4-a546-08f69e47d2d1\updater.exe', '32');
DeleteFile('C:\Windows\Microsoft\UpdatingServiceMed\Media Player ZNewVersionDownloader.exe', '32');
DeleteFile('C:\ProgramData\AlterGeo\Update', '32');
DeleteFile('provider\html5locsvc.exe', '32');
DeleteFile('C:\ProgramData\ExtTag\iedto40a.dll', '32');
DeleteFile('C:\Program Files (x86)\Internet Explorer\iexplore.bat', '32');
DeleteFile('C:\Users\Токарев\AppData\Roaming\OtVdi00YYfJn.exe', '32');
DeleteFile('C:\Users\Токарев\AppData\Roaming\ZorzjrQipU.exe', '32');
DeleteFile('C:\Users\Токарев\AppData\Roaming\istartsurf\UninstallManager.exe', '32');
DeleteFile('C:\Users\Токарев\AppData\Roaming\mystartsearch\UninstallManager.exe', '32');
DeleteFile('C:\Windows\microsoft\sogrmed\media player zupdater.exe', '32');
DeleteFile('C:\Windows\Tasks\OtVdi00YYfJn.job', '32');
DeleteFile('C:\Windows\Tasks\ZorzjrQipU.job', '32');
DeleteFile('C:\Windows\system32\Tasks\{062C0C74-184C-4621-A528-49AAA136CD68}', '64');
DeleteFile('C:\Windows\system32\Tasks\{30B93CD3-F69D-427C-AAD8-D39FF6250D2E}', '64');
DeleteFile('C:\Windows\system32\Tasks\{359127FA-606F-4953-9381-7B754F0C9C26}', '64');
DeleteFile('C:\Windows\system32\Tasks\{3DEBDD38-9C10-482D-825F-B33CE2581B39}', '64');
DeleteFile('C:\Windows\system32\Tasks\{62687BE7-ECCE-4E19-A456-FC91791D2EB3}', '64');
DeleteFile('C:\Windows\system32\Tasks\{99E54D3D-360A-461E-A645-B7AEB7912D57}', '64');
DeleteFile('C:\Windows\system32\Tasks\{EC13B85E-D371-49DE-906B-298E9CB4D680}', '64');
DeleteFile('C:\Windows\system32\Tasks\{B36149A0-1C34-469C-B240-C30EDBE536D7}', '64');
DeleteService('UpdatingServiceMed');
DeleteService('Update Mgr MagicalFind');
DeleteService('LiveUpdateSvc');
DeleteService('ExtTag');
DeleteService('Saophase');
DeleteService('fchk32');
DeleteService('C_28597');
DeleteService('dinohemo');
DeleteFileMask('C:\Program Files (x86)\03000200-1438968807-0500-0006-000700080009', '*', true);
DeleteFileMask('c:\programdata\saophase', '*', true);
DeleteFileMask('C:\Program Files\fchk32', '*', true);
DeleteFileMask('c:\program files (x86)\iobit', '*', true);
DeleteFileMask('C:\Users\Токарев\AppData\Local\PNRP32', '*', true);
DeleteFileMask('C:\ProgramData\ExtTag', '*', true);
DeleteFileMask('C:\ProgramData\AlterGeo', '*', true);
DeleteDirectory('C:\Program Files (x86)\03000200-1438968807-0500-0006-000700080009', '');
DeleteDirectory('c:\programdata\saophase', '');
DeleteDirectory('C:\Program Files\fchk32', '');
DeleteDirectory('c:\program files (x86)\iobit', '');
DeleteDirectory('C:\Users\Токарев\AppData\Local\PNRP32', '');
DeleteDirectory('C:\ProgramData\ExtTag', '');
DeleteDirectory('C:\ProgramData\AlterGeo', '');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'AlterGeoUpdater');
RegKeyParamDel('HKEY_USERS', 'S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run', 'AlterGeoUpdater');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
ExecuteWizard('SCU',2,3,true);
RebootWindows(true);
end.