We fix and optimize using the AVZ program. Quick removal of viruses using the AVZ utility

The AVZ anti-virus utility is a system research and recovery tool, and is designed to automatically or manually search and remove:

  • SpyWare and AdWare modules are the main purpose of the utility
  • Dialer (Trojan.Dialer)
  • Trojans
  • BackDoor modules
  • Network and mail worms
  • TrojanSpy, TrojanDownloader, TrojanDropper
  • This utility is not a full-fledged antivirus program (which, by the way, is good, because it does not conflict with what is already installed). AVZ is a utility that does not require installation and is a good helper in the most unpredictable cases. Often, it is with the help of AVZ that it is possible to let the system breathe wide enough again to at least revive/install a normal antivirus and finish off any riffraff with it.
    Anyway, let's get started.

    We do everything strictly as described. Deviations from the instructions may result in poor cleaning.

  • Download the AVZ antivirus utility from here or via search engine.
  • We unpack the archive wherever it is convenient for you.
  • We go to the folder where we unpacked the program and launch avz.exe there. In the program window select File –> Database update.
  • At the end of the line Settings: button with three dots, clicking on it takes you to the settings window.

    When the database update process is complete, click Close.On the tab, check all hard drives and flash drives (if not inserted, then insert).

  • Place a checkmark on the right - Carry out treatment.
  • In the first four lines we select Delete, in the penultimate Treat, and in the last one too Delete.
  • Also check the boxes Copy deleted files to Infected And Copy suspicious files to quarantine.
  • Go to the tab

  • very long: put a circle All files uncheck the box.
  • long: put a circle All files do not uncheck the box Do not scan archives larger than 10MB.
  • quick: put a circle Potentially dangerous files do not uncheck the box Do not scan archives larger than 10MB.
  • What's the difference? The difference is in the quality of the check - the longer, the more thorough and the greater the chance that all viruses will be removed.

    Go to the tab.

    Heuristic analysis
  • Slider Heuristic analysis move to the top
  • put a tick Advanced Analysis
  • Anti-RootKit
  • put a tick Detect API interceptors And RootKit
  • put a tick Block RootKit User-Mode
  • put a tick RootKit Kerner-Mode
  • This is necessary so that not a single virus can escape anywhere or launch anything that interferes with the operation of the antivirus.
    Winsock Service Provider
  • put a tick Check SPI/LSP settings
  • put a tick Automatically correct errors in SPI/LSP
  • Check the boxes even lower Search for keyboard loggers Keyloggers And Search for TCP/UDP ports of Trojan programs.

    Next click

    Enable AVZGuard

    Next, click AVZPM

    Install the advanced process monitoring driver. If a reboot is required, agree, but keep in mind that you will have to do everything except install the driver again.
    That's it now. Click the “Start” button and wait for the test to complete.

    Attention! During the check, most likely, you will not be able to run almost any program on the computer, or enter the system drive (usually C:\). It's better to leave the computer alone.
    The fact is that AVZ thus blocks all possible movements of viruses, programs, spyware, etc., i.e. any attempts to deceive the scanner (to run away, hide, pretend to be something else, etc.) or to make a dirty trick with their last breath.

    Actions after removing AVZ viruses

    Click AVZPM -> Remove and unload the advanced process monitoring driver. Then File ->Exit and be sure to restart your computer.
    After the reboot, you may be prompted to install unknown hardware found - do not be alarmed and cancel the offer. It shouldn't bother you anymore. If it still appears, then do:
    Start – Settings – Control Panel – System – Hardware – Device Manager. There, find something with a yellow question mark and delete it.
    If it doesn’t help, then in the same AVZ, try doing File - Standard Scripts– check the box Removing All AVZ Drivers and Registry Keys and press Execute marked scripts

    Don’t panic if, during the scan, the utility found those that work with the network, are able to make calls, or are programs registered in the startup. It is likely that this is not a virus, but something from utility software. As for suspicious files found but not deleted: after such a scan (even a quick one), most likely, most of the serious (or not so serious) viruses that lived on you up to this point have not survived on your computer, but I strongly recommend that you will be checked by some full-fledged large Anti-Virus.

    In addition to the above actions, AVZ can restore and clean the system. (

    Then this article is for you. But before proceeding with the further description of the instructions given here, I am forced to refer you to the article Cleaning up the hosts file so that you follow the recommendations given at the beginning of the article, in particular, save and make changes to the registry to restore the default folder of the hosts file.

    The wonderful AVZ utility, with its small size, allows you to solve almost all problematic computer security issues. The AVZ utility does not require installation and is fast. However, it can be viewed more as a system administrator tool. This utility is described in detail on the developer’s website www.z-oleg.com. Remember, the utility cannot be used as an antivirus program.

    Given the enormous capabilities of the AVZ utility, here we will only consider its capabilities for cleaning the hosts file. The current version can be downloaded at: z-oleg.com/secur/avz/download.php.

    The program archive can be downloaded anywhere, I recommend downloading it to your desktop and unpacking it, so it will always be visible.

    Run the avz.exe program and first update the database. If the program does not start, rename the avz.exe file to any other name, for example awr3k.exe. If the system reports that the program is not trusted and asks for your consent, answer in the affirmative.

    Check the boxes as in the picture below and start scanning. You can smoke while scanning...

    After the scan is completed, you must carefully study the log. AVZ eliminates many errors automatically, and simply warns about some. I specifically changed the hosts file folder in the registry and AVZ warned me about this.

    AVZ does not automatically clear the hosts file, since the contents of this file can be used, among other things, for useful tasks (see the article Hosts file). To clean the hosts file, AVZ offers us several methods.

    1. Clean up using a system recovery tool. We launch system recovery.

    A window for selecting functions for restoring system settings opens.

    In accordance with the topic of the article, I only have item “13. Cleaning the hosts file” checked. You, in accordance with your desires and/or needs, can mark other items. At the same time, let me note the following: changes in points 3, 4, 5 and 8 depend on the user’s personal settings and they can be reset, not fatal, but it can be unpleasant; changes in paragraphs 14, 15, 18 and 20 depend on the current network settings in accordance with the Internet connection agreement, and in paragraph 18 even the developers remind that it is dangerous; The change in paragraph 21 is only relevant if the Internet connection has some problems. In general, if the network connection is working normally, it is better not to touch the last points. Changes in points 1, 2, 6, 7, 10, 11, 12, 16, 17 and 19 are even useful for prevention. By the way, if, while following the recommendations for changing the registry to the default state in the article Cleaning the hosts file, you were informed that changing the registry was blocked, then check item 17 “Unblocking the registry editor”.

    After you have marked the necessary items, click the Perform selected operations button.

    2. Cleaning the hosts file using scripts. Open the Run script window.

    The Run Script window opens.

    Enter the script code into the window (as indicated in the picture):

    Begin ClearHostsFile; end.

    And click the “Run” button.

    Regardless of the chosen cleaning method, the result will be achieved in 99 cases out of 100. I leave 1% to crooked hands or when system recovery is only possible through a complete reinstallation.

    Every user has encountered system problems related to viruses and malware. The problems they cause are very serious. Sometimes you have to completely reinstall the system, or the equipment may malfunction. But you don’t always need to turn to specialists for help. Many problems can be solved on their own. This is where AVZ antivirus comes to the rescue. Let's take a closer look at how to work with it.

    What is this program

    AVZ does not work in real time like antiviruses installed on a PC. You don't have to install it. The utility is in Russian. Does not conflict with antiviruses installed on the system. I have Smart Security installed. In this case, the utility works great. There is no need to disable permanent antivirus.

    When to use it

    AVZ removes viruses such as AdWare, SpyWare and Trojans. If you notice that your PC is not working as usual: it freezes, the software loads slowly, it won’t turn off, try working with AVZ. Even if everything works as it should, periodically scan your PC with this utility.

    How to download and install

    Download the latest version from the official website: http://z-oleg.com/avz4.zip

    The latest version includes support for Windows 10

    Extract the downloaded archive to the “avz4” folder. If you want, change her name to something else. Next, launch it by clicking on the avz.exe file.
    Before starting work, update the databases. In the window that opens, find the “Update” icon.

    For Windows 7/10, for AVZ to work correctly, run it as an administrator. To do this, right-click on the avz.exe executable file. Next, select the appropriate item.

    What to do before work

    AVZ is a utility for troubleshooting problems caused by viruses. Therefore, before starting work, run, for example, a one-time utility. It will get rid of viruses, and AVZ will correct violations and delete files created by the virus. Will clean the system after removal.

    How to use

    Let's launch the utility. The main program window consists of three tabs:

    On the first tab “Search Area”, select what to scan on the HDD. A little lower there will be three options. Check the boxes next to them. This will allow you to perform heuristic analysis, scan running processes, and identify malicious software.

    File type

    In this tab, select what to scan. If a simple check is being performed, check the “Potentially dangerous” box. If there are a lot of viruses - “All files”. The utility works with archives in addition to simple documents. In this tab, configure this check. Uncheck the checkbox next to archive checking.

    Search options

    A slider will appear at the top. Move it up to enable checking for keyboard hooks. The end result should look like the picture.
    Next, configure what action to perform if a virus is found:

    A check will run, the result of which will be displayed in the area called “Protocol”. After a short period of time (depending on the amount of information being checked), the scanning will end. Next, the program will indicate the scanning time and the threats found.
    If threats are found, look at them by clicking on the button marked in the figure below.
    If there are suspicious objects, the program will write the path to them, description, and type. Here you can move it to quarantine or delete it.

    System functions

    In addition to checking for viruses and malware, AVZ performs many functions. Let's talk about the most useful ones. To access them, click on "File". A context menu with all functions will open.
    Let's look at the most important ones.

    System Research

    The function will collect information about the system. This is the technical and hardware part. This includes: system files, protocols, processes. By clicking on the “Research” link, a new window will open, where you indicate to the utility what information you need to collect. Having installed everything you need, click on “Start”.
    In a new window, the program will offer to save the document. It contains the selected information in html format. Opens in any browser. Next, click “Save”.
    Scanning will begin. After its completion, you will be able to view the selected information.

    Recovery

    These functions can return OS elements to their original state and remove settings. The malware wants to deny access to the “Registry Editor” or “Manager”. Tries to add parameters to the “hosts” system file. The restore option will unlock these items. To start, click on it and check the boxes for the actions you want to perform. I checked the 11, 13, 17 option. Next, click on “Run”.

    Scripts

    The list of options found in the “File” menu includes functions that work with scripts. These are “Run”, “Standard”.
    By clicking on “Standard” a window will appear with a list of ready-made scripts. Check the boxes as needed. Next, click on “Run”.
    Another option will launch the editor. Write the script yourself, or download from your PC. Next, click the “Run” button.

    Quarantine and Infected option

    By clicking on this item, view the potentially dangerous elements detected by the utility during scanning.
    Delete the files (if found), or restore if they are not dangerous.
    To have potentially dangerous software quarantined, check the appropriate boxes in the settings.

    Services

    To view the list of services offered by the program, click on the corresponding “Service” line.
    Let's look at the most used ones.

    Process Manager

    All executable files running on the system are displayed here. In a new window, look at their description and the path to them.
    End the process if necessary. Select it from the list and click on the button with a black cross. Located to the right of the window.

    This is a replacement for the dispatcher installed in the system. It is of particular value if it is blocked by a virus.

    Services and Driver Manager

    The second service on the list. By clicking on it, a window will open where you select the service using the switch: services, drivers all. Select the desired item and then disable, stop or delete it.

    Startup manager

    Use it to configure settings for programs that start with the system. To disable, uncheck the box next to the selected item. The entry can be completely deleted. To do this, press the button with a black cross on it.

    Once deleted, it cannot be restored. Therefore, check carefully so as not to erase important records.

    Hosts File Manager

    If a virus has written its own values ​​in this file and blocked access, use this option. A new window will display its contents. It won't be possible to add anything. Just delete. This is done using the button with a black cross.

    Launching utilities

    The program allows you to work with popular applications. To do this, go to “Service” - “System”. By clicking on system utilities, you can:


    AVZGuard

    If you have a virus that cannot be removed, use the AVZGuard function. It adds the malware to the list of untrusted software that cannot be operated on. To activate, click on the AVZGuard line.

    I would like to note that this function and AVZPM do not work for me, since these technologies are not supported by 64-bit versions of Windows operating systems. Read more about this in the official technical documentation at: http://z-oleg.com/secur/avz_doc/index.html?t_install.htm.

    Conclusion

    I recommend that all users download AVZ. Run the virus scan utility periodically. Its main task is to remove spyware, Trojans and SpyWare. But this does not mean that you do not need to use antiviruses that protect your PC in real time.

    The main task of any antivirus is to identify and destroy malicious software. Therefore, not all security software can work with files such as scripts. However, the hero of our today’s article is not one of those. In this lesson we will tell you how to work with scripts in AVZ.

    Scripts written and executed in AVZ are aimed at identifying and destroying various types of viruses and vulnerabilities. Moreover, the software contains both ready-made basic scripts and the ability to execute other scripts. We already mentioned this in passing in our separate article on using AVZ.

    Let's now look at the process of working with scripts in more detail.

    Method 1: Executing prepared scripts

    The scripts described in this method are built into the program itself by default. They cannot be changed, removed or modified. You can only start their execution. Here's what it looks like in practice.

    1. Run the file from the folder with the program "avz".
    2. At the very top of the window you will find a list of sections that are located horizontally. You need to left-click on the line "File". After this, an additional menu will appear. In it you need to click on the item "Standard scripts".
    3. As a result, a window will open with a list of standard scenarios. Unfortunately, it is impossible to view the code of each script, so you will have to be content with just the name of them. Moreover, the name indicates the purpose of the procedure. Check the checkboxes next to the scripts you want to execute. Please note that you can mark multiple scripts at once. They will be executed sequentially, one after the other.
    4. After you select the required items, you need to click on the button "Run marked scripts". It is located at the very bottom of the same window.
    5. Before the actual execution of the scripts starts, you will see an additional window on the screen. You will be asked if you really want to run the marked scripts. To confirm you need to press the button "Yes".
    6. Now you need to wait some time until the execution of the marked scripts is completed. When this happens, you will see a small window on the screen with a corresponding message. To complete you just need to press the button "Ok" in such a window.
    7. Next, close the window with the list of procedures. The entire script execution process will be displayed in the AVZ area called "Protocol".
    8. You can save it by clicking on the floppy disk button to the right of the area itself. In addition, a little lower there is a button with a picture of glasses.
    9. By clicking on this button with points, you will open a window that will display all suspicious and dangerous files detected by AVZ during script execution. By checking such files, you can move them to quarantine or completely erase them from your hard drive. To do this, there are special buttons with similar names at the bottom of the window.
    10. After operations with detected threats, all you have to do is close this window, as well as AVZ itself.

    That's the whole process of using standard scripts. As you can see, everything is very simple and does not require any special skills from you. These scripts are always up to date, as they are automatically updated along with the version of the program itself. If you want to write your own script or run another script, our next method will help you.

    Method 2: Working with individual procedures

    As we noted earlier, using this method you can write your own script for AVZ or download the necessary script from the Internet and execute it. To do this you need to do the following manipulations.

    1. Let's launch AVZ.
    2. As in the previous method, click on the line at the very top "File". In the list you need to find the item "Run script", then left-click on it.
    3. After this, the script editor window will open. In the very center there will be a work area in which you can write your own script or one downloaded from another source. Moreover, you can even simply paste the copied script text with a banal key combination "Ctrl+C" And "Ctrl+V".
    4. Slightly above the work area there will be four buttons shown in the image below.
    5. Buttons "Download" And "Save" Most likely they don't need any introduction. By clicking on the first one, you can select a text file with a procedure from the root directory, thereby opening it in the editor.
    6. When you press a button "Save", a similar window will appear. Only in it you will already need to specify the name and location for the saved file with the script text.
    7. Third button "Run" will allow you to execute a written or downloaded script. Moreover, its implementation will begin immediately. The process time will depend on the volume of actions performed. In any case, after some time you will see a window notifying you that the operation has completed. After this, it should be closed by pressing the button "Ok".
    8. The progress of the operation and accompanying steps of the procedure will be displayed in the main AVZ window in the field "Protocol".
    9. Please note that if the script contains errors, it simply will not run. As a result, you will see an error message on the screen.
    10. By closing such a window, you will automatically be taken to the line in which the error itself was found.
    11. If you write the script yourself, then the button will be useful to you "Check Syntax" in the main editor window. It will allow you to check the entire script for errors without first running it. If everything goes smoothly, you will see the following message.
    12. In this case, you can close the window and safely run the script or continue writing it.

    That's all the information we wanted to tell you about in this lesson. As we have already mentioned, all scripts for AVZ are aimed at eliminating virus threats. But besides scripts and AVZ itself, there are other ways to get rid of viruses without an antivirus installed. We talked about such methods earlier in one of our special articles.

    If after reading this article you have comments or questions, please voice them. We will try to give a detailed answer to each.

    So I got to the next healing utility, called AVZ, as promised. There are a huge number of viruses written for Windows and not every antivirus is able to find them all. In other words, the ideal protection has not yet been invented. But you can use several utilities at the same time. One will complement the other, since if one antivirus does not find this or that malicious file, then another antivirus will detect it.

    In one of my articles I talked about the utility, which is also a cool program that I recommend using, but we move on to what the AVZ antivirus utility is.

    Overview and use of the AVZ utility

    A little higher, I misspoke a little when I said that avz is an antivirus. In fact, this is a simple program that does not require installation, which searches for viruses and malware, treats or gets rid of them, the program, like Dr Web Cureit, does not work in real time, but that’s okay, the main thing for us is to find viruses. Also, if you already have some kind of antivirus on your computer, then AVZ will not conflict with it. Although, it would be possible to disable the antivirus during the scan, but this is not a prerequisite.

    When can I use AVZ and where can I download it?

    The program is quite universal, because it not only searches for viruses such as worms and Trojans, but also such malicious things as AdWare and . By the way, AVZ is a free utility; you can download it from the official website z-oleg.com. At the moment, the latest version of the program is 4.46, but if you use it often, then stay tuned for updates.

    The program will download as an archive that needs to be unpacked somewhere. Open the unpacked folder and run the file from there avz.exe. A program window opens, from here we will begin our review of the AVZ utility.

    Scanning and neutralizing viruses using AVZ

    So you launched the program, and there are many different settings, some of which may not be clear to the average user. But I will tell you how and what to do.

    First you need to update the utility database; to do this, you can click on the globe icon on the right, or click “File” - “Update databases”.

    A window appears in which click the button "Start" and wait until the necessary files are downloaded. When everything is downloaded, the program will tell you about it.


    Now in the program window go to the tab "Search area". You will see all the disks connected to the computer and drives, be sure to check the box next to the system drive, but it’s better to check the rest too.

    Below we check all the boxes where running processes are checked, heuristic checks and searches for potential vulnerabilities are carried out.

    On the right side of the treatment method, check the box "Perform treatment" and for all items we select "Delete". Next to the “HackTool” item, select the parameter "Treat". Just below we check all the available boxes.


    Now go to the tab "File Types", where we set the checkbox opposite "All files".If the “Do not check archives again” checkbox is checked, uncheck it. What we have set up is a long-term check, if you want to check the system in depth, then set up the program in accordance with these instructions.



    At this point we have finished setting up the program, which means you can press the button "Start" and wait for the system scan to complete. During the scanning process, it is better not to touch anything, but just wait. After the utility completes, restart your computer.

    Additional features of AVZ

    The AVZ program can not only scan the system and remove viruses. If you press the button "Service" in the program menu, then there you will see many different managers, for example, “Process Manager”, which shows all running processes in the system. There is a description of them and the manufacturer, and processes can be controlled from there.


    The Services and Driver Manager contains running processes. They can also be controlled.



    More on this topic:

    I think I'll end here. As you can see, the AVZ healing utility is a very cool thing; in combination with similar programs, you don’t have to worry about the security of your computer, but you still need to have a good antivirus that works in real time. I haven’t finished reviewing these products yet; there are a couple more on the way. After which I will write an article about what set of programs you should have on a flash drive for full-fledged work with a computer, so to speak, a flash drive for all occasions.