Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\system32\58.exe','');
QuarantineFile('C:\WINDOWS\system32\08.exe','');
QuarantineFile('C:\Documents and Settings\User\win93.exe','');
QuarantineFile('C:\Documents and Settings\User\wds.exe','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\W4XKRL3L\ddng[1].exe','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\W4XKRL3L\200f33fdndx[1].exe','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\MP2TTJYX\200hnfkvxx[1].exe','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\9IOASRM7\wffwwng[1].exe','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\9IOASRM7\ddng[1].exe','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\9IOASRM7\200f33fdndx[1].exe','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\9IOASRM7\200csdddvvvc[1].exe','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\81M8HBVS\hgydng[1].exe','');
QuarantineFile('C:\Documents and Settings\User\cdqj.exe','');
QuarantineFile('C:\Documents and Settings\User\cadqj.exe','');
QuarantineFile('C:\Documents and Settings\User\caddwqj.exe','');
QuarantineFile('C:\Documents and Settings\User\Application Data\FF.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\E8.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\E1.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\E0.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\DD.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\DC.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\DA.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\D9.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\D8.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\D7.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\D5.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\D0.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\CF.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\C9.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\C6.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\BD.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\B5.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\B0.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\A9.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\A7.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\A6.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\A5.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\A4.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\A3.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\A1.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\9F.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\9E.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\98.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\93.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\90.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\8F.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\8E.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\8C.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\80.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\7F.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\7A.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\77.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\70.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\6E.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\6C.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\6A.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\68.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\65.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\63.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\5E.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\5D.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\59.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\58.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\51.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\4E.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\4C.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\4B.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\41.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\3D.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\22B.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\10F.tmp','');
QuarantineFile('C:\Documents and Settings\User\Application Data\108.tmp','');
QuarantineFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\S617TWX6\w[1].exe','');
QuarantineFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\57Y3JPAJ\5943[1].exe','');
QuarantineFile('c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ winfixer c a r d .cmd','');
QuarantineFile('C:\WINDOWS\jodrive32.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1413\syitm.exe','');
QuarantineFile('C:\Documents and Settings\User\Application Data\trfmgr32.exe','');
QuarantineFile('C:\Documents and Settings\User\Application Data\Rbhuhl.exe','');
TerminateProcessByName('c:\windows\jodrive32.exe');
QuarantineFile('c:\windows\jodrive32.exe','');
TerminateProcessByName('c:\documents and settings\user\application data\dadvmgr32.exe');
QuarantineFile('c:\documents and settings\user\application data\dadvmgr32.exe','');
DeleteFile('c:\documents and settings\user\application data\dadvmgr32.exe');
DeleteFile('c:\windows\jodrive32.exe');
DeleteFile('C:\Documents and Settings\User\Application Data\Rbhuhl.exe');
DeleteFile('C:\Documents and Settings\User\Application Data\trfmgr32.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','trfmd');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','dadv');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Rbhuhl');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1413\syitm.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Tnaww');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Config Setup');
DeleteFile('C:\WINDOWS\jodrive32.exe');
DeleteFile('c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ winfixer c a r d .cmd');
DeleteFile('explorer.exe,C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1413\syitm.exe,Explorer.exe');
DeleteFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\57Y3JPAJ\5943[1].exe');
DeleteFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\S617TWX6\w[1].exe');
DeleteFile('C:\Documents and Settings\User\Application Data\108.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\10F.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\22B.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\3D.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\41.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\4B.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\4C.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\4E.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\51.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\58.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\59.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\5D.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\5E.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\63.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\65.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\68.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\6A.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\6C.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\6E.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\70.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\77.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\7A.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\7F.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\80.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\8C.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\8E.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\8F.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\90.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\93.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\98.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\9E.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\9F.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\A1.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\A3.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\A4.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\A5.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\A6.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\A7.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\A9.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\B0.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\B5.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\BD.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\C6.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\C9.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\CF.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\D0.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\D5.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\D7.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\D8.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\D9.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\DA.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\DC.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\DD.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\E0.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\E1.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\E8.tmp');
DeleteFile('C:\Documents and Settings\User\Application Data\FF.tmp');
DeleteFile('C:\Documents and Settings\User\caddwqj.exe');
DeleteFile('C:\Documents and Settings\User\cadqj.exe');
DeleteFile('C:\Documents and Settings\User\cdqj.exe');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\81M8HBVS\hgydng[1].exe');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\9IOASRM7\200csdddvvvc[1].exe');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\9IOASRM7\200f33fdndx[1].exe');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\9IOASRM7\ddng[1].exe');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\9IOASRM7\wffwwng[1].exe');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\MP2TTJYX\200hnfkvxx[1].exe');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\W4XKRL3L\ddng[1].exe');
DeleteFile('C:\Documents and Settings\User\wds.exe');
DeleteFile('C:\Documents and Settings\User\win93.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132410.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132412.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132413.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132417.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132421.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132422.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132423.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132424.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132425.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132430.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132433.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132437.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132438.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132439.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132441.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132444.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132446.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132450.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132451.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132452.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132457.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132461.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132466.exe');
DeleteFile('C:\System Volume Information\_restore{7E1D6DD8-E42C-4E7B-BC65-E591246F2F59}\RP70\A0132473.exe');
DeleteFile('C:\WINDOWS\system32\08.exe');
DeleteFile('C:\WINDOWS\system32\58.exe');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon','Taskman');
RebootWindows(true);
end.
Компьютер перезагрузится.