Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
end;
ClearQuarantine;
TerminateProcessByName('c:\program files\jump flip\bin\utiljumpflip.exe');
TerminateProcessByName('c:\program files\jump flip\updatejumpflip.exe');
SetServiceStart('11350', 4);
StopService('11350');
QuarantineFile('D:\autorun.inf','');
QuarantineFile('C:\wisptis.exe','');
QuarantineFile('C:\Program Files\Java\jre6\bin\winlogon.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\winlogon.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\svchost.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\smss.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\services.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\adobereader.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Znvwimsyumczhefb.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Zihdmvdpjrtkvnks.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Ybrmaqkiymaoghnr.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Wxpogkgipprxqzir.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Wmefbmuvgzftaplc.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Vaiccdfiwhtcglpf.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Uwoqlxiuydveette.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Uoyjjhszmdiatffi.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Sxblsfliaiclxikh.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Siecsndxuzcpqooi.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Sichtffwgiaawuol.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Sdrbdgmwohnrsuzi.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Rnevlelzgkrrmqjn.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Qqyraeabkncwpzme.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Pmcadfnjfoeahshr.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Pjmbletzpbiayxzk.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Phtctvephehubgiq.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Opugbcyjtbwdrvgi.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Ootdhjbponcfdnzy.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Ofuprfgvzlzgqgwg.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Mphcildpiwrdqtqs.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Lsxyakzdghkwrxse.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Laeyfbrfkbrrticv.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Jfxylcbeodzuzrfe.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Hjxgjfxhlkklqffi.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Dxvfrwidkhhllqxu.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Crxtiakbkajfyjwm.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Chlquspshadkwlay.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Bjbktvxwpyhnakfk.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Betqptojhkpaghdd.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Akgwdbhwjhoohfcc.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Application Data\Adobe\adbreader.exe','');
QuarantineFile('C:\D\V\I7\wisptis.exe','');
QuarantineFile('C:\D\G\N1\wisptis.exe','');
QuarantineFile('C:\D\G\N1\winlogon.exe','');
QuarantineFile('C:\D\G\N1\convert.exe','');
QuarantineFile('C:\DOCUME~1\Admin\LOCALS~1\Temp\temp98425363.exe','');
QuarantineFile('C:\DOCUME~1\Admin\LOCALS~1\Temp\temp67242558.exe','');
QuarantineFile('C:\DOCUME~1\Admin\LOCALS~1\Temp\temp32301734.exe','');
QuarantineFile('C:\DOCUME~1\Admin\LOCALS~1\Temp\temp20430108.exe','');
QuarantineFile('C:\DOCUME~1\Admin\LOCALS~1\Temp\11350.sys','');
QuarantineFile('c:\program files\jump flip\bin\utiljumpflip.exe','');
QuarantineFile('c:\program files\jump flip\updatejumpflip.exe','');
DeleteFile('c:\program files\jump flip\updatejumpflip.exe','32');
DeleteFile('c:\program files\jump flip\bin\utiljumpflip.exe','32');
DeleteFile('C:\DOCUME~1\Admin\LOCALS~1\Temp\11350.sys','32');
DeleteFile('C:\DOCUME~1\Admin\LOCALS~1\Temp\temp20430108.exe','32');
DeleteFile('C:\DOCUME~1\Admin\LOCALS~1\Temp\temp32301734.exe','32');
DeleteFile('C:\DOCUME~1\Admin\LOCALS~1\Temp\temp67242558.exe','32');
DeleteFile('C:\DOCUME~1\Admin\LOCALS~1\Temp\temp98425363.exe','32');
DeleteFile('C:\D\G\N1\convert.exe','32');
DeleteFile('C:\D\G\N1\winlogon.exe','32');
DeleteFile('C:\D\G\N1\wisptis.exe','32');
DeleteFile('C:\D\V\I7\wisptis.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Adobe\adbreader.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Akgwdbhwjhoohfcc.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Betqptojhkpaghdd.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Bjbktvxwpyhnakfk.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Chlquspshadkwlay.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Crxtiakbkajfyjwm.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Dxvfrwidkhhllqxu.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Hjxgjfxhlkklqffi.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Jfxylcbeodzuzrfe.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Laeyfbrfkbrrticv.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Lsxyakzdghkwrxse.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Mphcildpiwrdqtqs.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Ofuprfgvzlzgqgwg.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Ootdhjbponcfdnzy.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Opugbcyjtbwdrvgi.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Phtctvephehubgiq.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Pjmbletzpbiayxzk.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Pmcadfnjfoeahshr.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Qqyraeabkncwpzme.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Rnevlelzgkrrmqjn.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Sdrbdgmwohnrsuzi.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Sichtffwgiaawuol.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Siecsndxuzcpqooi.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Sxblsfliaiclxikh.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Uoyjjhszmdiatffi.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Uwoqlxiuydveette.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Vaiccdfiwhtcglpf.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Wmefbmuvgzftaplc.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Wxpogkgipprxqzir.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Ybrmaqkiymaoghnr.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Zihdmvdpjrtkvnks.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\Znvwimsyumczhefb.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\adobereader.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\services.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\smss.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\svchost.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\winlogon.exe','32');
DeleteFile('C:\Program Files\Java\jre6\bin\winlogon.exe','32');
DeleteFile('C:\wisptis.exe','32');
DeleteFile('C:\WINDOWS\Tasks\AmiUpdXp.job','32');
DeleteFile('D:\autorun.inf','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','TimeNotifyer');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','NetworkChecker');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','VideoVerifyer');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','CrashReportVerifyer');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','NetworkVerifyer');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ConnectionInformer');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','FolderUpdater');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','VideoChecker');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Adobe Reader Update');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Adobe Reader Update');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Akgwdbhwjhoohfcc.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Betqptojhkpaghdd.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Betqptojhkpaghdd.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Bjbktvxwpyhnakfk.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Chlquspshadkwlay.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Chlquspshadkwlay.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Crxtiakbkajfyjwm.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Dxvfrwidkhhllqxu.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Hjxgjfxhlkklqffi.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Jfxylcbeodzuzrfe.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Laeyfbrfkbrrticv.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Lsxyakzdghkwrxse.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Mphcildpiwrdqtqs.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Mphcildpiwrdqtqs.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Mzwdefutvdiqmvjr.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Ofuprfgvzlzgqgwg.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Ofuprfgvzlzgqgwg.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Ootdhjbponcfdnzy.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Opugbcyjtbwdrvgi.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Opugbcyjtbwdrvgi.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Phtctvephehubgiq.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Pjmbletzpbiayxzk.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Pjmbletzpbiayxzk.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Pmcadfnjfoeahshr.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Qqyraeabkncwpzme.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Qqyraeabkncwpzme.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Rnevlelzgkrrmqjn.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Rnevlelzgkrrmqjn.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Sdrbdgmwohnrsuzi.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Sichtffwgiaawuol.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Sichtffwgiaawuol.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Siecsndxuzcpqooi.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Sxblsfliaiclxikh.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Sxblsfliaiclxikh.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Uoyjjhszmdiatffi.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Uwoqlxiuydveette.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Vaiccdfiwhtcglpf.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Wmefbmuvgzftaplc.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Wmefbmuvgzftaplc.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Wxpogkgipprxqzir.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Ybrmaqkiymaoghnr.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Ybrmaqkiymaoghnr.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Zihdmvdpjrtkvnks.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Znvwimsyumczhefb.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Adobe Driver Update');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','services.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','smss.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','svchost.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','svchost.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','winlogon.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ConnectionNotifyer');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','FolderInformer');
DeleteService('11350');
BC_ImportAll;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.