Код:
begin
ExecuteAVUpdate;
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
end;
ClearQuarantine;
TerminateProcessByName('c:\documents and settings\all users\application data\wpm\wprotectmanager.exe');
TerminateProcessByName('c:\docume~1\4b8a~1\locals~1\temp\windows\winsys.exe');
TerminateProcessByName('c:\documents and settings\ксюша\local settings\application data\pricemeter\pricemeterw.exe');
TerminateProcessByName('c:\program files\pricemeterliveupdate\update\pricemeterliveupdate.exe');
TerminateProcessByName('c:\documents and settings\ксюша\local settings\application data\pricemeter\pricemeter.exe');
TerminateProcessByName('c:\documents and settings\all users\application data\iepluginservices\pluginservice.exe');
TerminateProcessByName('c:\program files\mobogenie\mgassist.exe');
TerminateProcessByName('c:\documents and settings\ксюша\application data\4.exe');
QuarantineFile('C:\Documents and Settings\All Users\Application Data\WPM\wprotectmanager.exe','');
QuarantineFile('C:\Documents and Settings\All Users\Application Data\IePluginServices\PluginService.exe','');
QuarantineFile('C:\Program Files\suptab\suptab.dll','');
QuarantineFile('C:\Program Files\mega browse\megabrowsebho.dll','');
QuarantineFile('G:\RECYCLER\S-7-8-08-3347135035-1358623218-032853270-7834\veiIDPWf.exe','');
QuarantineFile('G:\autorun.inf','');
QuarantineFile('C:\WINDOWS\TEMP\0.del','');
QuarantineFile('C:\RECYCLER\mscinet.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-8975460\frt22341.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-8642910\fz85221.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-42304520\dq025667.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-17291768\ndd777630xz.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1464710\fd861221.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-14564210\fd865221.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1291768\ndd7630xz.exe','');
QuarantineFile('C:\Program Files\Common Files\CreativeAudio\lgzovzrbn.exe','');
QuarantineFile('C:\Documents and Settings\ксюша\Application Data\Identities\llwrg\llwrg.exe','');
QuarantineFile('C:\Documents and Settings\ксюша\Application Data\Identities\Gpyeyk.exe','');
QuarantineFile('C:\DOCUME~1\ALLUSE~1\msidah.exe','');
QuarantineFile('C:\DOCUME~1\4B8A~1\LOCALS~1\Temp\sppp.exe','');
QuarantineFile('C:\DOCUME~1\4B8A~1\LOCALS~1\Temp\Adobe\Reader_sl.exe','');
QuarantineFile('c:\docume~1\4b8a~1\locals~1\temp\windows\winsys.exe','');
QuarantineFile('c:\documents and settings\ксюша\application data\4.exe','');
DeleteFile('c:\documents and settings\ксюша\application data\4.exe','32');
DeleteFile('C:\DOCUME~1\4B8A~1\LOCALS~1\Temp\Adobe\Reader_sl.exe','32');
DeleteFile('C:\DOCUME~1\4B8A~1\LOCALS~1\Temp\sppp.exe','32');
DeleteFile('C:\DOCUME~1\4B8A~1\LOCALS~1\Temp\windows\winsys.exe','32');
DeleteFile('C:\DOCUME~1\ALLUSE~1\msidah.exe','32');
DeleteFile('C:\Documents and Settings\ксюша\Application Data\Identities\Gpyeyk.exe','32');
DeleteFile('C:\Documents and Settings\ксюша\Application Data\Identities\llwrg\llwrg.exe','32');
DeleteFile('C:\Program Files\Common Files\CreativeAudio\lgzovzrbn.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1291768\ndd7630xz.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-14564210\fd865221.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1464710\fd861221.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-17291768\ndd777630xz.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-42304520\dq025667.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-8642910\fz85221.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-8975460\frt22341.exe','32');
DeleteFile('C:\WINDOWS\TEMP\0.del','32');
DeleteFile('C:\WINDOWS\Tasks\At1.job','32');
DeleteFile('C:\WINDOWS\Tasks\At2.job','32');
DeleteFile('C:\WINDOWS\Tasks\At3.job','32');
DeleteFile('C:\WINDOWS\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore.job','32');
DeleteFile('C:\WINDOWS\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA.job','32');
DeleteFile('C:\WINDOWS\Tasks\pricemetertask.job','32');
DeleteFile('C:\WINDOWS\Tasks\pricemeterwatcher.job','32');
DeleteFile('G:\autorun.inf','32');
DeleteFile('G:\RECYCLER\S-7-8-08-3347135035-1358623218-032853270-7834\veiIDPWf.exe','32');
DeleteFile('C:\Program Files\SupTab\SupTab.dll','32');
DeleteFile('C:\Program Files\Mega Browse\MegaBrowsebho.dll','32');
DeleteFile('C:\recycler\mscinet.exe','32');
DeleteFile('C:\Documents and Settings\All Users\Application Data\IePluginServices\PluginService.exe','32');
DeleteFile('C:\Documents and Settings\All Users\Application Data\WPM\wprotectmanager.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Adobe System Incorporated');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','MicrosoftPerfWD');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Windows Update Service');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','77224675');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Gpyeyk');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Windows Update');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','CreativeAudio');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','CreativeAudio');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','nd3763xz');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','dd75421');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','dd754121');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','dq025667');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','nd376773xz');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','drtt21');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','d9z121');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Windows Security Firewall Manager');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','Del4097015');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','Del4097015');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon','Taskman');
RegKeyStrParamWrite('HKLM', 'SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer','NoDriveTypeAutoRun','221');
BC_ImportAll;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
ExecuteRepair(9);
RebootWindows(false);
end.