Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\PROGRA~2\msrhlmf.exe','');
QuarantineFile('C:\Users\843E~1\AppData\Local\Temp\KB01951213.exe','');
QuarantineFile('C:\Users\843E~1\AppData\Local\Temp\Adobe\Reader_sl.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-1785130\da723n4.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-17185130\da723n4.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-127327\dqr37331.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-12473925\d4q931.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-12321413\dqr21rr31.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-123213413\dqr3331.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-12192660\da92254.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-121914160\d154a92254.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-12191160\d15a92254.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-12125660\da21254.exe','');
QuarantineFile('C:\ProgramData\CreativeAudio\xsytzecrn.exe','');
TerminateProcessByName('c:\recycler\s-1-5-21-0243556031-888888379-781862338-12192660\da92254.exe');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781862338-12192660\da92254.exe','');
DeleteFile('c:\recycler\s-1-5-21-0243556031-888888379-781862338-12192660\da92254.exe','32');
DeleteFile('C:\ProgramData\CreativeAudio\xsytzecrn.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-12125660\da21254.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-12191160\d15a92254.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-121914160\d154a92254.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-12192660\da92254.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-123213413\dqr3331.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-12321413\dqr21rr31.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-12473925\d4q931.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-127327\dqr37331.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-17185130\da723n4.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-1785130\da723n4.exe','32');
DeleteFile('C:\Users\843E~1\AppData\Local\Temp\Adobe\Reader_sl.exe','32');
DeleteFile('C:\Users\843E~1\AppData\Local\Temp\KB01951213.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','MicrosoftSfCnt');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Adobe System Incorporated');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','dak33n1');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','dak331n1');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','dq3r7441');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','dq95441');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','dqr12r441');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','dq3r441');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','d922153v');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','d915422153v');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','d91522153v');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','da212153v');
DeleteFile('C:\PROGRA~2\msrhlmf.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','3626444561');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon','Taskman');
RebootWindows(false);
end.
Компьютер перезагрузится.