Код:
begin
ExecuteAVUpdate;
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
end;
ClearQuarantine;
TerminateProcessByName('c:\users\123\appdata\roaming\asd8578668\splwow64.exe');
TerminateProcessByName('c:\programdata\windowsmangerprotect\protectwindowsmanager.exe');
TerminateProcessByName('c:\users\123\appdata\local\temp\52617577.exe');
TerminateProcessByName('c:\users\123\appdata\local\temp\46651677.exe');
TerminateProcessByName('c:\users\123\appdata\local\temp\45780771.exe');
TerminateProcessByName('c:\users\123\appdata\local\temp\14766305.exe');
SetServiceStart('WindowsMangerProtect', 4);
StopService('WindowsMangerProtect');
QuarantineFile('C:\Program Files (x86)\SupTab\SupTab.dll','');
QuarantineFile('C:\ProgramData\CreativeAudio\mwvaztybt.exe','');
QuarantineFile('C:\Users\123\AppData\Roaming\newSI_10\s_inst.exe','');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Roaming\ASD8578668\twunk_16.exe','');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Roaming\ASD8578668\splwow64.exe','');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Roaming\ASD8578668\regedit.exe','');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Roaming\ASD8578668\bfsvc.exe','');
QuarantineFile('C:\Windows\system32\config\systemprofile\AppData\Roaming\ASD8578668\IsUninst.exe','');
QuarantineFile('C:\Users\123\AppData\Roaming\Identities\mcxje\mcxje.exe','');
QuarantineFile('C:\Users\123\AppData\Roaming\Identities\Znogof.exe','');
QuarantineFile('C:\Users\123\AppData\Roaming\Identities\Wnogoc.exe','');
QuarantineFile('C:\Users\123\AppData\Roaming\4D76.exe','');
QuarantineFile('C:\Users\123\AppData\Local\Temp\Adobe\Reader_sl.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-98818121\131bz88.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-988121\131bdaz88.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-9881121\131bgfsa8.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-98181121\13b1bgfsa8.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-9814541\13871346.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-914541\1371346.exe','');
QuarantineFile('C:\PROGRA~3\msneyr.exe','');
QuarantineFile('c:\users\123\appdata\roaming\asd8578668\splwow64.exe','');
QuarantineFile('c:\programdata\windowsmangerprotect\protectwindowsmanager.exe','');
QuarantineFile('c:\users\123\appdata\local\temp\52617577.exe','');
QuarantineFile('c:\users\123\appdata\local\temp\46651677.exe','');
QuarantineFile('c:\users\123\appdata\local\temp\45780771.exe','');
QuarantineFile('c:\users\123\appdata\local\temp\14766305.exe','');
DeleteFile('c:\users\123\appdata\local\temp\45780771.exe','32');
DeleteFile('c:\users\123\appdata\local\temp\46651677.exe','32');
DeleteFile('c:\users\123\appdata\local\temp\52617577.exe','32');
DeleteFile('C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe','32');
DeleteFile('C:\PROGRA~3\msneyr.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-914541\1371346.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-9814541\13871346.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-98181121\13b1bgfsa8.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-9881121\131bgfsa8.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-988121\131bdaz88.exe','32');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-98818121\131bz88.exe','32');
DeleteFile('C:\Users\123\AppData\Local\Temp\14766305.exe','32');
DeleteFile('C:\Users\123\AppData\Roaming\4D76.exe','32');
DeleteFile('C:\Users\123\AppData\Roaming\ASD8578668\splwow64.exe','32');
DeleteFile('C:\Users\123\AppData\Roaming\Identities\Wnogoc.exe','32');
DeleteFile('C:\Users\123\AppData\Roaming\Identities\Znogof.exe','32');
DeleteFile('C:\Users\123\AppData\Roaming\Identities\mcxje\mcxje.exe','32');
DeleteFile('C:\Windows\system32\config\systemprofile\AppData\Roaming\ASD8578668\IsUninst.exe','32');
DeleteFile('C:\Windows\system32\config\systemprofile\AppData\Roaming\ASD8578668\bfsvc.exe','32');
DeleteFile('C:\Windows\system32\config\systemprofile\AppData\Roaming\ASD8578668\regedit.exe','32');
DeleteFile('C:\Windows\system32\config\systemprofile\AppData\Roaming\ASD8578668\splwow64.exe','32');
DeleteFile('C:\Windows\system32\config\systemprofile\AppData\Roaming\ASD8578668\twunk_16.exe','32');
DeleteFile('C:\Windows\Tasks\Digital Sites.job','64');
DeleteFile('C:\Windows\Tasks\newSI_10.job','64');
DeleteFile('C:\Users\123\AppData\Roaming\newSI_10\s_inst.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Digital Sites','64');
DeleteFile('C:\Windows\system32\Tasks\newSI_10','64');
DeleteFile('C:\ProgramData\CreativeAudio\mwvaztybt.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Windows Update Check - 0x0E7302EC','64');
DeleteFile('C:\Windows\system32\Tasks\{245B4172-10FE-4300-857A-C2B2ADEE8386}','64');
DeleteFile('C:\Windows\system32\Tasks\{DA61D0B3-1122-47D0-AF15-5E023962B580}','64');
DeleteFile('C:\Users\123\appdata\local\temp\adobe\reader_sl.exe','32');
DeleteFile('C:\Program Files (x86)\SupTab\SupTab.dll','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','909940600');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','617813t');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','6178813t');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','61dbaser8');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','61dbz18');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','61dbz1da8');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','61daser8');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','MicrosoftSfCnt');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Adobe System Incorporated');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','CreativeAudio');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','splwow64.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Wnogoc');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Znogof');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Windows Update');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Windows Update');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','twunk_16.exe');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','twunk_16.exe');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','splwow64.exe');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','splwow64.exe');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','regedit.exe');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','regedit.exe');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','bfsvc.exe');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','bfsvc.exe');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','IsUninst.exe');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','IsUninst.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon','Taskman');
RegKeyStrParamWrite('HKLM', 'SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon', 'UserInit', GetEnvironmentVariable('SystemRoot')+'\system32\userinit.exe,');
DeleteService('WindowsMangerProtect');
DeleteFileMask('C:\Windows\system32\config\systemprofile\AppData\Roaming\ASD8578668', '*', true, ' ');
DeleteFileMask('C:\Users\123\AppData\Roaming\ASD8578668', '*', true, ' ');
DeleteFileMask('C:\Users\123\AppData\Roaming\newSI_10', '*', true, ' ');
DeleteDirectory('C:\Windows\system32\config\systemprofile\AppData\Roaming\ASD8578668');
DeleteDirectory('C:\Users\123\AppData\Roaming\ASD8578668');
DeleteDirectory('C:\Users\123\AppData\Roaming\newSI_10');
BC_ImportAll;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
ExecuteRepair(9);
RebootWindows(false);
end.