Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\1\appdata\roaming\flash\cgminer-nogpu.exe','');
QuarantineFile('C:\Users\1\appdata\roaming\flash\cgminer.exe','');
QuarantineFile('C:\Users\1\AppData\Local\Temp\8514509.exe','');
QuarantineFile('C:\Windows\system32\machineupper32.exe','');
QuarantineFile('C:\Program Files\youfiles\svchost.exe','');
QuarantineFile('C:\Program Files (x86)\Intel\Intel.exe','');
QuarantineFile('C:\PROGRA~2\zekove64.exe','');
QuarantineFile('C:\PROGRA~2\xowoto.exe','');
QuarantineFile('C:\PROGRA~2\wobepe32.exe','');
QuarantineFile('C:\PROGRA~2\susivi32.exe','');
QuarantineFile('C:\PROGRA~2\sedidoh.exe','');
QuarantineFile('C:\PROGRA~2\resyw.exe','');
QuarantineFile('C:\PROGRA~2\qyhod.exe','');
QuarantineFile('C:\PROGRA~2\qiset.exe','');
QuarantineFile('C:\PROGRA~2\nutiqe64.exe','');
QuarantineFile('C:\PROGRA~2\fytex.exe','');
QuarantineFile('C:\PROGRA~2\dexenol.exe','');
QuarantineFile('C:\PROGRA~2\dedolu.exe','');
QuarantineFile('C:\PROGRA~2\burytu32.exe','');
QuarantineFile('C:\PROGRA~2\WUNOQE~1.EXE','');
QuarantineFile('C:\PROGRA~2\WOLOKO~1.EXE','');
QuarantineFile('C:\PROGRA~2\WODYME~1.EXE','');
QuarantineFile('C:\PROGRA~2\WECUGU~1.EXE','');
QuarantineFile('C:\PROGRA~2\SUCYSY~1.EXE','');
QuarantineFile('C:\PROGRA~2\LOHIFE~1.EXE','');
QuarantineFile('C:\PROGRA~2\JOFILU~1.EXE','');
SetServiceStart('{55685567-4840-4a91-962b-49a412e9485a}Gw', 4);
DeleteService('{55685567-4840-4a91-962b-49a412e9485a}Gw');
QuarantineFile('C:\Windows\system32\drivers\{55685567-4840-4a91-962b-49a412e9485a}w.sys','');
QuarantineFile('C:\Windows\system32\drivers\{55685567-4840-4a91-962b-49a412e9485a}Gw.sys','');
DeleteFile('C:\Windows\system32\drivers\{55685567-4840-4a91-962b-49a412e9485a}Gw.sys','32');
DeleteFile('C:\Windows\system32\drivers\{55685567-4840-4a91-962b-49a412e9485a}w.sys','32');
DeleteFile('C:\PROGRA~2\JOFILU~1.EXE','32');
DeleteFile('C:\PROGRA~2\LOHIFE~1.EXE','32');
DeleteFile('C:\PROGRA~2\SUCYSY~1.EXE','32');
DeleteFile('C:\PROGRA~2\WECUGU~1.EXE','32');
DeleteFile('C:\PROGRA~2\WODYME~1.EXE','32');
DeleteFile('C:\PROGRA~2\WOLOKO~1.EXE','32');
DeleteFile('C:\PROGRA~2\WUNOQE~1.EXE','32');
DeleteFile('C:\PROGRA~2\burytu32.exe','32');
DeleteFile('C:\PROGRA~2\dedolu.exe','32');
DeleteFile('C:\PROGRA~2\dexenol.exe','32');
DeleteFile('C:\PROGRA~2\fytex.exe','32');
DeleteFile('C:\PROGRA~2\nutiqe64.exe','32');
DeleteFile('C:\PROGRA~2\qiset.exe','32');
DeleteFile('C:\PROGRA~2\qyhod.exe','32');
DeleteFile('C:\PROGRA~2\resyw.exe','32');
DeleteFile('C:\PROGRA~2\sedidoh.exe','32');
DeleteFile('C:\PROGRA~2\susivi32.exe','32');
DeleteFile('C:\PROGRA~2\wobepe32.exe','32');
DeleteFile('C:\PROGRA~2\xowoto.exe','32');
DeleteFile('C:\PROGRA~2\zekove64.exe','32');
DeleteFile('C:\Program Files\youfiles\svchost.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','progrmma');
DeleteFile('C:\Windows\system32\machineupper32.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Windows Debugger 32');
DeleteFile('C:\Windows\Tasks\At1.job','32');
DeleteFile('C:\Users\1\AppData\Local\Temp\6992328','32');
DeleteFile('C:\Users\1\AppData\Local\Temp\8514509.exe','32');
DeleteFile('C:\Windows\system32\Tasks\At1','32');
DeleteFile('C:\Users\1\appdata\roaming\flash\cgminer.exe','32');
DeleteFile('C:\Users\1\appdata\roaming\flash\cgminer-nogpu.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Компьютер перезагрузится.