Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
end;
ClearQuarantine;
QuarantineFile('c:\docume~1\alluse~1.win\mshldweii.exe','');
QuarantineFile('C:\WINDOWS\system32\drivers\dcin.exe','');
QuarantineFile('C:\Program Files\Common Files\bett2f00\cpcnmzzcg.exe','');
QuarantineFile('C:\Documents and Settings\Дом\Application Data\update\swpxdxhamv.exe','');
QuarantineFile('C:\Documents and Settings\Дом\Application Data\Update\MSupdate.exe','');
QuarantineFile('C:\Documents and Settings\Дом\Application Data\Update\Explorer.exe','');
QuarantineFile('C:\Documents and Settings\Дом\Application Data\Microsoft\Windows\Mgagas.exe','');
QuarantineFile('C:\DOCUME~1\F184~1\LOCALS~1\Temp\Adobe\Reader_sl.exe','');
QuarantineFile('C:\DOCUME~1\ALLUSE~1.WIN\msntm.exe','');
QuarantineFile('C:\DOCUME~1\ALLUSE~1.WIN\msjywdf.exe','');
DeleteFile('C:\DOCUME~1\ALLUSE~1.WIN\msjywdf.exe','32');
DeleteFile('C:\DOCUME~1\ALLUSE~1.WIN\msntm.exe','32');
DeleteFile('C:\DOCUME~1\F184~1\LOCALS~1\Temp\Adobe\Reader_sl.exe','32');
DeleteFile('C:\Documents and Settings\Дом\Application Data\Microsoft\Windows\Mgagas.exe','32');
DeleteFile('C:\Documents and Settings\Дом\Application Data\Update\Explorer.exe','32');
DeleteFile('C:\Documents and Settings\Дом\Application Data\Update\MSupdate.exe','32');
DeleteFile('C:\Documents and Settings\Дом\Application Data\update\swpxdxhamv.exe','32');
DeleteFile('C:\Program Files\Common Files\bett2f00\cpcnmzzcg.exe','32');
DeleteFile('C:\WINDOWS\system32\drivers\dcin.exe','32');
DeleteFile('c:\docume~1\alluse~1.win\mshldweii.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','1689181934');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run-','1689181934');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','1689182183');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe System Incorporated','command');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Mgagas');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Windows Explorer Manager');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Windows Explorer Manager','command');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Windows Update Manager');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Windows Update Manager','command');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft AMP');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Microsoft AMP');
RegKeyParamDel('HKEY_USERS','S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run','Microsoft AMP');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\A38973873873','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Microsoft Driver Setup');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','61143');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(9);
RebootWindows(false);
end.