Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Windows\SysWOW64\nethtsrv.exe','');
QuarantineFile('C:\Windows\syswow64\nethtsrv.exe','');
QuarantineFile('C:\Windows\syswow64\hfpapi.dll','');
QuarantineFile('C:\Windows\system32\nethtsrv.exe','');
QuarantineFile('C:\Windows\system32\hfpapi.dll','');
QuarantineFile('C:\Users\www\AppData\Local\Temp\svchost.exe','');
QuarantineFile('C:\Users\www\AppData\Roaming\Dorrible\Ribble\d.exe','');
QuarantineFile('C:\Program Files (x86)\Microsoft Data\InstallAddons.exe','');
DelBHO('{1B084C86-9657-42F9-A5E5-AC8DD832CDE9}');
QuarantineFile('C:\Program Files (x86)\Speed Test\ScriptHost.dll','');
QuarantineFile('C:\Users\www\AppData\Local\Temp\revault.js','');
QuarantineFile('C:\Users\www\AppData\Local\Kometa\kometaup.exe','');
QuarantineFile('C:\Users\www\AppData\Local\Kometa\Panel\KometaLaunchPanel.exe','');
QuarantineFile('C:\Users\www\AppData\Local\Kometa\Application\kometa.exe','');
DeleteFile('C:\Users\www\AppData\Local\Kometa\Application\kometa.exe','32');
DeleteFile('C:\Users\www\AppData\Local\Kometa\Panel\KometaLaunchPanel.exe','32');
DeleteFile('C:\Users\www\AppData\Local\Kometa\kometaup.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\kometaup','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KometaLaunchPanel','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KometaAutoLaunch_F0DEA1DDD1514EB2E1B379A0ABFF2FB3','command');
DeleteFile('C:\Users\www\AppData\Local\Temp\revault.js','32');
DeleteFile('C:\Users\www\AppData\Local\Temp\VAULT.txt','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\tnotify','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\vltexec','command');
DeleteFile('C:\Program Files (x86)\Speed Test\ScriptHost.dll','32');
DeleteFile('C:\Program Files (x86)\Microsoft Data\InstallAddons.exe','32');
DeleteFile('C:\Windows\system32\Tasks\chrome5','64');
DeleteFile('C:\Windows\system32\Tasks\chrome5_logon','64');
DeleteFile('C:\Users\www\AppData\Roaming\Dorrible\Ribble\d.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Ribble','64');
DeleteFile('C:\Users\www\AppData\Local\Temp\svchost.exe','32');
DeleteFile('C:\Windows\system32\hfpapi.dll','32');
DeleteFile('C:\Windows\system32\nethtsrv.exe','32');
DeleteFile('C:\Windows\syswow64\hfpapi.dll','32');
DeleteFile('C:\Windows\syswow64\nethtsrv.exe','32');
DeleteFile('C:\Windows\SysWOW64\nethtsrv.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Компьютер перезагрузится.