Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
QuarantineFile('C:\Program Files (x86)\LuckyTab\LuckyTab.exe','');
QuarantineFile('C:\Program Files (x86)\Microsoft Data\InstallAddons.exe','');
QuarantineFile('C:\Users\Admin\AppData\Local\Yandex\browser.bat','');
QuarantineFile('C:\Windows\system32\drivers\{fc8e6a5c-9413-4b64-b2fd-0aad0e9e50eb}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{fa50efa5-2c2a-4d8c-b58d-b9548ceccd2b}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{f06ee1ad-d0c2-4bf7-ada2-fa0fb563c169}w64.sys','');
DeleteService('{fc8e6a5c-9413-4b64-b2fd-0aad0e9e50eb}w64');
DeleteService('{fa50efa5-2c2a-4d8c-b58d-b9548ceccd2b}w64');
DeleteService('{f06ee1ad-d0c2-4bf7-ada2-fa0fb563c169}w64');
QuarantineFile('C:\Windows\system32\drivers\{f0140d89-3c88-497e-896f-f889e74b42b2}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{e168bb47-74a7-440b-bf7d-d17153007d6b}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{c60870f2-8f6e-46c4-b1de-a1d328298cb8}w64.sys','');
DeleteService('{f0140d89-3c88-497e-896f-f889e74b42b2}w64');
DeleteService('{e168bb47-74a7-440b-bf7d-d17153007d6b}w64');
DeleteService('{c60870f2-8f6e-46c4-b1de-a1d328298cb8}w64');
QuarantineFile('C:\Windows\system32\drivers\{9ba18a1b-2c6c-45d9-9fbe-65697713d97f}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{ad76b08b-33a4-43ec-bb65-7d1eaac9bf0c}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{b52a596e-357b-4007-9a88-5592a17b1be9}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{bf167862-9559-4b38-94c6-2e5edae3632c}w64.sys','');
DeleteService('{bf167862-9559-4b38-94c6-2e5edae3632c}w64');
DeleteService('{b52a596e-357b-4007-9a88-5592a17b1be9}w64');
DeleteService('{ad76b08b-33a4-43ec-bb65-7d1eaac9bf0c}w64');
DeleteService('{9ba18a1b-2c6c-45d9-9fbe-65697713d97f}w64');
QuarantineFile('C:\Windows\system32\drivers\{5eeb83d0-96ea-4249-942c-beead6847053}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{651e31c1-db10-434b-a173-a9b0e6a15ce0}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{807699ff-a8ae-4ba9-8010-fe7f44646ff9}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{98a55059-ac5d-40d9-81ae-6bff294c9b89}w64.sys','');
DeleteService('{98a55059-ac5d-40d9-81ae-6bff294c9b89}w64');
DeleteService('{807699ff-a8ae-4ba9-8010-fe7f44646ff9}w64');
DeleteService('{651e31c1-db10-434b-a173-a9b0e6a15ce0}w64');
DeleteService('{5eeb83d0-96ea-4249-942c-beead6847053}w64');
QuarantineFile('C:\Windows\system32\drivers\{5ed000ad-96de-48d3-9cd7-f28c05fefd32}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{4b6b588f-fe6d-43d5-96e6-6583434569cd}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{4059f7a9-d023-4137-a1c8-01f0f6fe6110}w64.sys','');
DeleteService('{5ed000ad-96de-48d3-9cd7-f28c05fefd32}w64');
DeleteService('{4b6b588f-fe6d-43d5-96e6-6583434569cd}w64');
DeleteService('{4059f7a9-d023-4137-a1c8-01f0f6fe6110}w64');
DeleteService('{397e3208-0393-47ca-9748-370b27e14021}w64');
QuarantineFile('C:\Windows\system32\drivers\{397e3208-0393-47ca-9748-370b27e14021}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{2f1ed632-8cc1-4969-916a-211c6b0412c1}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{18a07fe2-6dab-4dea-b06c-b5b637cbeb7b}w64.sys','');
DeleteService('{2f1ed632-8cc1-4969-916a-211c6b0412c1}w64');
DeleteService('{18a07fe2-6dab-4dea-b06c-b5b637cbeb7b}w64');
QuarantineFile('C:\Windows\system32\drivers\{1291a179-48c2-4af9-ac74-8bb11631a9df}w64.sys','');
DeleteService('{1291a179-48c2-4af9-ac74-8bb11631a9df}w64');
DeleteService('{06b330c2-0607-4547-8f68-86805edbaa23}w64');
QuarantineFile('C:\Windows\system32\drivers\{06b330c2-0607-4547-8f68-86805edbaa23}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\ssnfd_1_10_0_1.sys','');
DeleteService('ssnfd_1_10_0_1');
TerminateProcessByName('c:\programdata\windows\csrss.exe');
QuarantineFile('c:\programdata\windows\csrss.exe','');
DeleteFile('c:\programdata\windows\csrss.exe','32');
DeleteFile('C:\Windows\system32\drivers\ssnfd_1_10_0_1.sys','32');
DeleteFile('C:\Windows\system32\drivers\{06b330c2-0607-4547-8f68-86805edbaa23}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{1291a179-48c2-4af9-ac74-8bb11631a9df}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{18a07fe2-6dab-4dea-b06c-b5b637cbeb7b}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{2f1ed632-8cc1-4969-916a-211c6b0412c1}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{397e3208-0393-47ca-9748-370b27e14021}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{4059f7a9-d023-4137-a1c8-01f0f6fe6110}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{4b6b588f-fe6d-43d5-96e6-6583434569cd}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{5ed000ad-96de-48d3-9cd7-f28c05fefd32}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{98a55059-ac5d-40d9-81ae-6bff294c9b89}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{807699ff-a8ae-4ba9-8010-fe7f44646ff9}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{651e31c1-db10-434b-a173-a9b0e6a15ce0}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{5eeb83d0-96ea-4249-942c-beead6847053}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{bf167862-9559-4b38-94c6-2e5edae3632c}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{b52a596e-357b-4007-9a88-5592a17b1be9}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{ad76b08b-33a4-43ec-bb65-7d1eaac9bf0c}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{9ba18a1b-2c6c-45d9-9fbe-65697713d97f}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{c60870f2-8f6e-46c4-b1de-a1d328298cb8}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{e168bb47-74a7-440b-bf7d-d17153007d6b}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{f0140d89-3c88-497e-896f-f889e74b42b2}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{f06ee1ad-d0c2-4bf7-ada2-fa0fb563c169}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{fa50efa5-2c2a-4d8c-b58d-b9548ceccd2b}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{fc8e6a5c-9413-4b64-b2fd-0aad0e9e50eb}w64.sys','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Client Server Runtime Subsystem');
DeleteFile('C:\Users\Admin\AppData\Local\Yandex\browser.bat','32');
DeleteFile('C:\Program Files (x86)\Microsoft Data\InstallAddons.exe','32');
DeleteFile('C:\Windows\system32\Tasks\chrome5_logon','64');
DeleteFile('C:\Windows\system32\Tasks\chrome5','64');
DeleteFile('C:\Program Files (x86)\LuckyTab\LuckyTab.exe','32');
DeleteFile('C:\Windows\system32\Tasks\LuckyTab','64');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Компьютер перезагрузится.