Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('c:\Users\All Users\dtdata\R001.exe','');
QuarantineFile('c:\Users\All Users\dtdata\R002.exe','');
QuarantineFile('C:\Program Files (x86)\Torrent Search\J2QfL7BU_T.exe','');
QuarantineFile('C:\Program Files (x86)\Cinema Plus Pro 3.2cV29.03\ddfbb344-2123-4a91-b89a-28f72e069b86-7.exe','');
QuarantineFile('C:\Program Files (x86)\Cinema Plus Pro 3.2cV29.03\ddfbb344-2123-4a91-b89a-28f72e069b86-6.exe','');
QuarantineFile('C:\Program Files (x86)\Cinema Plus Pro 3.2cV29.03\ddfbb344-2123-4a91-b89a-28f72e069b86-5.exe','');
QuarantineFile('C:\Program Files (x86)\Cinema Plus Pro 3.2cV29.03\ddfbb344-2123-4a91-b89a-28f72e069b86-10.exe','');
QuarantineFile('C:\Program Files (x86)\Cinema Plus Pro 3.2cV29.03\ddfbb344-2123-4a91-b89a-28f72e069b86-3.exe','');
QuarantineFile('C:\Program Files (x86)\Cinema Plus Pro 3.2cV29.03\ddfbb344-2123-4a91-b89a-28f72e069b86-1-7.exe','');
QuarantineFile('C:\Program Files (x86)\Cinema Plus Pro 3.2cV29.03\ddfbb344-2123-4a91-b89a-28f72e069b86-1-6.exe','');
QuarantineFile('C:\Users\Gera\AppData\Local\SwvUpdater\Updater.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-7.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-6.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-5.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-3.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-11.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-10.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-1-7.exe','');
QuarantineFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-1-6.exe','');
QuarantineFile('C:\iexplore.bat','');
QuarantineFile('C:\Users\Gera\AppData\Roaming\desktopy.ru\desktopy.exe','');
QuarantineFile('C:\Program Files (x86)\Google\chrome.bat','');
DeleteFile('C:\Program Files (x86)\Google\chrome.bat','32');
DeleteFile('C:\Users\Gera\AppData\Roaming\desktopy.ru\desktopy.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\desktopy','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NextLive','command');
DeleteFile('C:\Users\Gera\AppData\Roaming\newnext.me\nengine.dll','32');
DeleteFile('C:\iexplore.bat','32');
DeleteFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-1-6.exe','32');
DeleteFile('C:\Windows\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-1-6.job','64');
DeleteFile('C:\Windows\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-1-7.job','64');
DeleteFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-1-7.exe','32');
DeleteFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-10.exe','32');
DeleteFile('C:\Windows\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-10_user.job','64');
DeleteFile('C:\Windows\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-11.job','64');
DeleteFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-11.exe','32');
DeleteFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-3.exe','32');
DeleteFile('C:\Windows\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-3.job','64');
DeleteFile('C:\Windows\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-5.job','64');
DeleteFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-5.exe','32');
DeleteFile('C:\Windows\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-5_user.job','64');
DeleteFile('C:\Windows\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-6.job','64');
DeleteFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-6.exe','32');
DeleteFile('C:\Program Files (x86)\CinemaP-1.4cV29.03\619e4d32-4b39-42b9-af30-429a8e9aa88a-7.exe','32');
DeleteFile('C:\Windows\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-7.job','64');
DeleteFile('C:\Windows\Tasks\AmiUpdXp.job','64');
DeleteFile('C:\Users\Gera\AppData\Local\SwvUpdater\Updater.exe','32');
DeleteFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP1.job','64');
DeleteFile('C:\Windows\Tasks\APSnotifierPP2.job','64');
DeleteFile('C:\Windows\Tasks\APSnotifierPP3.job','64');
DeleteFile('C:\Windows\Tasks\ddfbb344-2123-4a91-b89a-28f72e069b86-1-6.job','64');
DeleteFile('C:\Program Files (x86)\Cinema Plus Pro 3.2cV29.03\ddfbb344-2123-4a91-b89a-28f72e069b86-1-6.exe','32');
DeleteFile('C:\Program Files (x86)\Cinema Plus Pro 3.2cV29.03\ddfbb344-2123-4a91-b89a-28f72e069b86-1-7.exe','32');
DeleteFile('C:\Windows\Tasks\ddfbb344-2123-4a91-b89a-28f72e069b86-1-7.job','64');
DeleteFile('C:\Windows\Tasks\ddfbb344-2123-4a91-b89a-28f72e069b86-10_user.job','64');
DeleteFile('C:\Windows\Tasks\ddfbb344-2123-4a91-b89a-28f72e069b86-3.job','64');
DeleteFile('C:\Program Files (x86)\Cinema Plus Pro 3.2cV29.03\ddfbb344-2123-4a91-b89a-28f72e069b86-3.exe','32');
DeleteFile('C:\Program Files (x86)\Cinema Plus Pro 3.2cV29.03\ddfbb344-2123-4a91-b89a-28f72e069b86-10.exe','32');
DeleteFile('C:\Program Files (x86)\Cinema Plus Pro 3.2cV29.03\ddfbb344-2123-4a91-b89a-28f72e069b86-5.exe','32');
DeleteFile('C:\Program Files (x86)\Cinema Plus Pro 3.2cV29.03\ddfbb344-2123-4a91-b89a-28f72e069b86-6.exe','32');
DeleteFile('C:\Windows\Tasks\ddfbb344-2123-4a91-b89a-28f72e069b86-5.job','64');
DeleteFile('C:\Windows\Tasks\ddfbb344-2123-4a91-b89a-28f72e069b86-5_user.job','64');
DeleteFile('C:\Windows\Tasks\ddfbb344-2123-4a91-b89a-28f72e069b86-6.job','64');
DeleteFile('C:\Windows\Tasks\ddfbb344-2123-4a91-b89a-28f72e069b86-7.job','64');
DeleteFile('C:\Program Files (x86)\Cinema Plus Pro 3.2cV29.03\ddfbb344-2123-4a91-b89a-28f72e069b86-7.exe','32');
DeleteFile('C:\Program Files (x86)\Torrent Search\J2QfL7BU_T.exe','32');
DeleteFile('C:\Windows\Tasks\Update Service for Torrent Search.job','64');
DeleteFile('C:\Windows\Tasks\Update Service for Torrent Search2.job','64');
DeleteFile('C:\Windows\system32\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-1-6','64');
DeleteFile('C:\Windows\system32\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-1-7','64');
DeleteFile('C:\Windows\system32\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-11','64');
DeleteFile('C:\Windows\system32\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-3','64');
DeleteFile('C:\Windows\system32\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-5','64');
DeleteFile('C:\Windows\system32\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-6','64');
DeleteFile('C:\Windows\system32\Tasks\619e4d32-4b39-42b9-af30-429a8e9aa88a-7','64');
DeleteFile('C:\Windows\system32\Tasks\AmiUpdXp','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP1','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP2','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP3','64');
DeleteFile('C:\Windows\system32\Tasks\ddfbb344-2123-4a91-b89a-28f72e069b86-1-6','64');
DeleteFile('C:\Windows\system32\Tasks\ddfbb344-2123-4a91-b89a-28f72e069b86-1-7','64');
DeleteFile('C:\Windows\system32\Tasks\ddfbb344-2123-4a91-b89a-28f72e069b86-3','64');
DeleteFile('C:\Windows\system32\Tasks\ddfbb344-2123-4a91-b89a-28f72e069b86-5','64');
DeleteFile('C:\Windows\system32\Tasks\ddfbb344-2123-4a91-b89a-28f72e069b86-6','64');
DeleteFile('C:\Windows\system32\Tasks\ddfbb344-2123-4a91-b89a-28f72e069b86-7','64');
DeleteFile('c:\Users\All Users\dtdata\R002.exe','32');
DeleteFile('c:\Users\All Users\dtdata\R001.exe','32');
DeleteFile('C:\Windows\system32\Tasks\DefaultReg','64');
DeleteFile('C:\Windows\system32\Tasks\DefaultCheck','64');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Компьютер перезагрузится.