Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
QuarantineFile('C:\Users\38th\local settings\application data\ExtensionInstaller_14\config.json','');
QuarantineFile('C:\Users\38th\local settings\application data\ExtensionInstaller_14\extinst.exe','');
QuarantineFile('C:\iexplore.bat','');
SetServiceStart('{ca4e7e4c-3ebf-4428-bf75-cc138b7061f1}w64', 4);
DeleteService('{ca4e7e4c-3ebf-4428-bf75-cc138b7061f1}w64');
SetServiceStart('{c88279d3-91dd-4bd9-ad38-681f71d6e36d}w64', 4);
SetServiceStart('{a16a1775-5ab3-4034-ac52-de0795db97f0}Gw64', 4);
DeleteService('{a16a1775-5ab3-4034-ac52-de0795db97f0}Gw64');
SetServiceStart('{91975f83-f39c-43cf-aad4-0b3396b0f6db}w64', 4);
DeleteService('{91975f83-f39c-43cf-aad4-0b3396b0f6db}w64');
SetServiceStart('{8299d9bc-4fe2-4889-9adf-025a0769d461}w64', 4);
DeleteService('{8299d9bc-4fe2-4889-9adf-025a0769d461}w64');
SetServiceStart('{507a9b68-2b48-4a22-b662-e674fb6a16f7}Gw64', 4);
DeleteService('{507a9b68-2b48-4a22-b662-e674fb6a16f7}Gw64');
SetServiceStart('{40d1e549-9fca-4f25-a19d-d845842dd635}w64', 4);
DeleteService('{40d1e549-9fca-4f25-a19d-d845842dd635}w64');
SetServiceStart('{2bf1e193-df72-4e3c-9f15-d1dc6e2f810f}Gw64', 4);
DeleteService('{2bf1e193-df72-4e3c-9f15-d1dc6e2f810f}Gw64');
SetServiceStart('{27899312-155f-40f3-8661-fb6675d82b4b}w64', 4);
DeleteService('{27899312-155f-40f3-8661-fb6675d82b4b}w64');
SetServiceStart('{078ad437-dc9f-4228-9edb-b3d1c0246ff8}Gw64', 4);
DeleteService('{078ad437-dc9f-4228-9edb-b3d1c0246ff8}Gw64');
QuarantineFile('C:\Windows\system32\drivers\{fb92e7a9-ee13-44c3-a51b-600382fe9211}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{ca4e7e4c-3ebf-4428-bf75-cc138b7061f1}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{c88279d3-91dd-4bd9-ad38-681f71d6e36d}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{a16a1775-5ab3-4034-ac52-de0795db97f0}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{91975f83-f39c-43cf-aad4-0b3396b0f6db}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{8299d9bc-4fe2-4889-9adf-025a0769d461}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{507a9b68-2b48-4a22-b662-e674fb6a16f7}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{40d1e549-9fca-4f25-a19d-d845842dd635}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{2bf1e193-df72-4e3c-9f15-d1dc6e2f810f}Gw64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{27899312-155f-40f3-8661-fb6675d82b4b}w64.sys','');
QuarantineFile('C:\Windows\system32\drivers\{078ad437-dc9f-4228-9edb-b3d1c0246ff8}Gw64.sys','');
TerminateProcessByName('c:\programdata\windows\csrss.exe');
QuarantineFile('c:\programdata\windows\csrss.exe','');
DeleteFile('c:\programdata\windows\csrss.exe','32');
DeleteFile('C:\Windows\system32\drivers\{078ad437-dc9f-4228-9edb-b3d1c0246ff8}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{27899312-155f-40f3-8661-fb6675d82b4b}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{2bf1e193-df72-4e3c-9f15-d1dc6e2f810f}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{40d1e549-9fca-4f25-a19d-d845842dd635}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{507a9b68-2b48-4a22-b662-e674fb6a16f7}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{8299d9bc-4fe2-4889-9adf-025a0769d461}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{91975f83-f39c-43cf-aad4-0b3396b0f6db}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{a16a1775-5ab3-4034-ac52-de0795db97f0}Gw64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{c88279d3-91dd-4bd9-ad38-681f71d6e36d}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{ca4e7e4c-3ebf-4428-bf75-cc138b7061f1}w64.sys','32');
DeleteFile('C:\Windows\system32\drivers\{fb92e7a9-ee13-44c3-a51b-600382fe9211}w64.sys','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Client Server Runtime Subsystem');
DeleteFile('C:\iexplore.bat','32');
DeleteFile('C:\Users\38th\local settings\application data\ExtensionInstaller_14\extinst.exe','32');
DeleteFile('C:\Windows\system32\Tasks\ExtensionInstallerX_14','64');
DeleteFile('C:\Users\38th\local settings\application data\ExtensionInstaller_14\config.json','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Компьютер перезагрузится.