Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('F:\windrv.exe','');
QuarantineFile('F:\autorun.inf','');
QuarantineFile('E:\autorun.inf','');
QuarantineFile('E:\windrv.exe','');
QuarantineFile('C:\Documents and Settings\Владелец\Application Data\Microsoft\Windows\IEUpdate\wscntfy.exe','');
QuarantineFile('C:\Documents and Settings\Владелец\Application Data\Microsoft\Windows\IEUpdate\esentutl.exe','');
QuarantineFile('C:\Documents and Settings\Владелец\Application Data\Microsoft\Windows\IEUpdate\actmovie.exe','');
QuarantineFile('c:\documents and settings\Владелец\wuaucldt.exe','');
QuarantineFile('C:\WINDOWS\winlogon_45.exe','');
QuarantineFile('C:\Documents and Settings\Владелец\Application Data\Microsoft\tyhyhiwyn.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1455\fresdg.exe','');
QuarantineFile('C:\WINDOWS\M-5050750432626272464870\windrv.exe','');
QuarantineFile('C:\WINDOWS\M-5050340395869302039403434737876\winsvc.exe','');
QuarantineFile('C:\WINDOWS\M-505045835374846834537486967020\windrv.exe','');
QuarantineFile('C:\windows\M-505039509030353677952470635045253050\winsvc.exe','');
QuarantineFile('C:\Documents and Settings\Владелец\Application Data\rundll32.exe','');
QuarantineFile('C:\windows\M-50504527908968746306450979006840850\winmgr.exe','');
QuarantineFile('C:\windows\C-59485327593927938375876992920\windrv32.exe','');
QuarantineFile('C:\WINDOWS\system32\UKbhokLVglKmPI.exe','');
TerminateProcessByName('c:\docume~1\7b5c~1\locals~1\temp\mipxrdneax.exe');
QuarantineFile('c:\docume~1\7b5c~1\locals~1\temp\mipxrdneax.exe','');
TerminateProcessByName('c:\windows\m-505039509030353677952470635045253050\winsvc.exe');
TerminateProcessByName('c:\windows\c-59485327593927938375876992920\windrv32.exe');
TerminateProcessByName('c:\documents and settings\Владелец\application data\rundll32.exe');
QuarantineFile('c:\documents and settings\Владелец\application data\rundll32.exe','');
QuarantineFile('c:\windows\c-59485327593927938375876992920\windrv32.exe','');
QuarantineFile('c:\windows\m-505039509030353677952470635045253050\winsvc.exe','');
DeleteFile('c:\windows\m-505039509030353677952470635045253050\winsvc.exe','32');
DeleteFile('c:\windows\c-59485327593927938375876992920\windrv32.exe','32');
DeleteFile('c:\documents and settings\Владелец\application data\rundll32.exe','32');
DeleteFile('c:\docume~1\7b5c~1\locals~1\temp\mipxrdneax.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Windows Service');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Windows Update');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Windows');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Driver');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Windows Manager');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Windows Security');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Windows Service');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Service Host Process for Windows');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Windows Manager');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Windows Security');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','NRYj__DJCBTOoBaXynvyEbkAgl');
DeleteFile('C:\WINDOWS\system32\UKbhokLVglKmPI.exe','32');
DeleteFile('C:\windows\C-59485327593927938375876992920\windrv32.exe','32');
DeleteFile('C:\windows\M-50504527908968746306450979006840850\winmgr.exe','32');
DeleteFile('C:\Documents and Settings\Владелец\Application Data\rundll32.exe','32');
DeleteFile('C:\windows\M-505039509030353677952470635045253050\winsvc.exe','32');
DeleteFile('C:\WINDOWS\M-505045835374846834537486967020\windrv.exe','32');
DeleteFile('C:\WINDOWS\M-5050340395869302039403434737876\winsvc.exe','32');
DeleteFile('C:\WINDOWS\M-5050750432626272464870\windrv.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\boutevid','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Fredg Application','command');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1455\fresdg.exe','32');
DeleteFile('C:\Documents and Settings\Владелец\Application Data\Microsoft\tyhyhiwyn.exe','32');
DeleteFile('C:\WINDOWS\winlogon_45.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Microsoft Security Essentials','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RDReminder','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\wougoow','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\wuaucldt','command');
DeleteFile('c:\documents and settings\Владелец\wuaucldt.exe','32');
DeleteFile('E:\windrv.exe','32');
DeleteFile('E:\autorun.inf','32');
DeleteFile('F:\autorun.inf','32');
DeleteFile('F:\windrv.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.