Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\PROGRA~1\GROOVE~1\Sauqiu.bat','');
QuarantineFile('C:\Users\бушмен\AppData\Local\4562\Updater.exe','');
DelBHO('{8E8F97CD-60B5-456F-A201-73065652D099}');
QuarantineFile('C:\ProgramData\WUziOq\eVXmfK5.bat','');
QuarantineFile('C:\ProgramData\SoLEklaaLW\WxwUaEOjFA0.bat','');
QuarantineFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe','');
QuarantineFile('C:\Program Files (x86)\rec_en_77\rec_en_77.exe','');
QuarantineFile('C:\Program Files (x86)\gmsd_ru_005010216\gmsd_ru_005010216.exe','');
QuarantineFile('C:\Program Files (x86)\gmsd_ru_005010214\gmsd_ru_005010214.exe','');
QuarantineFile('C:\Users\бушмен\AppData\Local\Birds\birds365.exe','');
QuarantineFile('C:\Windows\system32\DRIVERS\MPCKpt.sys','');
DeleteService('MPCKpt');
SetServiceStart('WdMan', 4);
SetServiceStart('sozidunozbt', 4);
DeleteService('sozidunozbt');
DeleteService('WdMan');
TerminateProcessByName('C:\Program Files\Sound+\idscservice.exe');
TerminateProcessByName('c:\program files (x86)\95ec4d18-1453467169-11e0-a8b3-7fd3463d2da4\knsj107.tmpfs');
TerminateProcessByName('c:\users\бушмен\appdata\local\95ec4d18-1454171977-11e0-a8b3-7fd3463d2da4\qnsw3d40.tmp');
TerminateProcessByName('c:\programdata\dwdmd\wdman.exe');
QuarantineFile('c:\programdata\dwdmd\wdman.exe','');
QuarantineFile('c:\users\бушмен\appdata\local\95ec4d18-1454171977-11e0-a8b3-7fd3463d2da4\qnsw3d40.tmp','');
QuarantineFile('c:\program files (x86)\95ec4d18-1453467169-11e0-a8b3-7fd3463d2da4\knsj107.tmpfs','');
DeleteFile('C:\Program Files\Sound+\idscservice.exe','32');
DeleteFile('c:\users\бушмен\appdata\local\95ec4d18-1454171977-11e0-a8b3-7fd3463d2da4\qnsw3d40.tmp','32');
DeleteFile('c:\programdata\dwdmd\wdman.exe','32');
DeleteFile('C:\Windows\system32\DRIVERS\MPCKpt.sys','32');
DeleteFile('C:\Users\бушмен\AppData\Local\Birds\birds365.exe','32');
DeleteFile('C:\Program Files (x86)\gmsd_ru_005010214\gmsd_ru_005010214.exe','32');
DeleteFile('C:\Program Files (x86)\gmsd_ru_005010216\gmsd_ru_005010216.exe','32');
DeleteFile('C:\Program Files (x86)\rec_en_77\rec_en_77.exe','32');
DeleteFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SpaceSoundPro','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\rec_en_77','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\gmsd_ru_005010216','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\gmsd_ru_005010214','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Birds','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\amigo','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MailRuUpdater','command');
DeleteFile('C:\ProgramData\SoLEklaaLW\WxwUaEOjFA0.bat','32');
DeleteFile('C:\ProgramData\WUziOq\eVXmfK5.bat','32');
DeleteFile('C:\Users\бушмен\AppData\Local\Mail.Ru\Sputnik\IESearchPlugin.dll','32');
DeleteFile('C:\Users\бушмен\AppData\Local\4562\Updater.exe','32');
DeleteFile('C:\Windows\system32\Tasks\AmiUpdXp','64');
DeleteFile('C:\Windows\Tasks\AmiUpdXp.job','32');
DeleteFile('C:\Windows\system32\Tasks\Ijiciluq','64');
DeleteFile('C:\PROGRA~1\GROOVE~1\Sauqiu.bat','32');
DeleteFile('C:\Users\бушмен\AppData\Local\Temp\nsh93B8.tmp\blowfish.dll','32');
DeleteFile('C:\Users\бушмен\AppData\Local\Temp\nsw3505.tmp\blowfish.dll','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.