Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Program Files (x86)\YubeAlckU\iuQhMgB.dll','');
QuarantineFile('C:\Program Files (x86)\MediaSerchU\xOvtuxq.dll','');
QuarantineFile('C:\Program Files (x86)\Coejershgiduph\RepacooleiedCch.dll','');
QuarantineFile('C:\Program Files\Synaptics\QF4MJBYTBISZRIZ92\yBl2M8-W5p.exe','');
DeleteService('4F95B43A5075BD18');
QuarantineFile('c:\program files (x86)\coejershgiduph\repacooleiedcch.dll','');
TerminateProcessByName('C:\Users\JENSEN\AppData\Roaming\plygrk4rte5\wjtnaidcsmx.exe');
QuarantineFile('C:\Users\JENSEN\AppData\Roaming\plygrk4rte5\wjtnaidcsmx.exe','');
TerminateProcessByName('C:\Users\JENSEN\AppData\Roaming\2slz2re2j4h\qk0jde5021h.exe');
QuarantineFile('C:\Users\JENSEN\AppData\Roaming\2slz2re2j4h\qk0jde5021h.exe','');
TerminateProcessByName('C:\Users\JENSEN\AppData\Roaming\mkq1nxb402t\lxu1nesvxlh.exe');
TerminateProcessByName('C:\Users\JENSEN\AppData\Roaming\jufjt2o0sn3\ntyirqnigft.exe');
QuarantineFile('C:\Users\JENSEN\AppData\Roaming\jufjt2o0sn3\ntyirqnigft.exe','');
QuarantineFile('C:\Users\JENSEN\AppData\Roaming\mkq1nxb402t\lxu1nesvxlh.exe','');
TerminateProcessByName('C:\Windows\Temp\g623C.tmp.exe');
QuarantineFile('C:\Windows\Temp\g623C.tmp.exe','');
DeleteFile('C:\Windows\Temp\g623C.tmp.exe','32');
DeleteFile('C:\Users\JENSEN\AppData\Roaming\mkq1nxb402t\lxu1nesvxlh.exe','32');
DeleteFile('C:\Users\JENSEN\AppData\Roaming\jufjt2o0sn3\ntyirqnigft.exe','32');
DeleteFile('C:\Users\JENSEN\AppData\Roaming\2slz2re2j4h\qk0jde5021h.exe','32');
DeleteFile('C:\Users\JENSEN\AppData\Roaming\plygrk4rte5\wjtnaidcsmx.exe','32');
DeleteFile('c:\program files (x86)\coejershgiduph\repacooleiedcch.dll','32');
DeleteFile('C:\Program Files\Synaptics\QF4MJBYTBISZRIZ92\yBl2M8-W5p.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','yBl2M8-W5p.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','absrepletqn');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','j0pncejvuwk');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','rptbmibnnvz');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','be5xgubshi2');
DeleteFile('C:\Program Files (x86)\Coejershgiduph\RepacooleiedCch.dll','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Aracity\Parameters','ServiceDll');
DeleteFile('C:\Program Files (x86)\MediaSerchU\xOvtuxq.dll','32');
DeleteFile('C:\Program Files (x86)\YubeAlckU\iuQhMgB.dll','32');
DeleteFile('C:\Windows\system32\Tasks\6E727987-C8EA-44DA-8749-310C0FBE3C3E','64');
DeleteFile('C:\Windows\Tasks\E3605470-291B-44EB-8648-745EE356599A.job','32');
DeleteFile('C:\Windows\Tasks\6E727987-C8EA-44DA-8749-310C0FBE3C3E.job','32');
DeleteFile('C:\Windows\system32\Tasks\6E727987-C8EA-44DA-8749-310C0FBE3C3E2','64');
DeleteFile('C:\Windows\system32\Tasks\E3605470-291B-44EB-8648-745EE356599A','64');
DeleteFile('C:\Windows\system32\Tasks\E3605470-291B-44EB-8648-745EE356599A2','64');
DeleteFile('C:\Windows\system32\Tasks\f5eb5562200cc901e1c3aa1d8fc02814','64');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\Wininet\PerfChecker','64');
DeleteFile('C:\Users\JENSEN\AppData\Local\GeoLocator\perfchecker.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.