Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\rwyntbft.bat','');
QuarantineFile('C:\autorun.inf','');
QuarantineFile('C:\WINDOWS\system32\iwhfulyvhbxksoadr.exe','');
QuarantineFile('C:\WINDOWS\Temp\iwhfulyvhbxksoadr.exe','');
QuarantineFile('C:\WINDOWS\system32\ewlngbstjhhykkahzoqje.exe','');
QuarantineFile('C:\WINDOWS\Temp\pguvnhxxmjiyjixduijb.exe .','');
QuarantineFile('C:\WINDOWS\system32\pguvnhxxmjiyjixduijb.exe','');
QuarantineFile('C:\WINDOWS\Temp\rgsrhznlytqenkxbqc.exe','');
QuarantineFile('C:\WINDOWS\system32\csffwpedrnlakiwbree.exe','');
TerminateProcessByName('c:\windows\temp\cghvahk.exe');
TerminateProcessByName('c:\windows\temp\boyvjzlhslgszufh.exe');
QuarantineFile('c:\windows\temp\cghvahk.exe','');
QuarantineFile('c:\windows\temp\boyvjzlhslgszufh.exe','');
DeleteFile('c:\windows\temp\boyvjzlhslgszufh.exe','32');
DeleteFile('c:\windows\temp\cghvahk.exe','32');
DeleteFile('C:\WINDOWS\system32\csffwpedrnlakiwbree.exe','32');
DeleteFile('C:\WINDOWS\Temp\rgsrhznlytqenkxbqc.exe','32');
DeleteFile('C:\WINDOWS\system32\pguvnhxxmjiyjixduijb.exe','32');
DeleteFile('C:\WINDOWS\Temp\pguvnhxxmjiyjixduijb.exe .','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','bimdlvbrwj');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','pssfjp');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','wejbkvctznd');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','egfru');
DeleteFile('C:\WINDOWS\system32\ewlngbstjhhykkahzoqje.exe','32');
DeleteFile('C:\WINDOWS\Temp\iwhfulyvhbxksoadr.exe','32');
DeleteFile('C:\WINDOWS\system32\iwhfulyvhbxksoadr.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','pssfjp');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','iorhoxcrv');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','egfru');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','rwyntbft');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','vwuf');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','cghvahk');
DeleteFile('C:\autorun.inf','32');
DeleteFile('C:\rwyntbft.bat','32')
RegKeyIntParamWrite('HKLM','SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer','NoDriveTypeAutoRun', 221);
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.