Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\Татьяна\appdata\local\xservice\xservice.dll','');
QuarantineFile('C:\Users\Татьяна\AppData\Local\Disc_Soft_Ltd\2329914613_123.exe','');
QuarantineFile('C:\Windows\Temp\JZkOEbITvPfCrZRe\hlQGcRqvv.exe','');
QuarantineFile('C:\Users\Татьяна\AppData\Local\Temp\skf53415tox\nuwpqicunde.exe','');
QuarantineFile('C:\Users\Татьяна\AppData\Local\Temp\wy1oaos0pqb\nuwpqicunde.exe','');
DeleteService('NmE1ZWFhOTQ');
DeleteService('NDk3NWVmY');
DeleteService('5B687B5');
DeleteService('46e7d78f24c40a11');
DeleteService('46e72fa46fda3d91');
DeleteService('46e72fa3954f6311');
SetServiceStart('MDc0O', 4);
SetServiceStart('OWJhMDNlNzRjNz', 4);
DeleteService('OWJhMDNlNzRjNz');
DeleteService('MDc0O');
DeleteService('Voyasollam');
DeleteService('Starter Check');
QuarantineFile('C:\ProgramData\Voyasollam\Voyasollam.exe','');
QuarantineFile('C:\ProgramData\WindowsMenu\enplus.exe','');
SetServiceStart('NzNhZWI5ZmU0', 4);
DeleteService('NzNhZWI5ZmU0');
QuarantineFile('C:\Windows\system32\drivers\YTFhOGFhMTYzYTJ.sys','');
QuarantineFile('C:\Windows\system32\drivers\OWJhMDNlNzRjNz','');
QuarantineFile('C:\Windows\system32\drivers\MDc0O','');
QuarantineFile('C:\Windows\TEMP\d532471.sys','');
QuarantineFile('C:\Windows\hdazelhq.xdaz','');
TerminateProcessByName('c:\program files\njdjode1zdm\ytrhyty4mmy1ndn.exe');
QuarantineFile('c:\program files\njdjode1zdm\ytrhyty4mmy1ndn.exe','');
DeleteFile('c:\program files\njdjode1zdm\ytrhyty4mmy1ndn.exe','32');
DeleteFile('C:\Windows\hdazelhq.xdaz','32');
DeleteFile('C:\Windows\TEMP\d532471.sys','32');
DeleteFile('C:\Windows\system32\drivers\MDc0O','32');
DeleteFile('C:\Windows\system32\drivers\OWJhMDNlNzRjNz','32');
DeleteFile('C:\Windows\system32\drivers\YTFhOGFhMTYzYTJ.sys','32');
DeleteFile('C:\ProgramData\WindowsMenu\enplus.exe','32');
DeleteFile('C:\ProgramData\Voyasollam\Voyasollam.exe','32');
DeleteFile('C:\Windows\TEMP\4ef9b42.sys','32');
DeleteFile('C:\Windows\TEMP\4e980d7.sys','32');
DeleteFile('C:\Windows\TEMP\4699953.sys','32');
DeleteFile('C:\Windows\system32\drivers\NDk3NWVmY.sys','32');
DeleteFile('C:\Windows\system32\drivers\NmE1ZWFhOTQ.sys','32');
DeleteFile('C:\Windows\Tasks\bkudKjWCXsrqkasAqgw.job','32');
DeleteFile('C:\Users\Татьяна\AppData\Local\Temp\wy1oaos0pqb\nuwpqicunde.exe','32');
DeleteFile('C:\Windows\Tasks\bkuejJVJrSPUQurIjwW.job','32');
DeleteFile('C:\Users\Татьяна\AppData\Local\Temp\skf53415tox\nuwpqicunde.exe','32');
DeleteFile('C:\Windows\Temp\JZkOEbITvPfCrZRe\hlQGcRqvv.exe','32');
DeleteFile('C:\Windows\system32\Tasks\bkudKjWCXsrqkasAqgw','64');
DeleteFile('C:\Windows\Tasks\bkugwyMExRQeEPYRDty.job','32');
DeleteFile('C:\Users\Татьяна\AppData\Local\Disc_Soft_Ltd\2329914613_123.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Disc_Soft_Ltd Updater','64');
DeleteFile('C:\Windows\system32\Tasks\bkugwyMExRQeEPYRDty','64');
DeleteFile('C:\Windows\system32\Tasks\bkuejJVJrSPUQurIjwW','64');
DeleteFile('C:\Windows\system32\Tasks\GoogleUpdateService','64');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\QuickLaunch','64');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\Starter','64');
DeleteFile('C:\Windows\system32\Tasks\{04B660CC-EB13-0326-965B-4CF5260FF119}','64');
DeleteFile('C:\Users\Татьяна\appdata\local\xservice\xservice.dll','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.