Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12389\newcont9rnd8.exe');
TerminateProcessByName('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12367\newcont7rnd6.exe');
TerminateProcessByName('c:\documents and settings\Администратор\application data\20.exe');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12389\newcont9rnd8.exe','');
QuarantineFile('c:\recycler\s-1-5-21-0243556031-888888379-781863308-12367\newcont7rnd6.exe','');
QuarantineFile('c:\documents and settings\Администратор\application data\20.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-12389\newcont9rnd8.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-12367\newcont7rnd6.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\20.exe','');
QuarantineFile('C:\untivirus\avz4\Infected\2012-08-16\avz00004.dta','');
QuarantineFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\7YDO0S7Z\r1234[1].jpg','');
QuarantineFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\7YDO0S7Z\xx3[1].exe','');
QuarantineFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\Q73BN5KI\rxyb[1].bmp','');
QuarantineFile('C:\Documents and Settings\Администратор\fuwin3.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\18.exe.gonewiththewings','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\19.exe.gonewiththewings','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\1A.exe.gonewiththewings','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\1B.exe.gonewiththewings','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\1C.exe.gonewiththewings','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\1F.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\22.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\23.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\24.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\25.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\26.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\28.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\29.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\2A.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\32.exe.gonewiththewings','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\33.exe.gonewiththewings','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\34.exe.gonewiththewings','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\36.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\37.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Local Settings\Temporary Internet Files\Content.IE5\5WC7H5SD\cv[1].exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Local Settings\Temporary Internet Files\Content.IE5\5WC7H5SD\cv[1].exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\27.exe','');
QuarantineFile('C:\WINDOWS\logfile32.txt','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\21.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\nd.bin','');
QuarantineFile('C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini','');
QuarantineFile('C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe','');
QuarantineFile('C:\WINDOWS\system32\wsnpoem\audio.dll','');
QuarantineFile('C:\WINDOWS\system32\wsnpoem\audio.dll.cla','');
QuarantineFile('C:\WINDOWS\system32\wsnpoem\video.dll','');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\20.exe');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-12367\newcont7rnd6.exe');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-12389\newcont9rnd8.exe');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-12389\newcont9rnd8.exe');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-12367\newcont7rnd6.exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\20.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035548.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035566.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0033459.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0034492.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035479.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035487.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035495.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035515.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035526.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035528.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035547.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035549.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035551.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035565.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035567.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035568.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035571.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035585.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035586.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035587.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035591.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035592.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035594.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035595.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035607.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035608.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035609.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035610.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035611.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035612.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035625.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035632.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035634.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035636.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035637.exe');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035641.scr');
DeleteFile('C:\System Volume Information\_restore{9AFD8FEB-80BE-4A7D-80E7-F7F4EA909FF4}\RP39\A0035642.exe');
DeleteFile('C:\untivirus\avz4\Infected\2012-08-16\avz00004.dta');
DeleteFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\7YDO0S7Z\r1234[1].jpg');
DeleteFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\7YDO0S7Z\xx3[1].exe');
DeleteFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\Q73BN5KI\rxyb[1].bmp');
DeleteFile('C:\Documents and Settings\Администратор\fuwin3.exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\18.exe.gonewiththewings');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\19.exe.gonewiththewings');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\1A.exe.gonewiththewings');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\1B.exe.gonewiththewings');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\1C.exe.gonewiththewings');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\1F.exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\22.exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\23.exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\24.exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\25.exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\26.exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\28.exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\29.exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\2A.exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\32.exe.gonewiththewings');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\33.exe.gonewiththewings');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\34.exe.gonewiththewings');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\36.exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\37.exe');
DeleteFile('C:\Documents and Settings\Администратор\Local Settings\Temporary Internet Files\Content.IE5\5WC7H5SD\cv[1].exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\27.exe');
DeleteFile('C:\WINDOWS\logfile32.txt');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\21.exe');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\nd.bin');
DeleteFile('C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini');
DeleteFile('C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-12389\newcont9rnd8.exe,explorer.exe,C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-12367\newcont7rnd6.exe');
DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-12367\newcont7rnd6.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','MSSMARTMON1');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','newcontr7nd6');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','newcontr9nd8');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteWizard('TSW',2,3,true);
RebootWindows(true);
end.