Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
end;
ClearQuarantine;
TerminateProcessByName('c:\users\hg\appdata\roaming\ssleas.exe');
TerminateProcessByName('c:\programdata\iepluginservices\pluginservice.exe');
TerminateProcessByName('c:\users\hg\appdata\roaming\x11\engine.exe');
TerminateProcessByName('c:\programdata\windows\csrss.exe');
TerminateProcessByName('c:\users\hg\appdata\roaming\cppredistx86.exe');
StopService('IePluginServices');
QuarantineFile('C:\Users\hg\appdata\roaming\mediahit\shadow\mediahit.update\mediahit.update.process.exe','');
QuarantineFile('C:\Users\hg\appdata\roaming\closer.exe','');
QuarantineFile('C:\Windows\syswow64\winmonitor.exe','');
QuarantineFile('C:\Windows\syswow64\hfpapi.dll','');
QuarantineFile('C:\Windows\syswow64\hfnapi.dll','');
QuarantineFile('C:\Windows\system32\hfpapi.dll','');
QuarantineFile('C:\Windows\system32\hfnapi.dll','');
QuarantineFile('C:\PROGRA~3\Mozilla\mxmlhui.exe','');
QuarantineFile('C:\iexplore.bat','');
QuarantineFile('C:\Users\hg\AppData\Local\chrome.bat','');
QuarantineFile('C:\Program Files\Zaxar\ZaxarLoader.exe','');
QuarantineFile('C:\Program Files (x86)\Google\chrome.bat','');
QuarantineFile('C:\PROGRA~3\Mozilla\eofilrf.dll','');
QuarantineFile('C:\Windows\system32\drivers\{b9a19c25-a741-47e5-91a2-0b62bef307ff}w64.sys','');
QuarantineFile('c:\program files (x86)\skinpack\winaeroglass.exe','');
QuarantineFile('c:\users\hg\appdata\roaming\ssleas.exe','');
QuarantineFile('c:\programdata\iepluginservices\pluginservice.exe','');
QuarantineFile('c:\users\hg\appdata\roaming\x11\engine.exe','');
QuarantineFile('c:\programdata\windows\csrss.exe','');
QuarantineFile('c:\users\hg\appdata\roaming\cppredistx86.exe','');
DeleteFile('c:\users\hg\appdata\roaming\cppredistx86.exe','32');
DeleteFile('c:\users\hg\appdata\roaming\ssleas.exe','32');
DeleteFile('C:\Windows\system32\drivers\{b9a19c25-a741-47e5-91a2-0b62bef307ff}w64.sys','32');
DeleteFile('C:\ProgramData\IePluginServices\PluginService.exe','32');
DeleteFile('C:\Windows\system32\drivers\ssnfd.sys','32');
DeleteFile('C:\PROGRA~3\Mozilla\eofilrf.dll','32');
DeleteFile('C:\Program Files (x86)\Google\chrome.bat','32');
DeleteFile('C:\Program Files\Zaxar\ZaxarLoader.exe','32');
DeleteFile('C:\ProgramData\Windows\csrss.exe','32');
DeleteFile('C:\Users\hg\AppData\Local\chrome.bat','32');
DeleteFile('C:\iexplore.bat','32');
DeleteFile('C:\Windows\Tasks\PennyBee.job','64');
DeleteFile('C:\Windows\Tasks\UpdaterEX.job','64');
DeleteFile('C:\Windows\system32\Tasks\PennyBee','64');
DeleteFile('C:\Windows\system32\Tasks\UpdaterEX','64');
DeleteFile('C:\Windows\system32\Tasks\vkocpah','64');
DeleteFile('C:\PROGRA~3\Mozilla\mxmlhui.exe','32');
DeleteFile('C:\Windows\system32\Tasks\{C4002D27-9CD1-4A3D-BCA6-27D9B0FDD987}','64');
DeleteFile('C:\Windows\system32\hfnapi.dll','32');
DeleteFile('C:\Windows\system32\hfpapi.dll','32');
DeleteFile('C:\Windows\syswow64\hfnapi.dll','32');
DeleteFile('C:\Windows\syswow64\hfpapi.dll','32');
DeleteFile('C:\Windows\syswow64\winmonitor.exe','32');
DeleteFile('C:\Users\hg\appdata\roaming\closer.exe','32');
DeleteFile('C:\Users\hg\appdata\roaming\mediahit\shadow\mediahit.update\mediahit.update.process.exe','32');
DeleteFile('C:\Users\hg\appdata\roaming\x11\engine.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Client Server Runtime Subsystem');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Visual C++ 2010');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
DeleteService('ssnfd');
DeleteService('IePluginServices');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.