Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Documents and Settings\Admin\Application Data\METFM.exe','');
QuarantineFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-7.exe','');
QuarantineFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-6.exe','');
QuarantineFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-5.exe','');
QuarantineFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-4.exe','');
QuarantineFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-11.exe','');
QuarantineFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-10.exe','');
QuarantineFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-1-7.exe','');
QuarantineFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-1-6.exe','');
DelBHO('{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}');
QuarantineFile('C:\opera.bat','');
QuarantineFile('C:\IEXPLORE.bat','');
QuarantineFile('C:\Documents and Settings\All Users\Application Data\KRB Updater Utility\krbupdater-utility.exe','');
QuarantineFile('C:\Documents and Settings\Admin\Local Settings\Application Data\Yandex\browser.bat','');
QuarantineFile('C:\Documents and Settings\Admin\Local Settings\Application Data\4C4C4544-1426110791-5810-8044-C4C04F394E31\bnsyE0.exe','');
SetServiceStart('qrnfd_1_10_0_9', 4);
DeleteService('qrnfd_1_10_0_9');
QuarantineFile('C:\Program Files\UpdateService\UpdateService.exe','');
DeleteService('pumygydy');
SetServiceStart('qrsvc_1.10.0.9', 4);
DeleteService('qrsvc_1.10.0.9');
SetServiceStart('kogefeko', 4);
DeleteService('kogefeko');
SetServiceStart('IHProtect Service', 4);
DeleteService('IHProtect Service');
SetServiceStart('corozylo', 4);
DeleteService('corozylo');
QuarantineFile('C:\WINDOWS\system32\drivers\qrnfd_1_10_0_9.sys','');
QuarantineFile('C:\WINDOWS\system32\BDL.dll','');
QuarantineFile('C:\Program Files\XTab\SupTab.dll','');
QuarantineFile('C:\Program Files\XTab\IeWatchDog.dll','');
QuarantineFile('C:\Program Files\XTab\BrowerWatchFF.dll','');
QuarantineFile('C:\Program Files\XTab\BrowerWatchCH.dll','');
QuarantineFile('C:\Program Files\SavePass 1.1\b523dc61-a18d-472e-a61a-8a020a40e213.dll','');
QuarantineFile('C:\Documents and Settings\Admin\Local Settings\Application Data\SmartWeb\swhk.dll','');
TerminateProcessByName('c:\documents and settings\admin\local settings\application data\smartweb\smartwebhelper.exe');
QuarantineFile('c:\documents and settings\admin\local settings\application data\smartweb\smartwebhelper.exe','');
TerminateProcessByName('c:\documents and settings\admin\local settings\application data\smartweb\smartwebapp.exe');
QuarantineFile('c:\documents and settings\admin\local settings\application data\smartweb\smartwebapp.exe','');
TerminateProcessByName('c:\program files\quickref_1.10.0.9\service\qrsvc.exe');
QuarantineFile('c:\program files\quickref_1.10.0.9\service\qrsvc.exe','');
TerminateProcessByName('c:\program files\xtab\protectservice.exe');
QuarantineFile('c:\program files\xtab\protectservice.exe','');
TerminateProcessByName('c:\documents and settings\admin\application data\4c4c4544-1426085504-5810-8044-c4c04f394e31\nsz81.tmpfs');
QuarantineFile('c:\documents and settings\admin\application data\4c4c4544-1426085504-5810-8044-c4c04f394e31\nsz81.tmpfs','');
TerminateProcessByName('c:\documents and settings\admin\application data\4c4c4544-1426085504-5810-8044-c4c04f394e31\jnsh8d.tmp');
QuarantineFile('c:\documents and settings\admin\application data\4c4c4544-1426085504-5810-8044-c4c04f394e31\jnsh8d.tmp','');
TerminateProcessByName('c:\program files\xtab\hpnotify.exe');
QuarantineFile('c:\program files\xtab\hpnotify.exe','');
TerminateProcessByName('c:\program files\xtab\cmdshell.exe');
QuarantineFile('c:\program files\xtab\cmdshell.exe','');
TerminateProcessByName('c:\program files\savepass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-6.exe');
QuarantineFile('c:\program files\savepass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-6.exe','');
TerminateProcessByName('c:\program files\savepass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-10.exe');
QuarantineFile('c:\program files\savepass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-10.exe','');
TerminateProcessByName('c:\program files\savepass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-1-6.exe');
QuarantineFile('c:\program files\savepass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-1-6.exe','');
DeleteFile('c:\program files\savepass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-1-6.exe','32');
DeleteFile('c:\program files\savepass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-10.exe','32');
DeleteFile('c:\program files\savepass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-6.exe','32');
DeleteFile('c:\program files\xtab\cmdshell.exe','32');
DeleteFile('c:\program files\xtab\hpnotify.exe','32');
DeleteFile('c:\documents and settings\admin\application data\4c4c4544-1426085504-5810-8044-c4c04f394e31\jnsh8d.tmp','32');
DeleteFile('c:\documents and settings\admin\application data\4c4c4544-1426085504-5810-8044-c4c04f394e31\nsz81.tmpfs','32');
DeleteFile('c:\program files\xtab\protectservice.exe','32');
DeleteFile('c:\program files\quickref_1.10.0.9\service\qrsvc.exe','32');
DeleteFile('c:\documents and settings\admin\local settings\application data\smartweb\smartwebapp.exe','32');
DeleteFile('c:\documents and settings\admin\local settings\application data\smartweb\smartwebhelper.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Local Settings\Application Data\SmartWeb\swhk.dll','32');
DeleteFile('C:\Program Files\SavePass 1.1\b523dc61-a18d-472e-a61a-8a020a40e213.dll','32');
DeleteFile('C:\Program Files\XTab\BrowerWatchCH.dll','32');
DeleteFile('C:\Program Files\XTab\BrowerWatchFF.dll','32');
DeleteFile('C:\Program Files\XTab\IeWatchDog.dll','32');
DeleteFile('C:\Program Files\XTab\SupTab.dll','32');
DeleteFile('C:\WINDOWS\system32\drivers\qrnfd_1_10_0_9.sys','32');
DeleteFile('pumygydy.sys','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','SmartWeb');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','WinCheck');
DeleteFile('C:\Documents and Settings\Admin\Local Settings\Application Data\4C4C4544-1426110791-5810-8044-C4C04F394E31\bnsyE0.exe','32');
DeleteFile('C:\Documents and Settings\Admin\Local Settings\Application Data\Yandex\browser.bat','32');
DeleteFile('C:\Documents and Settings\All Users\Application Data\KRB Updater Utility\krbupdater-utility.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','KRB Updater Utility');
DeleteFile('C:\IEXPLORE.bat','32');
DeleteFile('C:\opera.bat','32');
DeleteFile('C:\WINDOWS\Tasks\7b206284-ae33-41d5-a060-fe3ab7cd5f12-1-6.job','32');
DeleteFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-1-6.exe','32');
DeleteFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-1-7.exe','32');
DeleteFile('C:\WINDOWS\Tasks\7b206284-ae33-41d5-a060-fe3ab7cd5f12-1-7.job','32');
DeleteFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-10.exe','32');
DeleteFile('C:\WINDOWS\Tasks\7b206284-ae33-41d5-a060-fe3ab7cd5f12-10_user.job','32');
DeleteFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-11.exe','32');
DeleteFile('C:\WINDOWS\Tasks\7b206284-ae33-41d5-a060-fe3ab7cd5f12-11.job','32');
DeleteFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-4.exe','32');
DeleteFile('C:\WINDOWS\Tasks\7b206284-ae33-41d5-a060-fe3ab7cd5f12-4.job','32');
DeleteFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-5.exe','32');
DeleteFile('C:\WINDOWS\Tasks\7b206284-ae33-41d5-a060-fe3ab7cd5f12-5.job','32');
DeleteFile('C:\WINDOWS\Tasks\7b206284-ae33-41d5-a060-fe3ab7cd5f12-6.job','32');
DeleteFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-6.exe','32');
DeleteFile('C:\Program Files\SavePass 1.1\7b206284-ae33-41d5-a060-fe3ab7cd5f12-7.exe','32');
DeleteFile('C:\WINDOWS\Tasks\7b206284-ae33-41d5-a060-fe3ab7cd5f12-7.job','32');
DeleteFile('C:\Program Files\AnyProtectEx\AnyProtect.exe','32');
DeleteFile('C:\WINDOWS\Tasks\APSnotifierPP1.job','32');
DeleteFile('C:\WINDOWS\Tasks\APSnotifierPP2.job','32');
DeleteFile('C:\WINDOWS\Tasks\APSnotifierPP3.job','32');
DeleteFile('C:\Documents and Settings\Admin\Application Data\METFM.exe','32');
DeleteFile('C:\WINDOWS\Tasks\METFM.job','32');
DeleteFile('C:\WINDOWS\Tasks\Soft installer.job','32');
DeleteFile('C:\Documents and Settings\Admin\Local Settings\Application Data\IObit installer\iobitdownloader_monster.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Компьютер перезагрузится.