Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Program Files\DealPly\DealPlyUpdate.exe','');
QuarantineFile('C:\DOCUME~1\9335~1\APPLIC~1\DSite\UPDATE~1\UPDATE~1.EXE','');
DelBHO('{FB4F6285-4C32-49F2-950F-A5998F9CEC6C}');
DelBHO('{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}');
QuarantineFile('C:\Program Files\Baidu\BaiduSd\3.0.0.4605\websafe\WebMonBHO.dll','');
DelBHO('{15DEE173-1BE9-4424-81E0-58A87076E9B1}');
QuarantineFile('C:\Program Files\IQIYI Video\Common\Accelerator\IEHelper.dll','');
QuarantineFile('C:\Documents and Settings\Администратор\Local Settings\Application Data\Microsoft\Internet Explorer\Extensions\APIHelper.dll','');
QuarantineFile('C:\windows\System32\wlanmgr.dll','');
QuarantineFile('C:\windows\System32\ir16_32.dll','');
QuarantineFile('C:\windows\System32\d3dadapter.dll','');
QuarantineFile('C:\windows\System32\KBDMAI.dll','');
QuarantineFile('C:\launcher.bat','');
QuarantineFile('C:\iexplore.bat','');
QuarantineFile('C:\firefox.bat','');
QuarantineFile('C:\Documents and Settings\Администратор\Local Settings\Application Data\Microsoft\Windows\toolbar.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\Installer\url4.exe','');
QuarantineFile('C:\Documents and Settings\Администратор\Application Data\Browsers\exe.xoferif.bat','');
DeleteService('KDHacker');
DeleteService('kisnetm');
DeleteService('ksapi');
DeleteService('bd0002');
DeleteService('bd0001');
SetServiceStart('minidoke', 4);
DeleteService('minidoke');
QuarantineFile('C:\Program Files\IGS\BasementDuster.exe','');
QuarantineFile('C:\Program Files\XTab\ProtectService.exe','');
DeleteService('kxescore');
DeleteService('IHProtect Service');
DeleteService('BDMRTP');
DeleteService('BDKVRTP');
DeleteService('BasementDuster');
TerminateProcessByName('c:\documents and settings\Администратор\application data\03000200-1426304853-0500-0006-000700080009\jnsu6f.tmp');
QuarantineFile('c:\documents and settings\Администратор\application data\03000200-1426304853-0500-0006-000700080009\jnsu6f.tmp','');
TerminateProcessByName('c:\documents and settings\all users\application data\windows\csrss.exe');
QuarantineFile('c:\documents and settings\all users\application data\windows\csrss.exe','');
DeleteFile('c:\documents and settings\all users\application data\windows\csrss.exe','32');
DeleteFile('c:\documents and settings\Администратор\application data\03000200-1426304853-0500-0006-000700080009\jnsu6f.tmp','32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kxescore.exe','32');
DeleteFile('C:\Program Files\XTab\ProtectService.exe','32');
DeleteFile('C:\Program Files\Baidu\BaiduAn\2.3.0.2225\BaiduAnSvc.exe','32');
DeleteFile('C:\Program Files\Baidu\BaiduSd\3.0.0.4605\BaiduSdSvc.exe','32');
DeleteFile('C:\Program Files\IGS\BasementDuster.exe','32');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\03000200-1426304853-0500-0006-000700080009\jnsu6F.tmp','32');
DeleteFile('C:\windows\system32\DRIVERS\bd0001.sys','32');
DeleteFile('C:\windows\system32\DRIVERS\bd0002.sys','32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kdhacker.sys','32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\ksnetm\kisnetmxp.sys','32');
DeleteFile('C:\WINDOWS\system32\drivers\ksapi.sys','32');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\Browsers\exe.xoferif.bat','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Client Server Runtime Subsystem');
DeleteFile('C:\Documents and Settings\Администратор\Application Data\Installer\url4.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\url4.exe','command');
DeleteFile('C:\Documents and Settings\Администратор\Local Settings\Application Data\Microsoft\Windows\toolbar.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SystemScript','command');
DeleteFile('C:\Program Files\Baidu\BaiduSd\3.0.0.4605\BaiduSdTray.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','BaiduSdTray');
DeleteFile('C:\firefox.bat','32');
DeleteFile('C:\iexplore.bat','32');
DeleteFile('C:\launcher.bat','32');
DeleteFile('C:\windows\System32\d3dadapter.dll','32');
DeleteFile('C:\windows\System32\KBDMAI.dll','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\kbdmai\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\d3dadapter\Parameters','ServiceDll');
DeleteFile('C:\windows\System32\ir16_32.dll','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\ir16_32\Parameters','ServiceDll');
DeleteFile('C:\windows\System32\wlanmgr.dll','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\wlanmgr\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','kxesc');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kxetray.exe','32');
DeleteFile('C:\Documents and Settings\Администратор\Local Settings\Application Data\Microsoft\Internet Explorer\Extensions\APIHelper.dll','32');
DeleteFile('C:\Program Files\IQIYI Video\Common\Accelerator\IEHelper.dll','32');
DeleteFile('C:\Program Files\Baidu\BaiduSd\3.0.0.4605\websafe\WebMonBHO.dll','32');
DeleteFile('C:\Program Files\AnyProtectEx\AnyProtect.exe','32');
DeleteFile('C:\windows\Tasks\APSnotifierPP1.job','32');
DeleteFile('C:\windows\Tasks\APSnotifierPP2.job','32');
DeleteFile('C:\windows\Tasks\APSnotifierPP3.job','32');
DeleteFile('C:\windows\Tasks\At1.job','32');
DeleteFile('C:\windows\Tasks\DealPlyUpdate.job','32');
DeleteFile('C:\DOCUME~1\9335~1\APPLIC~1\DSite\UPDATE~1\UPDATE~1.EXE','32');
DeleteFile('C:\Program Files\DealPly\DealPlyUpdate.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Компьютер перезагрузится.