Код:
begin
ExecuteAVUpdate;
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;;
TerminateProcessByName('c:\program files\common files\baidu\baiduprotect1.3\1.3.0.622\baiduprotect.exe');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsa1136.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knse95c.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsef1b.tmp');
TerminateProcessByName('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsf1029.tmp');
TerminateProcessByName('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsf423.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsifad.tmp');
TerminateProcessByName('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsj1310.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsk17b2.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knskc22.tmp');
TerminateProcessByName('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knslb43.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsm106e.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsm8f1.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsn1158.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsn14af.tmp');
TerminateProcessByName('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsn4f2.tmp');
TerminateProcessByName('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsne10.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsod70.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsq121c.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsq1b2f.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsr1b5d.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knss17a4.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knst176a.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsu591.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsu80f.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsu925.tmp');
TerminateProcessByName('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsv1fe.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsvde6.tmp');
TerminateProcessByName('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsvf2a.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsw8ab.tmp');
TerminateProcessByName('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knswac6.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsx115d.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsxa92.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsy1398.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knsz44b.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knszbd9.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knszc79.tmp');
TerminateProcessByName('c:\program files\03000200-1436257299-0500-0006-000700080009\knszeb9.tmp');
StopService('bd0001');
StopService('bd0002');
StopService('bd0004');
StopService('BDArKit');
StopService('BDMWrench');
StopService('BDSGRTP');
StopService('bewuvori');
StopService('byhededo');
StopService('cewywosi');
StopService('dulynipy');
StopService('furyzyhu');
StopService('fydujusu');
StopService('fylinufo');
StopService('guxexufe');
StopService('guxibixe');
StopService('hemogety');
StopService('hyreguzu');
StopService('jofoxihy');
StopService('jugyzeco');
StopService('kydudero');
StopService('lenyboje');
StopService('mygurudu');
StopService('nisytesi');
StopService('pebocimi');
StopService('pimetemo');
StopService('qicojezu');
StopService('qitibosi');
StopService('quqepyre');
StopService('qutefyfy');
StopService('rymyvicu');
StopService('ryvodyfy');
StopService('silysopo');
StopService('sujegiho');
StopService('vivunume');
StopService('wepysigy');
StopService('wyredodo');
StopService('wyricexe');
StopService('xelinudy');
StopService('xofeceje');
StopService('xuhujiti');
StopService('zecywute');
StopService('zewibyjo');
QuarantineFile('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsf1029.tmp','');
QuarantineFile('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsf423.tmp','');
QuarantineFile('C:\Documents and Settings\Андрей\Application Data\03000200-1436257299-0500-0006-000700080009\knsj1310.tmp','');
QuarantineFile('C:\Documents and Settings\Андрей\Application Data\03000200-1436257299-0500-0006-000700080009\knslB43.tmp','');
QuarantineFile('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsn4f2.tmp','');
QuarantineFile('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsne10.tmp','');
QuarantineFile('C:\Documents and Settings\Андрей\Application Data\03000200-1436257299-0500-0006-000700080009\knsv1FE.tmp','');
QuarantineFile('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsvf2a.tmp','');
QuarantineFile('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knswac6.tmp','');
QuarantineFile('C:\DOCUME~1\86A9~1\LOCALS~1\Temp\qvrdia.exe','');
QuarantineFile('C:\DOCUME~1\86A9~1\LOCALS~1\Temp\xxysza.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsa1136.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knse95c.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsef1b.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsifad.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsk17b2.tmp','');
QuarantineFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knskC22.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsm106e.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsm8f1.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsn1158.tmp','');
QuarantineFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsn14AF.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsod70.tmp','');
QuarantineFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsq121C.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsq1b2f.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsr1b5d.tmp','');
QuarantineFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knss17A4.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knst176a.tmp','');
QuarantineFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsu591.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsu80f.tmp','');
QuarantineFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsu925.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsvde6.tmp','');
QuarantineFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsw8AB.tmp','');
QuarantineFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsx115D.tmp','');
QuarantineFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsxA92.tmp','');
QuarantineFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsy1398.tmp','');
QuarantineFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsz44B.tmp','');
QuarantineFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knszBD9.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knszc79.tmp','');
QuarantineFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knszeb9.tmp','');
QuarantineFile('C:\Program Files\CommFort\CommFort.exe','');
QuarantineFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\ad.dll','');
QuarantineFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\BaiduProtect.exe','');
QuarantineFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\BDKitUtils.dll','');
QuarantineFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\BDLogicUtils.dll','');
QuarantineFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\BDMNet.dll','');
QuarantineFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\BDMReport.dll','');
QuarantineFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\bdsg0001.dll','');
QuarantineFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\DriverManager.dll','');
QuarantineFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\plugins\BaiduRepair.dll','');
QuarantineFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\plugins\HIPS.dll','');
QuarantineFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\SafeBrowserDll.dll','');
QuarantineFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\SafeExplorer.dll','');
QuarantineFile('C:\Program Files\Zaxar\ZaxarGameBrowser.exe','');
QuarantineFile('C:\Program Files\Zaxar\ZaxarLoader.exe','');
QuarantineFile('C:\ProgramData\TimeTasks\timetasks.exe','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\bd0001.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\bd0002.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\bd0004.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\BDArKit.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\BDMWrench.sys','');
QuarantineFile('C:\winlogonss\winlogons\MS.exe','');
DeleteFile('C:\Documents and Settings\Андрей\Application Data\03000200-1436257299-0500-0006-000700080009\knsf1029.tmp','32');
DeleteFile('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsf423.tmp','32');
DeleteFile('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsj1310.tmp','32');
DeleteFile('C:\Documents and Settings\Андрей\Application Data\03000200-1436257299-0500-0006-000700080009\knslB43.tmp','32');
DeleteFile('C:\Documents and Settings\Андрей\Application Data\03000200-1436257299-0500-0006-000700080009\knsn4F2.tmp','32');
DeleteFile('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsne10.tmp','32');
DeleteFile('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsv1fe.tmp','32');
DeleteFile('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knsvf2a.tmp','32');
DeleteFile('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009\knswac6.tmp','32');
DeleteFile('C:\DOCUME~1\86A9~1\LOCALS~1\Temp\qvrdia.exe','32');
DeleteFile('C:\DOCUME~1\86A9~1\LOCALS~1\Temp\xxysza.tmp','32');
DeleteFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsa1136.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knse95C.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knseF1B.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsiFAD.tmp','32');
DeleteFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsk17b2.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knskC22.tmp','32');
DeleteFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsm106e.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsm8F1.tmp','32');
DeleteFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsn1158.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsn14AF.tmp','32');
DeleteFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsod70.tmp','32');
DeleteFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsq121c.tmp','32');
DeleteFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsq1b2f.tmp','32');
DeleteFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsr1b5d.tmp','32');
DeleteFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knss17a4.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knst176A.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsu591.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsu80F.tmp','32');
DeleteFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsu925.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsvDE6.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsw8AB.tmp','32');
DeleteFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsx115d.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsxA92.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knsy1398.tmp','32');
DeleteFile('c:\program files\03000200-1436257299-0500-0006-000700080009\knsz44b.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knszBD9.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knszC79.tmp','32');
DeleteFile('C:\Program Files\03000200-1436257299-0500-0006-000700080009\knszEB9.tmp','32');
DeleteFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\ad.dll','32');
DeleteFile('c:\program files\common files\baidu\baiduprotect1.3\1.3.0.622\baiduprotect.exe','32');
DeleteFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\BDKitUtils.dll','32');
DeleteFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\BDLogicUtils.dll','32');
DeleteFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\BDMNet.dll','32');
DeleteFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\BDMReport.dll','32');
DeleteFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\bdsg0001.dll','32');
DeleteFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\DriverManager.dll','32');
DeleteFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\plugins\BaiduRepair.dll','32');
DeleteFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\plugins\HIPS.dll','32');
DeleteFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\SafeBrowserDll.dll','32');
DeleteFile('C:\Program Files\Common Files\Baidu\BaiduProtect1.3\1.3.0.622\SafeExplorer.dll','32');
DeleteFile('C:\Program Files\Zaxar\ZaxarGameBrowser.exe','32');
DeleteFile('C:\Program Files\Zaxar\ZaxarLoader.exe','32');
DeleteFile('C:\ProgramData\TimeTasks\timetasks.exe','32');
DeleteFileMask('C:\ProgramData\TimeTasks', '*', true, ' ');
DeleteDirectory('C:\ProgramData\TimeTasks');
DeleteFileMask('C:\Program Files\Zaxar', '*', true, ' ');
DeleteDirectory('C:\Program Files\Zaxar');
DeleteFileMask('C:\Program Files\Common Files\Baidu', '*', true, ' ');
DeleteDirectory('C:\Program Files\Common Files\Baidu');
DeleteFileMask('C:\Program Files\03000200-1436257299-0500-0006-000700080009', '*', true, ' ');
DeleteDirectory('C:\Program Files\03000200-1436257299-0500-0006-000700080009');
DeleteFileMask('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009', '*', true, ' ');
DeleteDirectory('c:\documents and settings\Андрей\application data\03000200-1436257299-0500-0006-000700080009');
DeleteFile('C:\WINDOWS\system32\DRIVERS\bd0001.sys','32');
DeleteFile('C:\WINDOWS\system32\DRIVERS\bd0002.sys','32');
DeleteFile('C:\WINDOWS\system32\DRIVERS\bd0004.sys','32');
DeleteFile('C:\WINDOWS\system32\DRIVERS\BDArKit.sys','32');
DeleteFile('C:\WINDOWS\system32\DRIVERS\BDMWrench.sys','32');
DeleteFile('C:\WINDOWS\Tasks\SysScan.job','32');
DeleteFile('C:\winlogonss\winlogons\MS.exe','32');
DeleteService('bd0001');
DeleteService('bd0002');
DeleteService('bd0004');
DeleteService('BDArKit');
DeleteService('BDMWrench');
DeleteService('BDSGRTP');
DeleteService('bewuvori');
DeleteService('byhededo');
DeleteService('cewywosi');
DeleteService('dulynipy');
DeleteService('furyzyhu');
DeleteService('fydujusu');
DeleteService('fylinufo');
DeleteService('guxexufe');
DeleteService('guxibixe');
DeleteService('hemogety');
DeleteService('hyreguzu');
DeleteService('jofoxihy');
DeleteService('jugyzeco');
DeleteService('kydudero');
DeleteService('lenyboje');
DeleteService('mygurudu');
DeleteService('nisytesi');
DeleteService('pebocimi');
DeleteService('pimetemo');
DeleteService('qicojezu');
DeleteService('qitibosi');
DeleteService('quqepyre');
DeleteService('qutefyfy');
DeleteService('rymyvicu');
DeleteService('ryvodyfy');
DeleteService('silysopo');
DeleteService('sujegiho');
DeleteService('vivunume');
DeleteService('wepysigy');
DeleteService('wyredodo');
DeleteService('wyricexe');
DeleteService('xelinudy');
DeleteService('xofeceje');
DeleteService('xuhujiti');
DeleteService('zecywute');
DeleteService('zewibyjo');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Mozilla','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Timestasks');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ZaxarGameBrowser');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ZaxarLoader');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
После выполнения скрипта компьютер перезагрузится.