Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Program Files (x86)\DPower\uninstaller.exe','');
QuarantineFile('C:\ProgramData\wintools\WintoolUprI.exe','');
QuarantineFile('C:\Users\Влад\AppData\Roaming\S.T.A.L.K.E.R - Shadow of Chernobyl\Ctfhost\ctfhost.exe','');
QuarantineFile('C:\Program Files (x86)\Wuposmujopy\coimely.exe','');
QuarantineFile('C:\Program Files (x86)\Arerkhegertain Launcher\local64spl.dll','');
QuarantineFile('C:\Users\Влад\AppData\Roaming\WinSnare\WinSnare.dll','');
QuarantineFile('C:\ProgramData\Microsoft\IdentityCRL\ppcrlconf.dll','');
QuarantineFile('C:\Users\Влад\AppData\Roaming\SafeWeb\python\pythonw.exe','');
QuarantineFile('C:\Users\Влад\AppData\Roaming\SafeWeb\ml.py','');
QuarantineFile('C:\Users\Влад\AppData\Roaming\ForceUpdateVOF\ml.py','');
DeleteService('Windows');
QuarantineFile('C:\Windows\svchost.exe','');
QuarantineFile('C:\Program Files (x86)\amuleC2\ed2k.exe','');
SetServiceStart('ed2kidle', 4);
DeleteService('ed2kidle');
QuarantineFile('C:\Program Files (x86)\Inper\Application\chrome_child.dll','');
QuarantineFile('c:\programdata\winsapsvc\winsap.dll','');
QuarantineFile('c:\programdata\microsoft\identitycrl\ppcrlconf.dll','');
QuarantineFile('c:\program files (x86)\gubed\gubedzl.dll','');
QuarantineFile('c:\program files (x86)\winarcher\archer.dll','');
DeleteFile('c:\program files (x86)\winarcher\archer.dll','32');
DeleteFile('c:\program files (x86)\gubed\gubedzl.dll','32');
DeleteFile('c:\programdata\microsoft\identitycrl\ppcrlconf.dll','32');
DeleteFile('c:\programdata\winsapsvc\winsap.dll','32');
DeleteFile('C:\Program Files (x86)\amuleC2\ed2k.exe','32');
DeleteFile('C:\Windows\svchost.exe','32');
DeleteFile('C:\Users\Влад\AppData\Roaming\ForceUpdateVOF\ml.py','32');
DeleteFile('C:\Users\Влад\AppData\Roaming\SafeWeb\ml.py','32');
DeleteFile('C:\Users\Влад\AppData\Roaming\SafeWeb\python\pythonw.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','SafeWeb');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ForceUpdateVOF');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Archer\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\GubedZL\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\MSLN\Parameters','ServiceDll');
DeleteFile('C:\Users\Влад\AppData\Roaming\WinSnare\WinSnare.dll','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\WinSnare\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\pdycrzmegy','command');
DeleteFile('C:\Program Files (x86)\Arerkhegertain Launcher\local64spl.dll','32');
DeleteFile('C:\Windows\system32\Tasks\ForceUpdateVOF','64');
DeleteFile('C:\Windows\system32\Tasks\Facoent Schedule','64');
DeleteFile('C:\Program Files (x86)\Wuposmujopy\coimely.exe','32');
DeleteFile('C:\Windows\system32\Tasks\CTF Host','64');
DeleteFile('C:\Users\Влад\AppData\Roaming\S.T.A.L.K.E.R - Shadow of Chernobyl\Ctfhost\ctfhost.exe','32');
DeleteFile('C:\ProgramData\wintools\WintoolUprI.exe','32');
DeleteFile('C:\Windows\system32\Tasks\WinTOOL','64');
DeleteFile('C:\Windows\system32\Tasks\{5702C906-3A80-44CD-A8F5-0B66F355F6A3}','64');
DeleteFile('C:\Program Files (x86)\DPower\uninstaller.exe','32');
DeleteFile('C:\Windows\system32\Tasks\SafeWeb','64');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.