Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Windows\system32\wsaudio.dll','');
QuarantineFile('C:\Users\User\appdata\roaming\system\libs\svchost.exe','');
QuarantineFile('C:\Program Files (x86)\Common Files\Distribute Application\appdistrib.exe','');
QuarantineFile('C:\Users\User\AppData\Local\SmartWeb\SmartWebHelper.exe','');
QuarantineFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe','');
QuarantineFile('C:\Users\User\AppData\Local\Microsoft\Windows\toolbar.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\phbgijefmoangblimiifmafocmlfaobk\python\pythonw.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\phbgijefmoangblimiifmafocmlfaobk\ml.py','');
QuarantineFile('C:\Users\User\AppData\Local\Kometa\kometaup.exe','');
QuarantineFile('C:\Users\User\AppData\Local\Kometa\Panel\KometaLaunchPanel.exe','');
QuarantineFile('C:\Users\User\AppData\Local\Kometa\Application\kometa.exe','');
QuarantineFile('C:\Program Files (x86)\gmsd_ru_005010030\gmsd_ru_005010030.exe','');
QuarantineFile('C:\Program Files (x86)\gmsd_ru_005010031\gmsd_ru_005010031.exe','');
QuarantineFile('C:\Program Files (x86)\gmsd_ru_005010032\gmsd_ru_005010032.exe','');
QuarantineFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\cpuminer\sgminer\sgminer.cmd','');
QuarantineFile('C:\Windows\system32\cpuminer-gw64.exe','');
QuarantineFile('C:\Program Files (x86)\Baidu\BaiduAn\4.0.0.5166\baiduAnTray.exe','');
QuarantineFile('C:\Users\User\AppData\Local\Temp\11-20150313-154741.exe','');
QuarantineFile('C:\Users\User\AppData\Local\Microsoft\Extensions\safebrowser.exe','');
DeleteFile('C:\Users\User\AppData\Local\Microsoft\Extensions\safebrowser.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','SafeBrowser');
DeleteFile('C:\Users\User\AppData\Local\Temp\11-20150313-154741.exe','32');
DeleteFile('C:\Users\User\AppData\Local\Amigo\Application\amigo.exe','32');
DeleteFile('C:\Program Files (x86)\Baidu\BaiduAn\4.0.0.5166\baiduAnTray.exe','32');
DeleteFile('C:\Windows\system32\cpuminer-gw64.exe','32');
DeleteFile('C:\Users\User\AppData\Roaming\cpuminer\sgminer\sgminer.cmd','32');
DeleteFile('C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe','32');
DeleteFile('C:\Program Files (x86)\gmsd_ru_005010032\gmsd_ru_005010032.exe','32');
DeleteFile('C:\Program Files (x86)\gmsd_ru_005010031\gmsd_ru_005010031.exe','32');
DeleteFile('C:\Program Files (x86)\gmsd_ru_005010030\gmsd_ru_005010030.exe','32');
DeleteFile('C:\Users\User\AppData\Local\Kometa\Application\kometa.exe','32');
DeleteFile('C:\Users\User\AppData\Local\Kometa\Panel\KometaLaunchPanel.exe','32');
DeleteFile('C:\Users\User\AppData\Local\Kometa\kometaup.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\kometaup','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KometaLaunchPanel','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KometaAutoLaunch_6632489EDE512831E64C7AB45B89EBC1','command');
DeleteFile('C:\Users\User\AppData\Local\Mail.ru\Sputnik\ptls\LWPYCvofsemE.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LWPYCvofsemE','command');
DeleteFile('C:\Users\User\AppData\Roaming\phbgijefmoangblimiifmafocmlfaobk\ml.py','32');
DeleteFile('C:\Users\User\AppData\Roaming\phbgijefmoangblimiifmafocmlfaobk\python\pythonw.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\phbgijefmoangblimiifmafocmlfaobk','command');
DeleteFile('C:\Users\User\AppData\Local\Microsoft\Windows\toolbar.exe','32');
DeleteFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe','32');
DeleteFile('C:\Users\User\AppData\Local\SmartWeb\SmartWebHelper.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SmartWeb','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SpaceSoundPro','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SystemScript','command');
DeleteFile('C:\Windows\system32\Tasks\appdistrib','64');
DeleteFile('C:\Program Files (x86)\Common Files\Distribute Application\appdistrib.exe','32');
DeleteFile('C:\Windows\system32\Tasks\phbgijefmoangblimiifmafocmlfaobk','64');
DeleteFile('C:\Users\User\appdata\roaming\system\libs\svchost.exe','32');
DeleteFile('C:\Windows\system32\wsaudio.dll','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.