Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\ProgramData\Voyasollam\Toughron.dll','');
QuarantineFile('C:\ProgramData\Voyasollam\Ron-Phase.dll','');
QuarantineFile('C:\Users\User\AppData\Roaming\2sjvegpqk32\b3sirwf120f.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\etmbe0csdkc\p22shdbjytj.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\thwl5pnpncj\jf0iow1rmfk.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\v132jxnaned\mutvcld3okq.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\jmnfuqhrihb\etq3yfeb0ew.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\npfiakniwkr\ty5t0h4jsmc.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\xclq2fd4fjx\2qgl3ycuyy1.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\tj5jydnwxyq\ka34y5obh1p.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\we3kxloo2dw\4ra0fx0hhrc.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\ssbvvlemzrq\bhcjerretbb.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\22oigyvjbtc\lxp1ulpj0kw.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\ljrauelqlmn\aocefcuof4a.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\IeServ\IeServ.vbs','');
DeleteFile('C:\Users\User\AppData\Roaming\IeServ\IeServ.vbs','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','IeServ.vbs');
DeleteFile('C:\Users\User\AppData\Roaming\ljrauelqlmn\aocefcuof4a.exe','32');
DeleteFile('C:\Users\User\AppData\Roaming\22oigyvjbtc\lxp1ulpj0kw.exe','32');
DeleteFile('C:\Users\User\AppData\Roaming\ssbvvlemzrq\bhcjerretbb.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','5z24ldw1md2');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','eb3bsofts5m');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','0gnwz1jbjab');
DeleteFile('C:\Users\User\AppData\Roaming\we3kxloo2dw\4ra0fx0hhrc.exe','32');
DeleteFile('C:\Users\User\AppData\Roaming\tj5jydnwxyq\ka34y5obh1p.exe','32');
DeleteFile('C:\Users\User\AppData\Roaming\xclq2fd4fjx\2qgl3ycuyy1.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','lxxytptx5xu');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','vr4acb0ooxy');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','nd2b32g5mm5');
DeleteFile('C:\Users\User\AppData\Roaming\npfiakniwkr\ty5t0h4jsmc.exe','32');
DeleteFile('C:\Users\User\AppData\Roaming\jmnfuqhrihb\etq3yfeb0ew.exe','32');
DeleteFile('C:\Users\User\AppData\Roaming\v132jxnaned\mutvcld3okq.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','hqhztlt1myb');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','r1xvtm41ing');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','2pelfev5gap');
DeleteFile('C:\Users\User\AppData\Roaming\thwl5pnpncj\jf0iow1rmfk.exe','32');
DeleteFile('C:\Users\User\AppData\Roaming\etmbe0csdkc\p22shdbjytj.exe','32');
DeleteFile('C:\Users\User\AppData\Roaming\2sjvegpqk32\b3sirwf120f.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','lhut2s2j0w1');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','mrkoijw1413');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','135jomfp1ww');
DeleteFile('C:\ProgramData\Voyasollam\Ron-Phase.dll','32');
DeleteFile('C:\ProgramData\Voyasollam\Toughron.dll','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Будет выполнена перезагрузка компьютера.