Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Program Files (x86)\jzVqtpDsXbLU2\jeMSUONncuyjE.dll','');
QuarantineFile('C:\Program Files\POP3\POP3.dll','');
QuarantineFile('C:\Program Files\System Native\Main Services\restart.cmd','');
QuarantineFile('C:\ProgramData\0fe73cc6278241be9de79c81e8346ad3\HandlerExecution.exe','');
QuarantineFile('C:\Program Files (x86)\LfFoujfjU\eSOnuj.dll','');
DelBHO('{C0D38E5A-7CF8-4105-8FE8-31B81443A114}');
DelBHO('{8E8F97CD-60B5-456F-A201-73065652D099}');
QuarantineFile('C:\Program Files (x86)\JwYYyjKjrIE\kiYZ6gU.dll','');
QuarantineFile('C:\Users\Валера\AppData\Roaming\aajkqj4ume3\y0joaabmbgc.exe','');
QuarantineFile('C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe','');
DeleteService('updater');
DeleteService('sys32_udp_dll');
SetServiceStart('svchost64', 4);
DeleteService('svchost64');
QuarantineFile('C:\Program Files\System Native\Main Services\winreg64.exe','');
QuarantineFile('C:\Program Files\System Native\Main Services\updater.exe','');
QuarantineFile('C:\ProgramData\ee20b06aa4\84cf867318.exe','');
TerminateProcessByName('C:\Windows\Temp\xmrig.exe');
QuarantineFile('C:\Windows\Temp\xmrig.exe','');
TerminateProcessByName('C:\Windows\Temp\g9C90.tmp.exe');
QuarantineFile('C:\Windows\Temp\g9C90.tmp.exe','');
DeleteFile('C:\Windows\Temp\g9C90.tmp.exe','32');
DeleteFile('C:\Windows\Temp\xmrig.exe','32');
DeleteFile('C:\ProgramData\ee20b06aa4\84cf867318.exe','32');
DeleteFile('C:\Program Files\System Native\Main Services\winreg64.exe','32');
DeleteFile('C:\Program Files\System Native\Main Services\updater.exe','32');
DeleteFile('C:\Users\Валера\AppData\Roaming\aajkqj4ume3\y0joaabmbgc.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','5019255');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','amigo');
DeleteFile('C:\Users\Валера\AppData\Local\Amigo\Application\amigo.exe','32');
DeleteFile('C:\Program Files (x86)\JwYYyjKjrIE\kiYZ6gU.dll','32');
DeleteFile('C:\WINDOWS\Tasks\Online Application V2G1.job','32');
DeleteFile('C:\WINDOWS\Tasks\Online Application V2G2.job','32');
DeleteFile('C:\WINDOWS\Tasks\Online Application V2G3.job','32');
DeleteFile('C:\WINDOWS\Tasks\Online Application V2G5.job','32');
DeleteFile('C:\WINDOWS\Tasks\Online Application V2G4.job','32');
DeleteFile('C:\WINDOWS\Tasks\Online Application V2G6.job','32');
DeleteFile('C:\WINDOWS\Tasks\Updater_Online_Application.job','32');
DeleteFile('C:\WINDOWS\system32\Tasks\dTRRfHQjsHOvbdt2','64');
DeleteFile('C:\Program Files (x86)\LfFoujfjU\eSOnuj.dll','32');
DeleteFile('C:\WINDOWS\system32\Tasks\GoogleUpdateSecurityTaskMachine_FN','64');
DeleteFile('C:\WINDOWS\system32\Tasks\GoogleUpdateSecurityTaskMachine_HB','64');
DeleteFile('C:\WINDOWS\system32\Tasks\GoogleUpdateSecurityTaskMachine_NO','64');
DeleteFile('C:\WINDOWS\system32\Tasks\GoogleUpdateSecurityTaskMachine_XQ','64');
DeleteFile('C:\ProgramData\0fe73cc6278241be9de79c81e8346ad3\HandlerExecution.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\GoogleUpdateSecurityTaskMachine_YL','64');
DeleteFile('C:\WINDOWS\system32\Tasks\MailRuUpdater','64');
DeleteFile('C:\WINDOWS\system32\Tasks\OneSystemCare Task','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Online Application V2G1','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Online Application V2G2','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Online Application V2G3','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Online Application V2G4','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Online Application V2G5','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Online Application V2G6','64');
DeleteFile('C:\WINDOWS\system32\Tasks\operation','64');
DeleteFile('C:\Program Files\System Native\Main Services\restart.cmd','32');
DeleteFile('C:\WINDOWS\system32\Tasks\POP3','64');
DeleteFile('C:\Program Files\POP3\POP3.dll','32');
DeleteFile('C:\Program Files (x86)\jzVqtpDsXbLU2\jeMSUONncuyjE.dll','32');
DeleteFile('C:\WINDOWS\system32\Tasks\SystemHealer Task','64');
DeleteFile('C:\WINDOWS\system32\Tasks\qFbxfDUevnccZZ','64');
DeleteFile('C:\WINDOWS\system32\Tasks\updater','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Updater_Online_Application','64');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.