Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Program Files (x86)\YDHJZflmU\YdzvoV.dll','');
QuarantineFile('C:\Program Files (x86)\OPVdSgDQkfYyIdXmgQR\pmCXoGv.dll','');
QuarantineFile('C:\Program Files (x86)\QglbfRTiMpmU2\mYjdtzxvuoSVm.dll','');
QuarantineFile('C:\ProgramData\WindowsMenu\westat.exe','');
QuarantineFile('C:\WINDOWS\Temp\JZkOEbITvPfCrZRe\xiOdmJrCO.exe','');
QuarantineFile('C:\WINDOWS\Temp\InlCpPnPctgOdniy\fUBLyIUkw.exe','');
QuarantineFile('C:\WINDOWS\Temp\hdQiFPwnpefEZdvr\cmkYKNotB.exe','');
QuarantineFile('C:\Program Files\UJMLXZ3ZAM\68T05Y9ZA.exe','');
QuarantineFile('C:\Program Files (x86)\fh4r3dg31uw\8ORZB.exe','');
QuarantineFile('C:\Program Files\C0ZEEG7OPI\C0ZEEG7OP.exe','');
QuarantineFile('C:\Program Files\MM968YM66U\MM968YM66.exe','');
QuarantineFile('C:\Program Files\FM3B8KEOQX\FM3B8KEOQ.exe','');
SetServiceStart('MzQ4MzM5', 4);
DeleteService('MzQ4MzM5');
SetServiceStart('ZTYzMzRkODkxMDMyZTM', 4);
DeleteService('ZTYzMzRkODkxMDMyZTM');
SetServiceStart('Yzg4MjQ1OThmN2ExN', 4);
DeleteService('Yzg4MjQ1OThmN2ExN');
QuarantineFile('C:\WINDOWS\system32\drivers\ZGM3ZWNhOTczMjZiNj.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\MzQ4MzM5.sys','');
QuarantineFile('C:\WINDOWS\roywreyyogkrkwqd.royw','');
TerminateProcessByName('c:\programdata\windowsmenu\westat.exe');
QuarantineFile('c:\programdata\windowsmenu\westat.exe','');
TerminateProcessByName('c:\programdata\roll\sets.exe');
QuarantineFile('c:\programdata\roll\sets.exe','');
TerminateProcessByName('c:\program files\yzg4mjq1othmn2exn\n2vjnmu2mdhi.exe');
QuarantineFile('c:\program files\yzg4mjq1othmn2exn\n2vjnmu2mdhi.exe','');
DeleteFile('c:\program files\yzg4mjq1othmn2exn\n2vjnmu2mdhi.exe','32');
DeleteFile('c:\programdata\roll\sets.exe','32');
DeleteFile('c:\programdata\windowsmenu\westat.exe','32');
DeleteFile('C:\ProgramData\Roll\chrome_elf.dll','32');
DeleteFile('C:\ProgramData\Roll\libcef.dll','32');
DeleteFile('C:\WINDOWS\roywreyyogkrkwqd.royw','32');
DeleteFile('C:\WINDOWS\system32\drivers\MzQ4MzM5.sys','32');
DeleteFile('C:\WINDOWS\system32\drivers\ZGM3ZWNhOTczMjZiNj.sys','32');
DeleteFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ZaxarLoader');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','IY2PIJFVHSYBP14');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','5MQST6V3W3E8D6C');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','DU1YMT8KWKG3TP7');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','A8HGACH5MYQACU3');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','MCOD7NZPVGUXVNX');
DeleteFile('C:\Program Files\FM3B8KEOQX\FM3B8KEOQ.exe','32');
DeleteFile('C:\Program Files\MM968YM66U\MM968YM66.exe','32');
DeleteFile('C:\Program Files (x86)\fh4r3dg31uw\8ORZB.exe','32');
DeleteFile('C:\Program Files\UJMLXZ3ZAM\68T05Y9ZA.exe','32');
DeleteFile('C:\WINDOWS\Tasks\bkuBvjeTrqgJvxDoNOq.job','32');
DeleteFile('C:\WINDOWS\Tasks\bkukNrMqksuzdVzTCPm.job','32');
DeleteFile('C:\WINDOWS\Temp\hdQiFPwnpefEZdvr\cmkYKNotB.exe','32');
DeleteFile('C:\WINDOWS\Temp\InlCpPnPctgOdniy\fUBLyIUkw.exe','32');
DeleteFile('C:\WINDOWS\Temp\JZkOEbITvPfCrZRe\xiOdmJrCO.exe','32');
DeleteFile('C:\WINDOWS\Tasks\bkuMCNKBJXHSmaLnRJi.job','32');
DeleteFile('C:\WINDOWS\system32\Tasks\bkuMCNKBJXHSmaLnRJi','64');
DeleteFile('C:\WINDOWS\system32\Tasks\bkukNrMqksuzdVzTCPm','64');
DeleteFile('C:\WINDOWS\system32\Tasks\bkuBvjeTrqgJvxDoNOq','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\QuickLaunch','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\SSetings','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\BrUpdateCheckRun','64');
DeleteFile('C:\ProgramData\WindowsMenu\westat.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\NetTrace\TaskBrowser','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\NetTrace\TaskBrowser2','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\Shell\BrUpdateCheckRun','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\SideShow\APIPlayBrowser','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\SMB\UninstallSMB1ClientTask','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\SMB\UninstallSMB1ServerTask','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\Starter','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\SyncCenter\Browser','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\SyncCenter\Browser2','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\SyncCenter\OwnMic','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Microsoft\Windows\UPnP\TaskBarBrowser','64');
DeleteFile('C:\Program Files (x86)\QglbfRTiMpmU2\mYjdtzxvuoSVm.dll','32');
DeleteFile('C:\Program Files (x86)\OPVdSgDQkfYyIdXmgQR\pmCXoGv.dll','32');
DeleteFile('C:\Program Files (x86)\YDHJZflmU\YdzvoV.dll','32');
DeleteFile('C:\WINDOWS\system32\Tasks\yZiHCnIRlRiAMEG2','64');
DeleteFile('C:\WINDOWS\system32\Tasks\QmyrtYWFCGtDVzEvQ2','64');
DeleteFile('C:\WINDOWS\system32\Tasks\oZClSlEiAtCirp','64');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.