Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Program Files (x86)\vEuomKaIU\ROrxDj.dll','');
QuarantineFileF('C:\Program Files (x86)\vEuomKaIU', '*.exe,*.dll,*.sys', false,'', 0, 0);
QuarantineFile('C:\Program Files (x86)\wunGYWhMeqNU2\yRFOgrVxZDRjX.dll','');
QuarantineFileF('C:\Program Files (x86)\wunGYWhMeqNU2', '*.exe,*.dll,*.sys', false,'', 0, 0);
QuarantineFile('C:\ProgramData\vAtgRIojrOIejiVB\UOkHfCV.wsf','');
QuarantineFileF('C:\ProgramData\vAtgRIojrOIejiVB', '*.exe,*.dll,*.sys', false,'', 0, 0);
QuarantineFile('C:\Users\FXtrt-new\AppData\Local\Temp\csrss\scheduled.exe','');
QuarantineFileF('C:\Users\FXtrt-new\AppData\Local\Temp\csrss', '*.exe,*.dll,*.sys', false,'', 0, 0);
QuarantineFile('C:\Users\FXtrt-new\AppData\Roaming\keycreator\kget.exe','');
QuarantineFile('C:\Windows\winmain64.exe','');
QuarantineFile('F:\DOWNLOADS\Key Remapper Reset Trial!!!!!!!!!!!!!!!!\Reset Trial for Key Remapper\tr.exe','');
QuarantineFile('C:\Program Files (x86)\JQNLggXpPPpITxfrDoR\WBSBids.dll','');
QuarantineFileF('C:\Program Files (x86)\JQNLggXpPPpITxfrDoR', '*.exe,*.dll,*.sys', false,'', 0, 0);
QuarantineFile('C:\Program Files (x86)\WNVwerPrGBZQC\pHEzLFa.dll','');
QuarantineFileF('C:\Program Files (x86)\WNVwerPrGBZQC', '*.exe,*.dll,*.sys', false,'', 0, 0);
QuarantineFile('C:\Program Files\Pursuit\Pursuit.exe','');
QuarantineFile('C:\ProgramData\indus\start.vbs','');
QuarantineFileF('C:\ProgramData\indus', '*.exe,*.dll,*.sys', false,'', 0, 0);
DeleteFile('C:\ProgramData\indus\start.vbs','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','rundll');
DeleteFile('C:\Program Files (x86)\WNVwerPrGBZQC\pHEzLFa.dll','32');
DeleteFile('C:\Program Files (x86)\JQNLggXpPPpITxfrDoR\WBSBids.dll','32');
DeleteFile('C:\Users\FXtrt-new\AppData\Local\Temp\csrss\scheduled.exe','32');
DeleteFile('C:\ProgramData\vAtgRIojrOIejiVB\UOkHfCV.wsf','32');
DeleteFile('C:\Program Files (x86)\wunGYWhMeqNU2\yRFOgrVxZDRjX.dll','32');
DeleteFile('C:\Program Files (x86)\vEuomKaIU\ROrxDj.dll','32');
ExecuteFile('schtasks.exe', '/delete /TN "eVSrriCnrZQlODxsGDB2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "gkNqfjNoNlLfJVmHB2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ScheduledUpdate" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "TzltYpotJgryG2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "xdbGJPONaKkXIL" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "yKMtMHoPoUUExsP2" /F', 0, 15000, true);
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
После выполнения скрипта компьютер перезагрузится.