Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Users\stepa\appdata\local\temp\csrss\scheduled.exe','');
QuarantineFile('C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe','');
QuarantineFile('C:\Users\stepa\AppData\Local\App\svchost.exe','');
TerminateProcessByName('c:\users\stepa\appdata\local\app\svchost.exe');
QuarantineFile('c:\users\stepa\appdata\local\app\svchost.exe','');
DeleteFile('c:\users\stepa\appdata\local\app\svchost.exe','32');
DeleteFile('C:\Users\stepa\AppData\Local\App\svchost.exe','32');
DeleteFile('C:\Program Files (x86)\Zaxar\ZaxarLoader.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ZaxarLoader');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','App');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Web Companion');
DeleteFile('C:\Users\stepa\AppData\Roaming\g2wzxn0hbpg\chwreyalvze.exe','32');
DeleteFile('C:\Users\stepa\AppData\Local\Temp\is-CTUPT.tmp\Gaultron.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','6467882');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','2362819');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','2VG2VYMZEQ9LHEL');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','7916131');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','9872794');
DeleteFile('C:\Users\stepa\AppData\Roaming\e4t5s4c3h4w\ht5gektm1af.exe','32');
DeleteFile('C:\Program Files\QZRQ7DFO36\QZRQ7DFO3.exe','32');
DeleteFile('C:\Users\stepa\AppData\Roaming\0wxhxgn5kzp\3rfh0osjukt.exe','32');
DeleteFile('C:\Users\stepa\AppData\Local\Temp\is-NPUGV.tmp\Gaultron.exe','32');
DeleteFile('C:\Program Files\U20MV17GJR\U20MV17GJ.exe','32');
DeleteFile('C:\Program Files\CA0FFVSCLH\CA0FFVSCL.exe','32');
DeleteFile('C:\Program Files\XM3DK04594\XM3DK0459.exe','32');
DeleteFile('C:\Users\stepa\AppData\Roaming\oy2zgpycy4g\b1rpbap32l5.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','5591156');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','ETTMFA9XMTE7H8Z');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','RJOGCL3LV9MIQS0');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','4620737');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','6MAUQRV3UDOEDNW');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls','QuickTime');
DeleteFile('C:\WINDOWS\system32\Tasks\csrss','64');
DeleteFile('C:\WINDOWS\system32\Tasks\lsa64','64');
DeleteFile('C:\Users\stepa\AppData\Local\Temp\csrss\lsa64install.exe','32');
DeleteFile('C:\Windows\rss\csrss.exe','32');
DeleteFile('C:\Users\stepa\appdata\local\temp\csrss\scheduled.exe','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.