Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
DeleteFile(GetAVZDirectory+'log\virusinfo_cure.zip');
DeleteFileMask(GetAVZDirectory+'Quarantine', '*.*', true);
RegKeyIntParamWrite('HKLM','SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer','NoDriveTypeAutoRun', 221);
QuarantineFile('C:\Documents and Settings\USER\Local Settings\temp\vimsbls.exe','');
QuarantineFile('C:\Documents and Settings\USER\Local Settings\temp\vdsqwhjgscq.exe','');
QuarantineFile('C:\WINDOWS\system32\xyqkhfarqefxweupbieyw.exe','');
QuarantineFile('C:\WINDOWS\system32\vukcxtmbykjzwcqjtys.exe','');
QuarantineFile('C:\WINDOWS\system32\uqdskdtfzierlozp.exe','');
QuarantineFile('C:\WINDOWS\system32\kixoidvjfqodzerjsw.exe','');
QuarantineFile('C:\DOCUME~1\USER\LOCALS~1\Temp\kixoidvjfqodzerjsw.exe','');
QuarantineFile('C:\DOCUME~1\USER\LOCALS~1\Temp\iizsolfvtggxvcrlwcxq.exe .','');
QuarantineFile('C:\DOCUME~1\USER\LOCALS~1\Temp\iizsolfvtggxvcrlwcxq.exe','');
QuarantineFile('C:\DOCUME~1\USER\LOCALS~1\Temp\bymcvpgtoyvjeiult.exe .','');
QuarantineFile('C:\DOCUME~1\USER\LOCALS~1\Temp\bymcvpgtoyvjeiult.exe','');
QuarantineFile('c:\docume~1\user\locals~1\temp\vimsbls.exe','');
TerminateProcessByName('c:\docume~1\user\locals~1\temp\vimsbls.exe');
QuarantineFile('c:\docume~1\user\locals~1\temp\uqdskdtfzierlozp.exe','');
TerminateProcessByName('c:\docume~1\user\locals~1\temp\uqdskdtfzierlozp.exe');
DeleteFile('c:\docume~1\user\locals~1\temp\uqdskdtfzierlozp.exe');
DeleteFile('c:\docume~1\user\locals~1\temp\vimsbls.exe');
DeleteFile('C:\DOCUME~1\USER\LOCALS~1\Temp\bymcvpgtoyvjeiult.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ukramzjpdg');
DeleteFile('C:\DOCUME~1\USER\LOCALS~1\Temp\bymcvpgtoyvjeiult.exe .');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','xikov');
DeleteFile('C:\DOCUME~1\USER\LOCALS~1\Temp\iizsolfvtggxvcrlwcxq.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','hqq');
DeleteFile('C:\DOCUME~1\USER\LOCALS~1\Temp\iizsolfvtggxvcrlwcxq.exe .');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','bqwepbkpc');
DeleteFile('C:\DOCUME~1\USER\LOCALS~1\Temp\kixoidvjfqodzerjsw.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','oyzc');
DeleteFile('C:\WINDOWS\system32\kixoidvjfqodzerjsw.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','xikov');
DeleteFile('C:\WINDOWS\system32\uqdskdtfzierlozp.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','vimsbls');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','iuxckt');
DeleteFile('C:\WINDOWS\system32\vukcxtmbykjzwcqjtys.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','kydkufnr');
DeleteFile('C:\WINDOWS\system32\xyqkhfarqefxweupbieyw.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','oyzc');
DeleteFile('C:\Documents and Settings\USER\Local Settings\temp\vdsqwhjgscq.exe');
DeleteFile('C:\Documents and Settings\USER\Local Settings\temp\vimsbls.exe');
DeleteFile('C:\autorun.inf');
DeleteFile('D:\autorun.inf');
DeleteFile('F:\autorun.inf');
DeleteFile('G:\autorun.inf');
BC_ImportDeletedList;
ExecuteSysClean;
ExecuteWizard('TSW', 3, 3, true);
ExecuteWizard('SCU', 3, 3, true);
BC_Activate;
RebootWindows(true);
end.
После выполнения скрипта компьютер перезагрузится!