Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
DeleteFileMask(GetAVZDirectory + 'Quarantine', '*.*', true);
QuarantineFile('C:\Documents and Settings\All Users\Application Data\SecTaskMan\userini.exe.q_Quarantine_804DA00_q','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\307083.exe','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\~TM10.tmp','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\~TM12.tmp ','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\~TM13.tmp','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\~TM14.tmp','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\~TM16.tmp','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\~TM7.tmp','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\~TM8.tmp','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\~TM9.tmp','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\~TM9A.tmp','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\~TMA.tmp','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\~TMB.tmp','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\~TMC.tmp','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\~TMD.tmp','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\~TME.tmp','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temp\~TMF.tmp','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\3YPCG7KP\update[1].exe','');
QuarantineFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\I0GP359C\update[1].exe','');
QuarantineFile('C:\Program Files\Borland\Delphi7\Projects\Project1.exe ','');
QuarantineFile('C:\WINDOWS\system32\GreenFields.scr','');
QuarantineFile('C:\WINDOWS\system32\augy.vko','');
QuarantineFile('C:\WINDOWS\system32\wbem\grpconv.exe','');
QuarantineFile('C:\WINDOWS\Temp\wpv011278399986.exe','');
QuarantineFile('C:\WINDOWS\Temp\wpv021278400048.exe ','');
QuarantineFile('C:\WINDOWS\Temp\wpv091278399804.exe ','');
QuarantineFile('C:\WINDOWS\Temp\wpv091278400420.exe','');
QuarantineFile('C:\WINDOWS\Temp\wpv121278399629.exe','');
QuarantineFile('C:\WINDOWS\Temp\wpv151278399728.exe','');
QuarantineFile('C:\WINDOWS\Temp\wpv361278399382.exe','');
QuarantineFile('C:\WINDOWS\Temp\wpv401278399429.exe','');
QuarantineFile('C:\WINDOWS\Temp\wpv581278399510.exe','');
QuarantineFile('C:\WINDOWS\Temp\wpv661278399382.exe','');
QuarantineFile('C:\WINDOWS\Temp\wpv751278400473.exe','');
QuarantineFile('C:\WINDOWS\Temp\wpv771278399858.exe','');
QuarantineFile('C:\WINDOWS\Temp\wpv841278400146.exe','');
QuarantineFile('C:\WINDOWS\Temp\wpv911278400197.exe','');
QuarantineFile('C:\WINDOWS\Temp\wpv971278400097.exe','');
QuarantineFile('C:\WINDOWS\Temp\wpv151278400375.exe','');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\307083.exe');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\~TM10.tmp');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\~TM12.tmp');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\~TM13.tmp');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\~TM14.tmp');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\~TM16.tmp');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\~TM7.tmp');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\~TM8.tmp');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\~TM9.tmp');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\~TM9A.tmp');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\~TMA.tmp');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\~TMB.tmp');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\~TMC.tmp');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\~TMD.tmp');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\~TME.tmp');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temp\~TMF.tmp');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\3YPCG7KP\update[1].exe');
DeleteFile('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\I0GP359C\update[1].exe');
DeleteFileMask('C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5', '*.*', true);
DeleteFile('C:\WINDOWS\Temp\wpv011278399986.exe');
DeleteFile('C:\WINDOWS\Temp\wpv021278400048.exe');
DeleteFile('C:\WINDOWS\Temp\wpv091278399804.exe');
DeleteFile('C:\WINDOWS\Temp\wpv091278400420.exe');
DeleteFile('C:\WINDOWS\Temp\wpv121278399629.exe');
DeleteFile('C:\WINDOWS\Temp\wpv151278399728.exe');
DeleteFile('C:\WINDOWS\Temp\wpv361278399382.exe');
DeleteFile('C:\WINDOWS\Temp\wpv401278399429.exe');
DeleteFile('C:\WINDOWS\Temp\wpv581278399510.exe');
DeleteFile('C:\WINDOWS\Temp\wpv661278399382.exe');
DeleteFile('C:\WINDOWS\Temp\wpv751278400473.exe');
DeleteFile('C:\WINDOWS\Temp\wpv771278399858.exe');
DeleteFile('C:\WINDOWS\Temp\wpv841278400146.exe');
DeleteFile('C:\WINDOWS\Temp\wpv911278400197.exe');
DeleteFile('C:\WINDOWS\Temp\wpv971278400097.exe');
DeleteFile('C:\WINDOWS\Temp\wpv151278400375.exe');
BC_ImportAll;
ExecuteSysClean;
ExecuteWizard('TSW', 2, 2, true);
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.
После перезагрузки: