Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ClearQuarantine;
TerminateProcessByName('c:\windows\system32\msvmiode.exe');
TerminateProcessByName('c:\windows\cfdrive32.exe');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','Wireless Zero ConfigurationWZCSvc (XP)');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','Windows Logon Application');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','TCP/IP NetBIOS Helper');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','Spooler SubSystem App');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','Plug and Play');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','NTLM Security Support Provider');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','Local Security Authority Service');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','Background Intelligent Transfer Service');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','Application Layer Gateway service');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Print Spooler');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','MSRPC');
RegKeyResetSecurity('HKLM','SYSTEM\CurrentControlSet\Services\vjuipt');
RegKeyResetSecurity('HKLM','SYSTEM\CurrentControlSet\Services\lctlvvrss');
RegKeyResetSecurity('HKLM','SYSTEM\CurrentControlSet\Services\golkolmzc');
RegKeyResetSecurity('HKLM','SYSTEM\CurrentControlSet\Services\fopkx');
RegKeyResetSecurity('HKLM','SYSTEM\CurrentControlSet\Services\fnjibzm');
RegKeyResetSecurity('HKLM','SYSTEM\CurrentControlSet\Services\fdfrhob');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon','Taskman');
QuarantineFileF('%appdata%', 'exe.*', false, '', 0, 0);
QuarantineFile('c:\windows\system32\msvmiode.exe','');
QuarantineFile('c:\windows\system32\11.exe','');
QuarantineFile('c:\windows\cfdrive32.exe','');
QuarantineFile('C:\autorun.inf','');
DeleteFileMask('%appdata%','*.exe', false);
DeleteFile('C:\WINDOWS\system32\msvmiode.exe');
DeleteFile('C:\WINDOWS\system32\11.exe');
DeleteFile('C:\WINDOWS\cfdrive32.exe');
DeleteFile('C:\autorun.inf');
DeleteService('vjuipt');
DeleteService('lctlvvrss');
DeleteService('golkolmzc');
DeleteService('fopkx');
DeleteService('fnjibzm');
DeleteService('fdfrhob');
ExecuteWizard('TSW', 2, 2, true);
ExecuteWizard('SCU', 2, 2, true);
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
SetAVZPMStatus(True);
RebootWindows(true);
end.