Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
DeleteFileMask(GetAVZDirectory+'Quarantine', '*.*', true);
terminateprocessbyname('F:\WINDOWS\system32\umdmgr.exe');
QuarantineFile('F:\RECYCLER\S-1-5-21-8562727992-8274133030-328035668-9419\syscr.exe','');
QuarantineFile('F:\WINDOWS\system32\logon.scr','');
QuarantineFile('F:\System Volume Information\_restore{BC6241A9-BF3C-475E-94D7-56CD9D7E7FA3}\RP1\A0000029.scr','');
QuarantineFile('F:\WINDOWS\system32\umdmgr.exe','');
QuarantineFile('F:\WINDOWS\system32\syre32.exe','');
QuarantineFile('F:\WINDOWS\system32\msvmcls64.exe','');
QuarantineFile('F:\WINDOWS\system32\.exe','');
QuarantineFile('F:\WINDOWS\ndll.exe','');
QuarantineFile('F:\WINDOWS\jjdrive32.exe','');
QuarantineFile('F:\WINDOWS\cidrive32.exe','');
QuarantineFile('F:\RECYCLER\S-1-5-21-8562727992-8274133030-328035668-9419\syscr.exe','');
QuarantineFile('F:\RECYCLER\S-1-5-21-8256274527-0381162581-259373066-8863\wmfcgr.exe','');
QuarantineFile('F:\RECYCLER\S-1-5-21-4924529600-7314696115-643252364-0428\syscr.exe','');
QuarantineFile('F:\RECYCLER\S-1-5-21-0609913008-5857336788-697393397-2702\wmfcgr.exe','');
QuarantineFile('F:\RECYCLER\S-1-5-21-0609913008-5857336788-697393397-2702\wmfcgr.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe','');
DeleteService('Nimb8xhmwm');
QuarantineFile('Nimb8xhmwm.sys','');
QuarantineFile('f:\windows\system32\wuauclt.exe','');
DeleteFile('Nimb8xhmwm.sys');
DeleteFile('C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','12CFG214-K641-12SF-N85P');
DeleteFile('F:\RECYCLER\S-1-5-21-0609913008-5857336788-697393397-2702\wmfcgr.exe');
DeleteFile('F:\RECYCLER\S-1-5-21-0609913008-5857336788-697393397-2702\wmfcgr.exe');
DeleteFile('F:\WINDOWS\cidrive32.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Driver Setup');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Microsoft Driver Setup');
DeleteFile('F:\WINDOWS\jjdrive32.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Update Setup');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Microsoft Update Setup');
DeleteFile('F:\WINDOWS\ndll.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','oo');
DeleteFile('F:\WINDOWS\system32\.exe');
DeleteFile('F:\WINDOWS\system32\msvmcls64.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','MS Virtual CLS');
DeleteFile('F:\WINDOWS\system32\syre32.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','syre32');
DeleteFile('F:\WINDOWS\system32\umdmgr.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','003');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','916');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','658');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','582');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','770');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','227');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','207');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','044');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','912');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','996');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','612');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','881');
DeleteFile('F:\System Volume Information\_restore{BC6241A9-BF3C-475E-94D7-56CD9D7E7FA3}\RP1\A0000029.scr');
DeleteFile('F:\RECYCLER\S-1-5-21-8562727992-8274133030-328035668-9419\syscr.exe');
DeleteFileMask('F:\RECYCLER', '*.*', true);
DeleteFileMask('C:\RECYCLER', '*.*', true);
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteWizard('TSW',2,2,true);
ExecuteWizard('SCU',3,3,true);
RebootWindows(true);
end.
После перезагрузки