Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
QuarantineFile('C:\WINDOWS\system32\UKbhokLVglKmPI.exe','');
QuarantineFile('C:\Temp\tmp3a1aa14436.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\write.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\winlogon.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\winfxdocobj.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\wextract.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\wdfmgr.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\vssvc.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\verclsid.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\utilman.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\unlodctr.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\tasklist.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\syskey.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\sigverif.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\schtasks.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rwinsta.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rsm.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rexec.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\reg.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rcp.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rcimlby.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rasphone.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rasdial.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rasautou.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\qfecheck.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\proquota.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\pentnt.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\packager.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\osuninst.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\osk.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\openfiles.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\nvcplui.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\ntvdm.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\ntkrnlpa.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\netsh.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\netdde.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\msswchx.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\msg.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\mqbkup.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\mountvol.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\mmc.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\migpwd.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\magnify.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\logonui.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\logman.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\logagent.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\locator.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\lnkstub.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\label.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\javaws.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\fsutil.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\findstr.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\esentutl.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\dvdupgrd.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\dplaysvr.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\dfrgfat.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\conime.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\cliconfg.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\cipher.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\cidaemon.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\cacls.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\auditusr.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\asr_fmt.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\alg.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\ahui.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\UKbhokLVglKmPI.exe','');
QuarantineFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\TSWbPrxy.exe','');
QuarantineFile('C:\WINDOWS\system32\drivers\pfnfd_1_10_0_8.sys','');
SetServiceStart('pfnfd_1_10_0_8', 4);
DeleteService('pfnfd_1_10_0_8');
DeleteFile('C:\WINDOWS\system32\drivers\pfnfd_1_10_0_8.sys','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\TSWbPrxy.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','TSWbPrxy');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','TSWbPrxy');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','TSWbPrxy');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','TSWbPrxy');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\UKbhokLVglKmPI.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','UKbhokLVglKmPI');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','UKbhokLVglKmPI');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','UKbhokLVglKmPI');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','UKbhokLVglKmPI');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\ahui.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','ahui');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','ahui');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','ahui');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','ahui');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\alg.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','alg');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','alg');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','alg');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','alg');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\asr_fmt.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','asr_fmt');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','asr_fmt');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','asr_fmt');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','asr_fmt');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\auditusr.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','auditusr');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','auditusr');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','auditusr');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','auditusr');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\cacls.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','cacls');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','cacls');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','cacls');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','cacls');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\cidaemon.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','cidaemon');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','cidaemon');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','cidaemon');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','cipher');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\cipher.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','cidaemon');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','cipher');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','cipher');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','cipher');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\cliconfg.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','cliconfg');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','cliconfg');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','cliconfg');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','cliconfg');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\conime.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','conime');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','conime');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','conime');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','conime');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\dfrgfat.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','dfrgfat');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','dfrgfat');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','dfrgfat');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','dfrgfat');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\dplaysvr.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','dplaysvr');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','dplaysvr');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','dplaysvr');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','dplaysvr');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\dvdupgrd.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','dvdupgrd');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','dvdupgrd');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','dvdupgrd');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','dvdupgrd');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\esentutl.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','esentutl');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','esentutl');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','esentutl');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','esentutl');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\findstr.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','findstr');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','findstr');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','findstr');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','findstr');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\fsutil.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','fsutil');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','fsutil');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','fsutil');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','fsutil');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\javaws.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','javaws');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','javaws');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','javaws');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','javaws');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\label.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','label');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','label');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','label');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','label');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\lnkstub.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','lnkstub');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','lnkstub');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','lnkstub');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','lnkstub');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\locator.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','locator');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','locator');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','locator');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','locator');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\logagent.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','logagent');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','logagent');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','logagent');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','logagent');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\logman.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','logman');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','logman');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','logman');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','logman');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\logonui.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','logonui');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','logonui');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','logonui');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','logonui');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\magnify.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','magnify');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','magnify');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','magnify');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','magnify');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\migpwd.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','migpwd');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','migpwd');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','migpwd');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','migpwd');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\mmc.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','mmc');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','mmc');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','mmc');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','mmc');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\mountvol.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','mountvol');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','mountvol');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Control Panel\Desktop','scrnsave.exe');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Command Processor','AutoRun');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Command Processor\','Autorun');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer','Run');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer','Run');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Command Processor\','Autorun');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Command Processor','AutoRun');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Control Panel\Desktop','scrnsave.exe');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','mountvol');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','mountvol');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\mqbkup.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','mqbkup');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','mqbkup');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','mqbkup');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','mqbkup');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\msg.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','msg');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','msg');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','msg');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','msg');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\msswchx.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','msswchx');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','msswchx');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','msswchx');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','msswchx');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\netdde.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','netdde');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','netdde');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','netdde');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','netdde');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\netsh.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','netsh');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','netsh');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','netsh');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','netsh');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\ntkrnlpa.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','ntkrnlpa');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','ntkrnlpa');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','ntkrnlpa');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','ntkrnlpa');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\ntvdm.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','ntvdm');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','ntvdm');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','ntvdm');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','ntvdm');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\nvcplui.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\openfiles.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\osk.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\osuninst.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\packager.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\pentnt.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\proquota.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\qfecheck.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rasautou.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rasdial.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rasphone.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rcimlby.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rcp.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\reg.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rexec.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rsm.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\rwinsta.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\schtasks.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\sigverif.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\syskey.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\tasklist.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\unlodctr.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\utilman.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\verclsid.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\vssvc.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\wdfmgr.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\wextract.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\winfxdocobj.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\winlogon.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Application Data\Microsoft\Windows\dllcache\write.exe','32');
DeleteFile('C:\Documents and Settings\Виктория\Local Settings\Application Data\Amigo\Application\ok.exe','32');
DeleteFile('C:\Temp\_uninst_38196102.bat','32');
DeleteFile('C:\Temp\tmp3a1aa14436.exe','32');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','tmp3a1aa14436');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce','tmp3a1aa14436');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','tmp3a1aa14436');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce','tmp3a1aa14436');
DeleteFile('C:\WINDOWS\system32\UKbhokLVglKmPI.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','NRYj__DJCBTOoBaXynvyEbkAgl');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Компьютер перезагрузится.