Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
SetAVZPMStatus(false);
TerminateProcessByName('c:\users\user\appdata\roaming\a3926140-1430940309-11dc-86a3-001bfc756d1b\vnsncb2a.tmp');
TerminateProcessByName('c:\users\user\appdata\roaming\a3926140-1430940309-11dc-86a3-001bfc756d1b\nso1e49.tmp');
TerminateProcessByName('c:\program files\crossbrowse\crossbrowse\application\crossbrowse.exe');
TerminateProcessByName('c:\program files\ge-force\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-6.exe');
TerminateProcessByName('c:\program files\ge-force\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-10.exe');
TerminateProcessByName('c:\program files\ge-force\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-1-6.exe');
TerminateProcessByName('c:\program files\sense\c1c0ef1d-776b-4a59-b7de-24061c69dee8-6.exe');
TerminateProcessByName('c:\program files\sense\c1c0ef1d-776b-4a59-b7de-24061c69dee8-1-6.exe');
TerminateProcessByName('c:\program files\savepass 1.1\ba084722-89f4-488a-834a-50c2b0bf7996-6.exe');
TerminateProcessByName('c:\program files\savepass 1.1\ba084722-89f4-488a-834a-50c2b0bf7996-10.exe');
TerminateProcessByName('c:\program files\savepass 1.1\ba084722-89f4-488a-834a-50c2b0bf7996-1-6.exe');
TerminateProcessByName('c:\program files\cinemaplus-4.5vv17.05\99a75547-4ace-47d6-a932-8dec59b65f34-6.exe');
TerminateProcessByName('c:\program files\cinemaplus-4.5vv17.05\99a75547-4ace-47d6-a932-8dec59b65f34-10.exe');
TerminateProcessByName('c:\program files\cinemaplus-4.5vv19.05\08d6f50a-1641-485c-9513-276ced7a12aa-6.exe');
TerminateProcessByName('c:\program files\cinemaplus-4.5vv19.05\08d6f50a-1641-485c-9513-276ced7a12aa-10.exe');
StopService('fegukygy');
QuarantineFile('C:\Program Files\application assistance\ap.exe', '');
QuarantineFile('C:\Users\User\AppData\Roaming\jwQdX510Q90KhVO4O0z59.exe', '');
QuarantineFile('C:\Program Files\CinemaPlus-4.5vV19.05\08d6f50a-1641-485c-9513-276ced7a12aa-1-6.exe', '');
QuarantineFile('C:\Program Files\ver4SpeedChecker\S7SpeedCheckerZ46.exe', '');
QuarantineFile('C:\Program Files\Crossbrowse\Crossbrowse\Application\utility.exe', '');
QuarantineFile('C:\Program Files\Sense\c1c0ef1d-776b-4a59-b7de-24061c69dee8-5.exe', '');
QuarantineFile('C:\Program Files\AnyProtectEx\AnyProtect.exe', '');
QuarantineFile('C:\iexplore.bat', '');
QuarantineFile('C:\TEMP\nsg5FAE.tmp\IpConfig.dll', '');
QuarantineFile('c:\users\user\appdata\roaming\a3926140-1430940309-11dc-86a3-001bfc756d1b\vnsncb2a.tmp', '');
QuarantineFile('c:\users\user\appdata\roaming\a3926140-1430940309-11dc-86a3-001bfc756d1b\nso1e49.tmp', '');
QuarantineFile('c:\program files\crossbrowse\crossbrowse\application\crossbrowse.exe', '');
QuarantineFile('c:\program files\ge-force\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-6.exe', '');
QuarantineFile('c:\program files\ge-force\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-10.exe', '');
QuarantineFile('c:\program files\ge-force\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-1-6.exe', '');
QuarantineFile('c:\program files\sense\c1c0ef1d-776b-4a59-b7de-24061c69dee8-6.exe', '');
QuarantineFile('c:\program files\sense\c1c0ef1d-776b-4a59-b7de-24061c69dee8-1-6.exe', '');
QuarantineFile('c:\program files\savepass 1.1\ba084722-89f4-488a-834a-50c2b0bf7996-6.exe', '');
QuarantineFile('c:\program files\savepass 1.1\ba084722-89f4-488a-834a-50c2b0bf7996-10.exe', '');
QuarantineFile('c:\program files\savepass 1.1\ba084722-89f4-488a-834a-50c2b0bf7996-1-6.exe', '');
QuarantineFile('c:\program files\cinemaplus-4.5vv17.05\99a75547-4ace-47d6-a932-8dec59b65f34-6.exe', '');
QuarantineFile('c:\program files\cinemaplus-4.5vv17.05\99a75547-4ace-47d6-a932-8dec59b65f34-10.exe', '');
QuarantineFile('c:\program files\cinemaplus-4.5vv19.05\08d6f50a-1641-485c-9513-276ced7a12aa-6.exe', '');
QuarantineFile('c:\program files\cinemaplus-4.5vv19.05\08d6f50a-1641-485c-9513-276ced7a12aa-10.exe', '');
DeleteFile('c:\program files\cinemaplus-4.5vv19.05\08d6f50a-1641-485c-9513-276ced7a12aa-10.exe', '32');
DeleteFile('c:\program files\cinemaplus-4.5vv19.05\08d6f50a-1641-485c-9513-276ced7a12aa-6.exe', '32');
DeleteFile('c:\program files\cinemaplus-4.5vv17.05\99a75547-4ace-47d6-a932-8dec59b65f34-10.exe', '32');
DeleteFile('c:\program files\cinemaplus-4.5vv17.05\99a75547-4ace-47d6-a932-8dec59b65f34-6.exe', '32');
DeleteFile('c:\program files\savepass 1.1\ba084722-89f4-488a-834a-50c2b0bf7996-1-6.exe', '32');
DeleteFile('c:\program files\savepass 1.1\ba084722-89f4-488a-834a-50c2b0bf7996-10.exe', '32');
DeleteFile('c:\program files\sense\c1c0ef1d-776b-4a59-b7de-24061c69dee8-1-6.exe', '32');
DeleteFile('c:\program files\sense\c1c0ef1d-776b-4a59-b7de-24061c69dee8-6.exe', '32');
DeleteFile('c:\program files\ge-force\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-1-6.exe', '32');
DeleteFile('c:\program files\ge-force\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-10.exe', '32');
DeleteFile('c:\program files\ge-force\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-6.exe', '32');
DeleteFile('c:\program files\crossbrowse\crossbrowse\application\crossbrowse.exe', '32');
DeleteFile('c:\users\user\appdata\roaming\a3926140-1430940309-11dc-86a3-001bfc756d1b\vnsncb2a.tmp', '32');
DeleteFile('C:\Program Files\Crossbrowse\Crossbrowse\Application\39.4.2171.95\chrome.dll', '32');
DeleteFile('C:\Program Files\Crossbrowse\Crossbrowse\Application\39.4.2171.95\chrome_child.dll', '32');
DeleteFile('C:\Program Files\Crossbrowse\Crossbrowse\Application\39.4.2171.95\chrome_elf.dll', '32');
DeleteFile('C:\Program Files\Crossbrowse\Crossbrowse\Application\39.4.2171.95\libegl.dll', '32');
DeleteFile('C:\Program Files\Crossbrowse\Crossbrowse\Application\39.4.2171.95\libglesv2.dll', '32');
DeleteFile('C:\TEMP\nsg5FAE.tmp\IpConfig.dll', '32');
DeleteFile('C:\Users\User\AppData\Roaming\A3926140-1430940309-11DC-86A3-001BFC756D1B\nso1E49.tmp', '32');
DeleteFile('C:\iexplore.bat', '32');
DeleteFile('C:\Windows\Tasks\08d6f50a-1641-485c-9513-276ced7a12aa-1-6.job', '32');
DeleteFile('C:\Windows\Tasks\08d6f50a-1641-485c-9513-276ced7a12aa-1-7.job', '32');
DeleteFile('C:\Windows\Tasks\08d6f50a-1641-485c-9513-276ced7a12aa-10_user.job', '32');
DeleteFile('C:\Windows\Tasks\08d6f50a-1641-485c-9513-276ced7a12aa-3.job', '32');
DeleteFile('C:\Windows\Tasks\08d6f50a-1641-485c-9513-276ced7a12aa-5.job', '32');
DeleteFile('C:\Windows\Tasks\08d6f50a-1641-485c-9513-276ced7a12aa-5_user.job', '32');
DeleteFile('C:\Windows\Tasks\08d6f50a-1641-485c-9513-276ced7a12aa-6.job', '32');
DeleteFile('C:\Windows\Tasks\08d6f50a-1641-485c-9513-276ced7a12aa-7.job', '32');
DeleteFile('C:\Windows\Tasks\3e9444d8-73a6-40e7-a8b9-8a32d30d533e-1-6.job', '32');
DeleteFile('C:\Windows\Tasks\3e9444d8-73a6-40e7-a8b9-8a32d30d533e-1-7.job', '32');
DeleteFile('C:\Windows\Tasks\3e9444d8-73a6-40e7-a8b9-8a32d30d533e-10_user.job', '32');
DeleteFile('C:\Windows\Tasks\3e9444d8-73a6-40e7-a8b9-8a32d30d533e-5.job', '32');
DeleteFile('C:\Windows\Tasks\3e9444d8-73a6-40e7-a8b9-8a32d30d533e-5_user.job', '32');
DeleteFile('C:\Windows\Tasks\3e9444d8-73a6-40e7-a8b9-8a32d30d533e-6.job', '32');
DeleteFile('C:\Windows\Tasks\3e9444d8-73a6-40e7-a8b9-8a32d30d533e-7.job', '32');
DeleteFile('C:\Windows\Tasks\8hq6w8e8F9mYw6yZLVnuZA1S.job', '32');
DeleteFile('C:\Windows\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-1-6.job', '32');
DeleteFile('C:\Windows\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-1-7.job', '32');
DeleteFile('C:\Windows\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-10_user.job', '32');
DeleteFile('C:\Windows\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-3.job', '32');
DeleteFile('C:\Windows\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-5.job', '32');
DeleteFile('C:\Windows\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-5_user.job', '32');
DeleteFile('C:\Windows\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-6.job', '32');
DeleteFile('C:\Windows\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-7.job', '32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP1.job', '32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP3.job', '32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP2.job', '32');
DeleteFile('C:\Windows\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-1-6.job', '32');
DeleteFile('C:\Windows\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-1-7.job', '32');
DeleteFile('C:\Windows\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-10_user.job', '32');
DeleteFile('C:\Windows\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-3.job', '32');
DeleteFile('C:\Windows\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-5.job', '32');
DeleteFile('C:\Windows\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-5_user.job', '32');
DeleteFile('C:\Windows\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-6.job', '32');
DeleteFile('C:\Windows\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-7.job', '32');
DeleteFile('C:\Windows\Tasks\c1c0ef1d-776b-4a59-b7de-24061c69dee8-1-6.job', '32');
DeleteFile('C:\Windows\Tasks\c1c0ef1d-776b-4a59-b7de-24061c69dee8-1-7.job', '32');
DeleteFile('C:\Windows\Tasks\c1c0ef1d-776b-4a59-b7de-24061c69dee8-5.job', '32');
DeleteFile('C:\Program Files\Sense\c1c0ef1d-776b-4a59-b7de-24061c69dee8-5.exe', '32');
DeleteFile('C:\Windows\Tasks\c1c0ef1d-776b-4a59-b7de-24061c69dee8-5_user.job', '32');
DeleteFile('C:\Windows\Tasks\c1c0ef1d-776b-4a59-b7de-24061c69dee8-6.job', '32');
DeleteFile('C:\Windows\Tasks\c1c0ef1d-776b-4a59-b7de-24061c69dee8-7.job', '32');
DeleteFile('C:\Windows\Tasks\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-1-6.job', '32');
DeleteFile('C:\Windows\Tasks\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-1-7.job', '32');
DeleteFile('C:\Windows\Tasks\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-10_user.job', '32');
DeleteFile('C:\Windows\Tasks\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-5.job', '32');
DeleteFile('C:\Windows\Tasks\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-5_user.job', '32');
DeleteFile('C:\Windows\Tasks\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-7.job', '32');
DeleteFile('C:\Windows\Tasks\Crossbrowse.job', '32');
DeleteFile('C:\Windows\Tasks\Digital Sites.job', '32');
DeleteFile('C:\Program Files\Crossbrowse\Crossbrowse\Application\utility.exe', '32');
DeleteFile('C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job', '32');
DeleteFile('C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job', '32');
DeleteFile('C:\Windows\Tasks\jwQdX510Q90KhVO4O0z59.job', '32');
DeleteFile('C:\Windows\Tasks\NJOFOlS.job', '32');
DeleteFile('C:\Program Files\ver4SpeedChecker\S7SpeedCheckerZ46.exe', '32');
DeleteFile('C:\Windows\Tasks\SpeedChecker Update.job', '32');
DeleteFile('C:\Program Files\CinemaPlus-4.5vV19.05\08d6f50a-1641-485c-9513-276ced7a12aa-1-6.exe', '32');
DeleteFile('C:\Windows\system32\Tasks\08d6f50a-1641-485c-9513-276ced7a12aa-1-6', '32');
DeleteFile('C:\Windows\system32\Tasks\08d6f50a-1641-485c-9513-276ced7a12aa-1-7', '32');
DeleteFile('C:\Windows\system32\Tasks\08d6f50a-1641-485c-9513-276ced7a12aa-3', '32');
DeleteFile('C:\Windows\system32\Tasks\08d6f50a-1641-485c-9513-276ced7a12aa-5', '32');
DeleteFile('C:\Windows\system32\Tasks\08d6f50a-1641-485c-9513-276ced7a12aa-5_user', '32');
DeleteFile('C:\Windows\system32\Tasks\08d6f50a-1641-485c-9513-276ced7a12aa-6', '32');
DeleteFile('C:\Windows\system32\Tasks\08d6f50a-1641-485c-9513-276ced7a12aa-7', '32');
DeleteFile('C:\Windows\system32\Tasks\3e9444d8-73a6-40e7-a8b9-8a32d30d533e-1-6', '32');
DeleteFile('C:\Windows\system32\Tasks\3e9444d8-73a6-40e7-a8b9-8a32d30d533e-1-7', '32');
DeleteFile('C:\Windows\system32\Tasks\3e9444d8-73a6-40e7-a8b9-8a32d30d533e-10_user', '32');
DeleteFile('C:\Windows\system32\Tasks\3e9444d8-73a6-40e7-a8b9-8a32d30d533e-3', '32');
DeleteFile('C:\Windows\system32\Tasks\3e9444d8-73a6-40e7-a8b9-8a32d30d533e-5', '32');
DeleteFile('C:\Windows\system32\Tasks\3e9444d8-73a6-40e7-a8b9-8a32d30d533e-5_user', '32');
DeleteFile('C:\Windows\system32\Tasks\3e9444d8-73a6-40e7-a8b9-8a32d30d533e-6', '32');
DeleteFile('C:\Windows\system32\Tasks\3e9444d8-73a6-40e7-a8b9-8a32d30d533e-7', '32');
DeleteFile('C:\Windows\system32\Tasks\8hq6w8e8F9mYw6yZLVnuZA1S', '32');
DeleteFile('C:\Windows\system32\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-1-6', '32');
DeleteFile('C:\Windows\system32\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-1-7', '32');
DeleteFile('C:\Windows\system32\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-10_user', '32');
DeleteFile('C:\Windows\system32\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-3', '32');
DeleteFile('C:\Windows\system32\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-5', '32');
DeleteFile('C:\Windows\system32\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-5_user', '32');
DeleteFile('C:\Windows\system32\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-6', '32');
DeleteFile('C:\Windows\system32\Tasks\99a75547-4ace-47d6-a932-8dec59b65f34-7', '32');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP1', '32');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP2', '32');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP3', '32');
DeleteFile('C:\Windows\system32\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-1-6', '32');
DeleteFile('C:\Windows\system32\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-1-7', '32');
DeleteFile('C:\Windows\system32\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-10_user', '32');
DeleteFile('C:\Windows\system32\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-3', '32');
DeleteFile('C:\Windows\system32\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-5', '32');
DeleteFile('C:\Windows\system32\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-5_user', '32');
DeleteFile('C:\Windows\system32\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-6', '32');
DeleteFile('C:\Windows\system32\Tasks\ba084722-89f4-488a-834a-50c2b0bf7996-7', '32');
DeleteFile('C:\Windows\system32\Tasks\c1c0ef1d-776b-4a59-b7de-24061c69dee8-1-6', '32');
DeleteFile('C:\Windows\system32\Tasks\c1c0ef1d-776b-4a59-b7de-24061c69dee8-1-7', '32');
DeleteFile('C:\Windows\system32\Tasks\c1c0ef1d-776b-4a59-b7de-24061c69dee8-5', '32');
DeleteFile('C:\Windows\system32\Tasks\c1c0ef1d-776b-4a59-b7de-24061c69dee8-5_user', '32');
DeleteFile('C:\Windows\system32\Tasks\c1c0ef1d-776b-4a59-b7de-24061c69dee8-6', '32');
DeleteFile('C:\Windows\system32\Tasks\c1c0ef1d-776b-4a59-b7de-24061c69dee8-7', '32');
DeleteFile('C:\Windows\system32\Tasks\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-1-6', '32');
DeleteFile('C:\Windows\system32\Tasks\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-1-7', '32');
DeleteFile('C:\Windows\system32\Tasks\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-10_user', '32');
DeleteFile('C:\Windows\system32\Tasks\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-5', '32');
DeleteFile('C:\Windows\system32\Tasks\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-5_user', '32');
DeleteFile('C:\Windows\system32\Tasks\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-6', '32');
DeleteFile('C:\Windows\system32\Tasks\cca6c26d-c6ed-4b38-9461-cf28e479f6c4-7', '32');
DeleteFile('C:\Windows\system32\Tasks\Crossbrowse', '32');
DeleteFile('C:\Windows\system32\Tasks\Digital Sites', '32');
DeleteFile('C:\Windows\system32\Tasks\Driver Booster SkipUAC (User)', '32');
DeleteFile('C:\Windows\system32\Tasks\globalUpdateUpdateTaskMachineCore', '32');
DeleteFile('C:\Windows\system32\Tasks\globalUpdateUpdateTaskMachineUA', '32');
DeleteFile('C:\Windows\system32\Tasks\jwQdX510Q90KhVO4O0z59', '32');
DeleteFile('C:\Users\User\AppData\Roaming\jwQdX510Q90KhVO4O0z59.exe', '32');
DeleteFile('C:\Windows\system32\Tasks\NJOFOlS', '32');
DeleteFile('C:\Windows\system32\Tasks\SmartWeb Upgrade Trigger Task', '32');
DeleteFile('C:\Windows\system32\Tasks\SpeedChecker Update', '32');
DeleteFile('C:\Program Files\anyprotectex\anyprotect.exe', '32');
DeleteFile('C:\Program Files\application assistance\ap.exe', '32');
DeleteService('innfd_1_10_0_13');
DeleteService('innfd_1_10_0_14');
DeleteService('QMUdisk');
DeleteService('fegukygy');
DeleteFileMask('C:\Program Files\application assistance', '*', true);
DeleteFileMask('C:\Program Files\anyprotectex', '*', true);
DeleteFileMask('C:\Program Files\CinemaPlus-4.5v', '*', true);
DeleteFileMask('C:\Program Files\ver4SpeedChecker', '*', true);
DeleteFileMask('C:\Program Files\Crossbrowse', '*', true);
DeleteFileMask('C:\Program Files\Sense', '*', true);
DeleteFileMask('c:\program files\savepass 1.1', '*', true);
DeleteFileMask('C:\Users\User\AppData\Roaming\A3926140-1430940309-11DC-86A3-001BFC756D1B', '*', true);
DeleteDirectory('C:\Program Files\application assistance');
DeleteDirectory('C:\Program Files\anyprotectex');
DeleteDirectory('C:\Program Files\CinemaPlus-4.5v');
DeleteDirectory('C:\Program Files\ver4SpeedChecker');
DeleteDirectory('C:\Program Files\Crossbrowse');
DeleteDirectory('C:\Program Files\Sense');
DeleteDirectory('c:\program files\savepass 1.1');
DeleteDirectory('C:\Users\User\AppData\Roaming\A3926140-1430940309-11DC-86A3-001BFC756D1B');
DelBHO('{0633EE93-D776-472f-A0FF-E1416B8B2E3D}');
DelBHO('{1bb456da-878f-44a5-b013-4bfe0ae02fce}');
BC_ImportDeletedList;
ExecuteSysClean;
BC_DeleteSvc('fegukygy');
ExecuteRepair(2);
ExecuteRepair(4);
ExecuteRepair(3);
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.