Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\program files\bytefence\bytefence.exe');
TerminateProcessByName('c:\program files\bytefence\bytefenceservice.exe');
TerminateProcessByName('c:\program files\bytefence\rslggr.exe');
TerminateProcessByName('c:\program files\bytefence\rtop\bin\rtop_bg.exe');
TerminateProcessByName('c:\program files\bytefence\rtop\bin\rtop_svc.exe');
TerminateProcessByName('c:\program files\common files\noobzo\gnupdate\smu.exe');
TerminateProcessByName('c:\users\Пользователь\appdata\local\temp\csrss\proxy\tor\tor.exe');
StopService('4a6b66534c5515925271f0bb9f4018ef');
StopService('ByteFenceService');
StopService('DrToolKrl');
StopService('mracsvc');
StopService('rtop');
StopService('SMUpd');
StopService('SMUpdd');
StopService('wfcre');
StopService('WinDefender');
QuarantineFile(' C:\Users\Пользователь\AppData\Roaming\Miner\Miner.exe', '');
QuarantineFile(' C:\Users\ПользовательAppData\Roaming\Adobe\Manager.exe', '');
QuarantineFile('c:\program files\bytefence\bytefence.exe', '');
QuarantineFile('c:\program files\bytefence\bytefenceservice.exe', '');
QuarantineFile('c:\program files\bytefence\rslggr.exe', '');
QuarantineFile('c:\program files\bytefence\rtop\bin\rtop_bg.exe', '');
QuarantineFile('c:\program files\bytefence\rtop\bin\rtop_svc.exe', '');
QuarantineFile('C:\Program Files\Common Files\Noobzo\GNUpdate\smci32.dll', '');
QuarantineFile('c:\program files\common files\noobzo\gnupdate\smu.exe', '');
QuarantineFile('C:\Program Files\Common Files\Noobzo\GNUpdate\smw.sys', '');
QuarantineFile('C:\ProgramData\a49d1a021b3e4a97bb99dc8315535910\chipset.exe', '');
QuarantineFile('C:\ProgramData\SearchModule\smhe.js', '');
QuarantineFile('C:\ProgramData\smp2.exe', '');
QuarantineFile('C:\Users\Пользователь\AppData\Local\e38dfa0f014e419e9220b0fb6a7d371c\chipset.exe', '');
QuarantineFile('C:\Users\Пользователь\AppData\Local\Temp\470d4db2628f4976b2a113ecf1a849e8\chipset.exe', '');
QuarantineFile('C:\Users\Пользователь\AppData\Local\Temp\61d8b9d1d2af497a930621ffd123f26f\chipset.exe', '');
QuarantineFile('c:\users\Пользователь\appdata\local\temp\csrss\proxy\tor\tor.exe', '');
QuarantineFile('C:\Users\Пользователь\AppData\Roaming\Microsoft\ugijfawe\aiecbrih.exe', '');
QuarantineFile('C:\Users\Пользователь\AppData\Roaming\3e40c1bde68c480f9014abf626f97d8a\chipset.exe', '');
QuarantineFile('C:\Windows\f50434fe53286e1cc0aeec004213a19e.ps1', '');
QuarantineFile('C:\Windows\system32\drivers\4a6b66534c5515925271f0bb9f4018ef.sys', '');
QuarantineFile('C:\Windows\system32\drivers\DrToolKrl.sys', '');
QuarantineFile('C:\Windows\system32\drivers\wfcre.sys', '');
QuarantineFile('C:\Windows\System32\mracsvc.exe', '');
QuarantineFile('C:\Windows\windefender.exe', '');
DeleteFile(' C:\Users\Пользователь\AppData\Roaming\Adobe\Manager.exe 604C4206-B430-43E1-A102-8BF11249AEC2', '32');
DeleteFile(' C:\Users\Пользователь\AppData\Roaming\Miner\Miner.exe /start ClaymoreMonero', '32');
DeleteFile('c:\program files\bytefence\bytefence.exe', '32');
DeleteFile('C:\Program Files\ByteFence\ByteFenceGUI.dll', '32');
DeleteFile('c:\program files\bytefence\bytefenceservice.exe', '32');
DeleteFile('C:\Program Files\ByteFence\Microsoft.Win32.TaskScheduler.dll', '32');
DeleteFile('C:\Program Files\ByteFence\rsEngine.dll', '32');
DeleteFile('C:\Program Files\ByteFence\rsLggr.dll', '32');
DeleteFile('c:\program files\bytefence\rslggr.exe', '32');
DeleteFile('C:\Program Files\ByteFence\rsUtils.dll', '32');
DeleteFile('c:\program files\bytefence\rtop\bin\rtop_bg.exe', '32');
DeleteFile('c:\program files\bytefence\rtop\bin\rtop_svc.exe', '32');
DeleteFile('C:\Program Files\Common Files\Noobzo\GNUpdate\smci32.dll', '32');
DeleteFile('c:\program files\common files\noobzo\gnupdate\smu.exe', '32');
DeleteFile('C:\Program Files\Common Files\Noobzo\GNUpdate\smw.sys', '32');
DeleteFile('C:\ProgramData\a49d1a021b3e4a97bb99dc8315535910\chipset.exe', '32');
DeleteFile('C:\ProgramData\SearchModule\smhe.js', '32');
DeleteFile('C:\ProgramData\smp2.exe', '32');
DeleteFile('C:\Users\Пользователь\AppData\Local\Temp\470d4db2628f4976b2a113ecf1a849e8\chipset.exe', '32');
DeleteFile('C:\Users\Пользователь\AppData\Local\Temp\61d8b9d1d2af497a930621ffd123f26f\chipset.exe', '32');
DeleteFile('c:\users\Пользователь\appdata\local\temp\csrss\proxy\tor\tor.exe', '32');
DeleteFile('C:\Users\Пользователь\AppData\Roaming\Microsoft\ugijfawe\aiecbrih.exe', '32');
DeleteFile('C:\Users\Пользователь\Local\e38dfa0f014e419e9220b0fb6a7d371c\chipset.exe', '32');
DeleteFile('C:\Users\Пользователь\AppData\Roaming\3e40c1bde68c480f9014abf626f97d8a\chipset.exe', '32');
DeleteFile('C:\Windows\f50434fe53286e1cc0aeec004213a19e.ps1', '32');
DeleteFile('C:\Windows\system32\drivers\4a6b66534c5515925271f0bb9f4018ef.sys', '32');
DeleteFile('C:\Windows\system32\drivers\DrToolKrl.sys', '32');
DeleteFile('C:\Windows\system32\drivers\wfcre.sys', '32');
DeleteFile('C:\Windows\System32\mracsvc.exe', '32');
DeleteFile('C:\Windows\windefender.exe', '32');
ExecuteFile('schtasks.exe', '/delete /TN "a0fedc4263ced41409c4a4cfe16ef7e2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ByteFence" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "f50434fe53286e1cc0aeec004213a19e" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "GoogleUpdateSecurityTaskMachine_AM" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "GoogleUpdateSecurityTaskMachine_IX" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "GoogleUpdateSecurityTaskMachine_WY" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "GoogleUpdateSecurityTaskMachine_YO" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "GoogleUpdateSecurityTaskMachine_ZV" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Multimedia\ClaymoreMonero" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Multimedia\Manager" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SMW_P" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SMW_UpdateTask_Time_323435333131383133312d3437415a556c2a3223346c41" /F', 0, 15000, true);
DeleteService('4a6b66534c5515925271f0bb9f4018ef');
DeleteService('ByteFenceService');
DeleteService('DrToolKrl');
DeleteService('mracsvc');
DeleteService('rtop');
DeleteService('SMUpd');
DeleteService('SMUpdd');
DeleteService('TCPSvc');
DeleteService('wfcre');
DeleteService('WinDefender');
DeleteFileMask(' c:\users\Пользователь\appdata\roaming\miner', '*', true);
DeleteFileMask('c:\program files\bytefence', '*', true);
DeleteFileMask('c:\program files\common files\noobzo', '*', true);
DeleteFileMask('c:\programdata\a49d1a021b3e4a97bb99dc8315535910', '*', true);
DeleteFileMask('c:\programdata\searchmodule', '*', true);
DeleteFileMask('c:\users\Пользователь\appdata\local\e38dfa0f014e419e9220b0fb6a7d371c', '*', true);
DeleteFileMask('c:\users\Пользователь\appdata\local\temp\470d4db2628f4976b2a113ecf1a849e8', '*', true);
DeleteFileMask('c:\users\Пользователь\appdata\local\temp\61d8b9d1d2af497a930621ffd123f26f', '*', true);
DeleteFileMask('c:\users\Пользователь\appdata\roaming\3e40c1bde68c480f9014abf626f97d8a', '*', true);
DeleteFileMask('c:\users\пользователь\appdata\roaming\microsoft\ugijfawe', '*', true);
DeleteDirectory(' c:\users\Пользователь\appdata\roaming\miner');
DeleteDirectory('c:\program files\bytefence');
DeleteDirectory('c:\program files\common files\noobzo');
DeleteDirectory('c:\programdata\a49d1a021b3e4a97bb99dc8315535910');
DeleteDirectory('c:\programdata\searchmodule');
DeleteDirectory('c:\users\Пользователь\appdata\local\e38dfa0f014e419e9220b0fb6a7d371c');
DeleteDirectory('c:\users\Пользователь\appdata\local\temp\470d4db2628f4976b2a113ecf1a849e8');
DeleteDirectory('c:\users\Пользователь\appdata\local\temp\61d8b9d1d2af497a930621ffd123f26f');
DeleteDirectory('c:\users\Пользователь\appdata\roaming\3e40c1bde68c480f9014abf626f97d8a');
DeleteDirectory('c:\users\пользователь\appdata\roaming\microsoft\ugijfawe');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'Chromium');
BC_ImportALL;
ExecuteSysClean;
ExecuteRepair(2);
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.