RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1) RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3) RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3) RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1) RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Advanced SystemCare', '圆4') RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Advanced SystemCare', 'x32') QuarantineFile('C:\Users\Black\AppData\Local\ZVRWH\ULUTJ.py', '') ĭeleteSchedulerTask('ASC_PerformanceMonitor') ĭeleteSchedulerTask('ASC_SkipUac_Black') ĭeleteSchedulerTask('ASC_SkipUac_BlackTensityGuy') ĭeleteSchedulerTask('Microsoft\Windows\SMB\UninstallSMB1ClientTask') ĭeleteSchedulerTask('Microsoft\Windows\SMB\UninstallSMB1ServerTask') ĭeleteSchedulerTask('System config updates') ĭeleteSchedulerTask('Windows Protection') ĭeleteFile('C:\ProgramData\Defender\Start.exe', '64') ĭeleteFile('C:\Users\Black\AppData\Local\BHNAC\JAHLA.py', '64') ĭeleteFile('C:\Users\Black\AppData\Local\config\updater.py', '64') ĭeleteFile('C:\Users\Black\AppData\Local\GVREV\CVNVG.py', '64') ĭeleteFile('C:\Users\Black\AppData\Local\mrJWF\cNJ.py', '64') ĭeleteFile('C:\Users\Black\AppData\Local\QEJFR\FCKGT.py', '64') ĭeleteFile('C:\Users\Black\AppData\Local\UCWKO\WXTUC.py', '64') ĭeleteFile('C:\Users\Black\AppData\Local\ZVRWH\ULUTJ.py', '64') ĭeleteService('AdvancedSystemCareService14') QuarantineFile('C:\Users\Black\AppData\Local\UCWKO\WXTUC.py', '') QuarantineFile('C:\Users\Black\AppData\Local\QEJFR\FCKGT.py', '') QuarantineFile('C:\Users\Black\AppData\Local\mrJWF\cNJ.py', '') QuarantineFile('C:\Users\Black\AppData\Local\GVREV\CVNVG.py', '') QuarantineFile('C:\Users\Black\AppData\Local\config\updater.py', '') QuarantineFile('C:\Users\Black\AppData\Local\BHNAC\JAHLA.py', '') QuarantineFile('C:\ProgramData\Defender\Start.exe', '')