begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
TerminateProcessByName('c:\programdata\ywdmy\wdman.exe');
TerminateProcessByName('c:\program files (x86)\gmsd_ru_005010187\gmsd_ru_005010187.exe');
TerminateProcessByName('c:\program files (x86)\gmsd_ru_005010189\gmsd_ru_005010189.exe');
TerminateProcessByName('c:\program files (x86)\gmsd_ru_005010190\gmsd_ru_005010190.exe');
TerminateProcessByName('c:\program files (x86)\32444335-1448269821-5131-4756-80c16e41b41f\jnsice12.tmp');
TerminateProcessByName('c:\program files (x86)\32444335-1451042468-5131-4756-80c16e41b41f\knsl3691.tmp');
TerminateProcessByName('c:\users\738f~1\appdata\local\temp\nsj7832.tmp');
TerminateProcessByName('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\3\plugin.exe');
TerminateProcessByName('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\8\plugin.exe');
TerminateProcessByName('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\2\plugin.exe');
TerminateProcessByName('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\5\plugin.exe');
TerminateProcessByName('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\12\plugin.exe');
TerminateProcessByName('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\7\plugin.exe');
TerminateProcessByName('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\10\plugin.exe');
TerminateProcessByName('c:\programdata\tmp0x0x\protectwindowsmanager.exe');
TerminateProcessByName('c:\program files (x86)\sfk\ssfk.exe');
TerminateProcessByName('c:\users\Азат\appdata\local\gmsd_ru_005010189\upgmsd_ru_005010189.exe');
StopService('WdMan');
StopService('Update Mgr MiddleRush');
StopService('Service Mgr MiddleRush');
StopService('hebimycy');
StopService('jyzyvomo');
StopService('SSFK');
StopService('WindowsMangerProtect');
QuarantineFile('C:\Program Files (x86)\Zaxar\ZaxarGameBrowser.exe','');
QuarantineFile('C:\Program Files (x86)\Common Files\48ed1695-d484-472b-bd42-582714ef1368\updater.exe','');
QuarantineFile('C:\ProgramData\48ed1695-d484-472b-bd42-582714ef1368\plugincontainer.exe','');
QuarantineFile('c:\programdata\ywdmy\wdman.exe','');
QuarantineFileF('c:\programdata\tmp0x0x', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js', true, '', 0 ,0);
QuarantineFileF('c:\program files (x86)\sfk', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js', true, '', 0 ,0);
QuarantineFile('c:\program files (x86)\gmsd_ru_005010187\gmsd_ru_005010187.exe', '');
QuarantineFile('c:\program files (x86)\gmsd_ru_005010189\gmsd_ru_005010189.exe', '');
QuarantineFile('c:\program files (x86)\gmsd_ru_005010190\gmsd_ru_005010190.exe', '');
QuarantineFile('c:\program files (x86)\32444335-1448269821-5131-4756-80c16e41b41f\jnsice12.tmp', '');
QuarantineFile('c:\program files (x86)\32444335-1451042468-5131-4756-80c16e41b41f\knsl3691.tmp', '');
QuarantineFile('c:\users\738f~1\appdata\local\temp\nsj7832.tmp', '');
QuarantineFile('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\3\plugin.exe', '');
QuarantineFile('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\8\plugin.exe', '');
QuarantineFile('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\2\plugin.exe', '');
QuarantineFile('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\5\plugin.exe', '');
QuarantineFile('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\12\plugin.exe', '');
QuarantineFile('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\7\plugin.exe', '');
QuarantineFile('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\10\plugin.exe', '');
QuarantineFile('c:\programdata\tmp0x0x\protectwindowsmanager.exe', '');
QuarantineFile('c:\program files (x86)\sfk\ssfk.exe', '');
QuarantineFile('c:\users\Азат\appdata\local\gmsd_ru_005010189\upgmsd_ru_005010189.exe', '');
QuarantineFile('C:\Users\738F~1\AppData\Local\Temp\{04710452-F85C-4F66-AA8F-721D67F13932}.dll', '');
QuarantineFile('C:\Program Files (x86)\gmsd_ru_005010169\gmsd_ru_005010169.exe', '');
QuarantineFile('C:\Users\Азат\AppData\Local\gmsd_ru_005010187\upgmsd_ru_005010187.exe', '');
QuarantineFile('C:\Users\Азат\AppData\Local\gmsd_ru_005010177\upgmsd_ru_005010177.exe', '');
QuarantineFile('C:\Users\Азат\AppData\Local\gmsd_ru_005010190\upgmsd_ru_005010190.exe', '');
QuarantineFile('C:\Users\Азат\AppData\Local\coprofit\coprofit_stb.exe', '');
QuarantineFile('C:\Users\Азат\AppData\Roaming\Browsers\exe.resworb.bat', '');
QuarantineFile('C:\ProgramData\btHpzjckDRbkY1.bat', '');
DeleteFile('c:\programdata\ywdmy\wdman.exe','32');
DeleteFile('C:\ProgramData\48ed1695-d484-472b-bd42-582714ef1368\plugincontainer.exe','32');
DeleteFile('C:\Program Files (x86)\Common Files\48ed1695-d484-472b-bd42-582714ef1368\updater.exe','32');
DeleteFile('C:\Program Files (x86)\Zaxar\ZaxarGameBrowser.exe','32');
DeleteFile('C:\Users\Азат\AppData\Roaming\Browsers\exe.resworb.bat', '32');
DeleteFile('C:\ProgramData\btHpzjckDRbkY1.bat', '32');
DeleteFile('c:\program files (x86)\gmsd_ru_005010187\gmsd_ru_005010187.exe', '32');
DeleteFile('c:\program files (x86)\gmsd_ru_005010189\gmsd_ru_005010189.exe', '32');
DeleteFile('c:\program files (x86)\gmsd_ru_005010190\gmsd_ru_005010190.exe', '32');
DeleteFile('c:\program files (x86)\32444335-1448269821-5131-4756-80c16e41b41f\jnsice12.tmp', '32');
DeleteFile('c:\program files (x86)\32444335-1451042468-5131-4756-80c16e41b41f\knsl3691.tmp', '32');
DeleteFile('c:\users\738f~1\appdata\local\temp\nsj7832.tmp', '32');
DeleteFile('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\3\plugin.exe', '32');
DeleteFile('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\8\plugin.exe', '32');
DeleteFile('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\2\plugin.exe', '32');
DeleteFile('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\5\plugin.exe', '32');
DeleteFile('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\12\plugin.exe', '32');
DeleteFile('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\7\plugin.exe', '32');
DeleteFile('c:\programdata\48ed1695-d484-472b-bd42-582714ef1368\plugins\10\plugin.exe', '32');
DeleteFile('c:\programdata\tmp0x0x\protectwindowsmanager.exe', '32');
DeleteFile('c:\program files (x86)\sfk\ssfk.exe', '32');
DeleteFile('c:\users\Азат\appdata\local\gmsd_ru_005010189\upgmsd_ru_005010189.exe', '32');
DeleteFile('C:\Users\738F~1\AppData\Local\Temp\{04710452-F85C-4F66-AA8F-721D67F13932}.dll', '32');
DeleteFile('C:\Program Files (x86)\gmsd_ru_005010169\gmsd_ru_005010169.exe', '32');
DeleteFile('C:\Users\Азат\AppData\Local\gmsd_ru_005010187\upgmsd_ru_005010187.exe', '32');
DeleteFile('C:\Users\Азат\AppData\Local\gmsd_ru_005010177\upgmsd_ru_005010177.exe', '32');
DeleteFile('C:\Users\Азат\AppData\Local\gmsd_ru_005010190\upgmsd_ru_005010190.exe', '32');
DeleteFile('C:\Users\Азат\AppData\Local\coprofit\coprofit_stb.exe', '32');
DeleteService('WdMan');
DeleteService('Update Mgr MiddleRush');
DeleteService('Service Mgr MiddleRush');
DeleteService('hebimycy');
DeleteService('jyzyvomo');
DeleteService('SSFK');
DeleteService('WindowsMangerProtect');
DeleteFileMask('c:\programdata\tmp0x0x', '*', true);
DeleteFileMask('c:\program files (x86)\sfk', '*', true);
DeleteDirectory('c:\programdata\tmp0x0x');
DeleteDirectory('c:\program files (x86)\sfk');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ZaxarGameBrowser');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gmsd_ru_005010169');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gmsd_ru_005010187');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gmsd_ru_005010189');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gmsd_ru_005010190');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','upgmsd_ru_005010187.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','upgmsd_ru_005010177.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','upgmsd_ru_005010189.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','upgmsd_ru_005010190.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','coprofit');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\4ce69cd0246458d85a41bd1f1bd57da16bbdc46a','command');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
RebootWindows(true);
end.