begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
TerminateProcessByName('C:\Program Files\DIMKK0KODO\Q7TZSZQPC.exe');
StopService('qobobuqu');
QuarantineFileF('c:\program files\dimkk0kodo', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFileF('c:\program files (x86)\prasufoderght', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFileF('c:\program files\spacesoundpro', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFileF('c:\users\макс\appdata\local\smartweb', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFileF('c:\users\макс\appdata\roaming\browsers', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFileF('c:\program files (x86)\anyprotectex', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFileF('c:\users\макс\appdata\roaming\mydesktop', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFileF('c:\users\макс\appdata\local\filesystemdriver', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFileF('c:\users\макс\appdata\local\fupdate', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFileF('c:\users\макс\appdata\local\hostinstaller', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFile('C:\Program Files\DIMKK0KODO\Q7TZSZQPC.exe', '');
QuarantineFile('c:\program files (x86)\prasufoderght\stmisstercultlg.dll', '');
QuarantineFile('C:\Users\Макс\AppData\Roaming\5F8A8E56-1434027400-3667-A7E2-AC220B4E947D\nsu7089.tmpfs', '');
QuarantineFile('C:\Users\4D88~1\AppData\Local\Temp\servicesc.exe', '');
QuarantineFile('C:\Users\Макс\AppData\Local\Temp\4OWOAX7V8\4OWOAX7V8.exe', '');
QuarantineFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe', '');
QuarantineFile('C:\Users\Макс\AppData\Local\SmartWeb\SmartWebHelper.exe', '');
QuarantineFile('C:\Users\Макс\AppData\Roaming\Browsers\exe.resworb.bat', '');
QuarantineFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe', '');
QuarantineFile('C:\Users\Макс\AppData\Roaming\MyDesktop\linkme.exe', '');
QuarantineFile('C:\Users\Макс\AppData\Local\FileSystemDriver\FileSystemDriver.exe', '');
QuarantineFile('C:\Users\Макс\AppData\Local\fupdate\fupdate.exe', '');
QuarantineFile('C:\Users\Макс\AppData\Local\Hostinstaller\975826238_monster.exe', '');
QuarantineFile('C:\Program Files\spacesoundpro\uninstaller.exe', '');
DeleteFile('C:\Windows\Tasks\APSnotifierPP1.job', '64');
DeleteFile('C:\Windows\Tasks\APSnotifierPP2.job', '64');
DeleteFile('C:\Windows\Tasks\APSnotifierPP3.job', '64');
DeleteFile('C:\Windows\Tasks\Windows desktop installer.job', '64');
ExecuteFile('schtasks.exe', '/delete /TN "APSnotifierPP1" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "APSnotifierPP2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "APSnotifierPP3" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "FileSystemDriver" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "fupdate" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "SmartWeb Upgrade Trigger Task" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Soft installer" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Windows desktop installer" /F', 0, 15000, true);
DeleteFile('C:\Program Files\DIMKK0KODO\Q7TZSZQPC.exe', '32');
DeleteFile('c:\program files (x86)\prasufoderght\stmisstercultlg.dll', '32');
DeleteFile('C:\Users\Макс\AppData\Roaming\5F8A8E56-1434027400-3667-A7E2-AC220B4E947D\nsu7089.tmpfs', '32');
DeleteFile('C:\Users\4D88~1\AppData\Local\Temp\servicesc.exe', '32');
DeleteFile('C:\Users\Макс\AppData\Local\Temp\4OWOAX7V8\4OWOAX7V8.exe', '32');
DeleteFile('C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe', '32');
DeleteFile('C:\Users\Макс\AppData\Local\SmartWeb\SmartWebHelper.exe', '32');
DeleteFile('C:\Users\Макс\AppData\Roaming\Browsers\exe.resworb.bat', '32');
DeleteFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe', '32');
DeleteFile('C:\Users\Макс\AppData\Roaming\MyDesktop\linkme.exe', '32');
DeleteFile('C:\Users\Макс\AppData\Local\FileSystemDriver\FileSystemDriver.exe', '32');
DeleteFile('C:\Users\Макс\AppData\Local\fupdate\fupdate.exe', '32');
DeleteFile('C:\Users\Макс\AppData\Local\Hostinstaller\975826238_monster.exe', '32');
DeleteFile('C:\Program Files\spacesoundpro\uninstaller.exe', '32');
DeleteFileMask('c:\program files\dimkk0kodo', '*', true);
DeleteFileMask('c:\program files (x86)\prasufoderght', '*', true);
DeleteFileMask('c:\program files\spacesoundpro', '*', true);
DeleteFileMask('c:\users\макс\appdata\local\smartweb', '*', true);
DeleteFileMask('c:\users\макс\appdata\roaming\browsers', '*', true);
DeleteFileMask('c:\program files (x86)\anyprotectex', '*', true);
DeleteFileMask('c:\users\макс\appdata\roaming\mydesktop', '*', true);
DeleteFileMask('c:\users\макс\appdata\local\filesystemdriver', '*', true);
DeleteFileMask('c:\users\макс\appdata\local\fupdate', '*', true);
DeleteFileMask('c:\users\макс\appdata\local\hostinstaller', '*', true);
DeleteDirectory('c:\program files\dimkk0kodo');
DeleteDirectory('c:\program files (x86)\prasufoderght');
DeleteDirectory('c:\program files\spacesoundpro');
DeleteDirectory('c:\users\макс\appdata\local\smartweb');
DeleteDirectory('c:\users\макс\appdata\roaming\browsers');
DeleteDirectory('c:\program files (x86)\anyprotectex');
DeleteDirectory('c:\users\макс\appdata\roaming\mydesktop');
DeleteDirectory('c:\users\макс\appdata\local\filesystemdriver');
DeleteDirectory('c:\users\макс\appdata\local\fupdate');
DeleteDirectory('c:\users\макс\appdata\local\hostinstaller');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','servicesc.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','fuvlezaook');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','02J1OUXI7V');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','HLNVLEYMW1');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Stecos\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','SpaceSoundPro');
DeleteService('qobobuqu');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
RebootWindows(true);
end.