begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
QuarantineFileF('c:\users\crisord\appdata\local\mail.ru\gamecenter', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFileF('c:\users\crisord\appdata\local\svshost', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFile('c:\users\crisord\appdata\local\temp\878.tmp.exe', '');
QuarantineFile('c:\users\crisord\appdata\local\temp\e.exe', '');
QuarantineFile('C:\Users\crisord\AppData\Local\Mail.Ru\GameCenter\GameCenter@Mail.Ru.exe', '');
QuarantineFile('C:\Users\crisord\AppData\Local\svshost\svshost.exe', '');
ExecuteFile('schtasks.exe', '/delete /TN "svshost" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "wd-client" /F', 0, 15000, true);
DeleteFile('c:\users\crisord\appdata\local\temp\878.tmp.exe', '32');
DeleteFile('c:\users\crisord\appdata\local\temp\e.exe', '32');
DeleteFile('C:\Users\crisord\AppData\Local\Mail.Ru\GameCenter\GameCenter@Mail.Ru.exe', '32');
DeleteFile('C:\Users\crisord\AppData\Local\svshost\svshost.exe', '32');
DeleteFileMask('c:\users\crisord\appdata\local\mail.ru\gamecenter', '*', true);
DeleteFileMask('c:\users\crisord\appdata\local\svshost', '*', true);
DeleteDirectory('c:\users\crisord\appdata\local\mail.ru\gamecenter');
DeleteDirectory('c:\users\crisord\appdata\local\svshost');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','dsfabzvime');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\RunOnce','xdcummcgjo');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GameCenterMailRu','command');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
RebootWindows(true);
end.