Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
TerminateProcessByName('c:\program files (x86)\gmsd_ru_005010189\gmsd_ru_005010189.exe');
TerminateProcessByName('c:\program files (x86)\gmsd_ru_005010192\gmsd_ru_005010192.exe');
TerminateProcessByName('c:\program files (x86)\gmsd_ru_005010193\gmsd_ru_005010193.exe');
TerminateProcessByName('c:\program files (x86)\gmsd_ru_005010195\gmsd_ru_005010195.exe');
TerminateProcessByName('c:\program files (x86)\03d410e2-1451304695-e311-9e80-201a06cafe87\knsn523f.tmpfs');
TerminateProcessByName('c:\program files (x86)\03d410e2-1450290400-e311-9e80-201a06cafe87\knsod378.tmpfs');
TerminateProcessByName('c:\users\user\appdata\local\temp\nsne6f8.tmp');
TerminateProcessByName('c:\users\user\appdata\local\temp\nszd12a.tmp');
TerminateProcessByName('c:\users\user\appdata\local\temp\nszd1c3.tmp');
TerminateProcessByName('c:\users\user\appdata\local\03d410e2-1451837651-e311-9e80-201a06cafe87\qnsdb687.tmp');
TerminateProcessByName('c:\users\user\appdata\local\smartweb\smartwebapp.exe');
TerminateProcessByName('c:\users\user\appdata\local\smartweb\smartwebhelper.exe');
TerminateProcessByName('c:\program files (x86)\sfk\ssfk.exe');
TerminateProcessByName('c:\users\user\appdata\local\gmsd_ru_005010195\upgmsd_ru_005010195.exe');
StopService('hurufiry');
StopService('lunywydy');
StopService('WindowsMangerProtect');
QuarantineFileF('C:\Users\user\AppData\Local\wjnjDfbTnYLYZOG\', '*p*', true, '', 0, 0);
QuarantineFileF('C:\ProgramData\DWdMD\', '*', true, '', 0, 0);
QuarantineFileF('c:\users\user\appdata\local\smartweb', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\program files (x86)\sfk', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFile('c:\program files (x86)\gmsd_ru_005010189\gmsd_ru_005010189.exe', '');
QuarantineFile('c:\program files (x86)\gmsd_ru_005010192\gmsd_ru_005010192.exe', '');
QuarantineFile('c:\program files (x86)\gmsd_ru_005010193\gmsd_ru_005010193.exe', '');
QuarantineFile('c:\program files (x86)\gmsd_ru_005010195\gmsd_ru_005010195.exe', '');
QuarantineFile('c:\program files (x86)\03d410e2-1451304695-e311-9e80-201a06cafe87\knsn523f.tmpfs', '');
QuarantineFile('c:\program files (x86)\03d410e2-1450290400-e311-9e80-201a06cafe87\knsod378.tmpfs', '');
QuarantineFile('c:\users\user\appdata\local\temp\nsne6f8.tmp', '');
QuarantineFile('c:\users\user\appdata\local\temp\nszd12a.tmp', '');
QuarantineFile('c:\users\user\appdata\local\temp\nszd1c3.tmp', '');
QuarantineFile('c:\users\user\appdata\local\03d410e2-1451837651-e311-9e80-201a06cafe87\qnsdb687.tmp', '');
QuarantineFile('c:\users\user\appdata\local\smartweb\smartwebapp.exe', '');
QuarantineFile('c:\users\user\appdata\local\smartweb\smartwebhelper.exe', '');
QuarantineFile('c:\program files (x86)\sfk\ssfk.exe', '');
QuarantineFile('c:\users\user\appdata\local\gmsd_ru_005010195\upgmsd_ru_005010195.exe', '');
QuarantineFile('C:\Users\user\AppData\Local\SmartWeb\swhk.dll', '');
QuarantineFile('C:\ProgramData\Tmp0x0x\ProtectWindowsManager.exe', '');
QuarantineFile('C:\Users\user\AppData\Local\gmsd_ru_005010192\upgmsd_ru_005010192.exe', '');
QuarantineFile('C:\Users\user\AppData\Local\wjnjDfbTnYLYZOG\nQDarLalSdPe1.bat', '');
QuarantineFile('C:\Users\user\appdata\local\gmsd_ru_005010179\upgmsd_ru_005010179.exe', '');
QuarantineFile('C:\Users\user\appdata\local\gmsd_ru_005010181\upgmsd_ru_005010181.exe', '');
QuarantineFile('C:\Users\user\appdata\local\smartweb\__u.exe', '');
QuarantineFile('C:\Users\user\appdata\roaming\daemon2.exe', '');
DeleteFile('c:\program files (x86)\gmsd_ru_005010189\gmsd_ru_005010189.exe', '32');
DeleteFile('c:\program files (x86)\gmsd_ru_005010192\gmsd_ru_005010192.exe', '32');
DeleteFile('c:\program files (x86)\gmsd_ru_005010193\gmsd_ru_005010193.exe', '32');
DeleteFile('c:\program files (x86)\gmsd_ru_005010195\gmsd_ru_005010195.exe', '32');
DeleteFile('c:\program files (x86)\03d410e2-1451304695-e311-9e80-201a06cafe87\knsn523f.tmpfs', '32');
DeleteFile('c:\program files (x86)\03d410e2-1450290400-e311-9e80-201a06cafe87\knsod378.tmpfs', '32');
DeleteFile('c:\users\user\appdata\local\temp\nsne6f8.tmp', '32');
DeleteFile('c:\users\user\appdata\local\temp\nszd12a.tmp', '32');
DeleteFile('c:\users\user\appdata\local\temp\nszd1c3.tmp', '32');
DeleteFile('c:\users\user\appdata\local\03d410e2-1451837651-e311-9e80-201a06cafe87\qnsdb687.tmp', '32');
DeleteFile('c:\users\user\appdata\local\smartweb\smartwebapp.exe', '32');
DeleteFile('c:\users\user\appdata\local\smartweb\smartwebhelper.exe', '32');
DeleteFile('c:\program files (x86)\sfk\ssfk.exe', '32');
DeleteFile('c:\users\user\appdata\local\gmsd_ru_005010195\upgmsd_ru_005010195.exe', '32');
DeleteFile('C:\Users\user\AppData\Local\SmartWeb\swhk.dll', '32');
DeleteFile('C:\ProgramData\Tmp0x0x\ProtectWindowsManager.exe', '32');
DeleteFile('C:\Users\user\AppData\Local\gmsd_ru_005010192\upgmsd_ru_005010192.exe', '32');
DeleteFile('C:\Users\user\AppData\Local\wjnjDfbTnYLYZOG\nQDarLalSdPe1.bat', '32');
DeleteFile('C:\Users\user\appdata\local\gmsd_ru_005010179\upgmsd_ru_005010179.exe', '32');
DeleteFile('C:\Users\user\appdata\local\gmsd_ru_005010181\upgmsd_ru_005010181.exe', '32');
DeleteFile('C:\Users\user\appdata\local\smartweb\__u.exe', '32');
DeleteFile('C:\Users\user\appdata\roaming\daemon2.exe', '32');
ExecuteFile('schtasks.exe', '/delete /TN "SmartWeb Upgrade Trigger Task" /F', 0, 15000, true);
DeleteService('hurufiry');
DeleteService('lunywydy');
DeleteService('WindowsMangerProtect');
DeleteFileMask('C:\Users\user\AppData\Local\wjnjDfbTnYLYZOG\', '*', true);
DeleteFileMask('C:\ProgramData\DWdMD\', '*', true);
DeleteFileMask('c:\users\user\appdata\local\smartweb', '*', true);
DeleteFileMask('c:\program files (x86)\sfk', '*', true);
DeleteDirectory('C:\Users\user\AppData\Local\wjnjDfbTnYLYZOG\');
DeleteDirectory('C:\ProgramData\DWdMD\');
DeleteDirectory('c:\users\user\appdata\local\smartweb');
DeleteDirectory('c:\program files (x86)\sfk');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'gmsd_ru_005010189');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'gmsd_ru_005010192');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'SmartWeb');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'gmsd_ru_005010193');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'gmsd_ru_005010195');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'upgmsd_ru_005010192.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\RunOnce', 'upgmsd_ru_005010195.exe');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.