Код:
begin
TerminateProcessByName('C:\ProgramData\System32\Logs\ShellExperienceHost.exe');
TerminateProcessByName('C:\ProgramData\WindowsTask\MicrosoftShellHost.exe');
TerminateProcessByName('c:\windows\ehome\mediacenter\wmserver.exe');
QuarantineFile('C:\Program Files\RDP Wrapper\rdpwrap.dll', '');
QuarantineFile('C:\ProgramData\Microsoft Services\lsm.exe', '');
QuarantineFile('C:\ProgramData\System32\Logs\ShellExperienceHost.exe', '');
QuarantineFile('C:\ProgramData\WindowsTask\MicrosoftShellHost.exe', '');
QuarantineFile('C:\Users\User\AppData\Local\UpdaterProBrowser\UpdaterProBrowser.exe', '');
QuarantineFile('c:\windows\ehome\mediacenter\wmserver.exe', '');
QuarantineFile('C:\Windows\Logs\WMIADAP.vbs', '');
QuarantineFile('C:\Windows\Media\Update\updatem.exe', '');
QuarantineFile('C:\Windows\Microsoft.NET\assembly\regasm.exe', '');
QuarantineFileF('c:\programdata\microsoft services', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 , 0);
DeleteFile('C:\Program Files\RDP Wrapper\rdpwrap.dll', '32');
DeleteFile('C:\ProgramData\Microsoft Services\lsm.exe', '');
DeleteFile('C:\ProgramData\System32\Logs\ShellExperienceHost.exe', '');
DeleteFile('C:\ProgramData\System32\Logs\ShellExperienceHost.exe', '32');
DeleteFile('C:\ProgramData\WindowsTask\MicrosoftShellHost.exe', '');
DeleteFile('C:\Users\User\AppData\Local\UpdaterProBrowser\UpdaterProBrowser.exe', '');
DeleteFile('c:\windows\ehome\mediacenter\wmserver.exe', '');
DeleteFile('C:\Windows\Logs\WMIADAP.vbs', '');
DeleteFile('C:\Windows\Media\Update\updatem.exe', '');
DeleteFile('C:\Windows\Microsoft.NET\assembly\regasm.exe', '');
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft LocalManager" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Diagnosis\WinLogService" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Media Center\MediaCenter" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\Multimedia\UpdateMedia" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\SoftwareProtectionPlatform\SoftwareProtectionPTask" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "UpdaterProBrowser" /F', 0, 15000, true);
DeleteFileMask('c:\program files\rdp wrapper', '*', true);
DeleteFileMask('c:\programdata\microsoft services', '*', true);
DeleteFileMask('c:\programdata\windowstask', '*', true);
DeleteFileMask('c:\users\user\appdata\local\updaterprobrowser', '*', true);
DeleteDirectory('c:\program files\rdp wrapper');
DeleteDirectory('c:\programdata\microsoft services');
DeleteDirectory('c:\programdata\windowstask');
DeleteDirectory('c:\users\user\appdata\local\updaterprobrowser');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\TermService\Parameters', 'ServiceDll');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.