Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
TerminateProcessByName('c:\program files\wproxy\winproxy\winproxy.exe');
QuarantineFile('c:\program files\wproxy\winproxy\winproxy.exe', '');
QuarantineFile('C:\ProgramData\behave-column\bin.exe', '');
QuarantineFile('C:\Users\Satelite\AppData\Local\Programs\4ac27e5d\d8ca182948.msi', '');
QuarantineFile('c:\windows\System32\evntagnt.dll', '');
QuarantineFile('C:\WINDOWS\SysWOW64\evntagnt.dll', '');
QuarantineFileF('c:\program files\wproxy', '*', true, '', 0 , 0);
QuarantineFileF('c:\programdata\behave-column', '*', true, '', 0 , 0);
QuarantineFileF('C:\ProgramData\CaphAnchor-daf74178-9f6b-4f6e-997d-d1b9561a2055', '*', true, '', 0 , 0);
DeleteFile('c:\users\satelite\appdata\local\programs\4ac27e5d\d8ca182948.msi', '64');
DeleteFile('c:\program files\wproxy\winproxy\winproxy.exe', '');
DeleteFile('C:\Program Files\WProxy\WinProxy\WinProxy.exe', '64');
DeleteFile('C:\ProgramData\behave-column\bin.exe', '64');
DeleteFile('C:\Users\Satelite\AppData\Local\Programs\4ac27e5d\d8ca182948.msi', '64');
DeleteFile('c:\windows\System32\evntagnt.dll', '');
DeleteFile('C:\WINDOWS\SysWOW64\evntagnt.dll', '64');
DeleteFileMask('c:\programdata\behave-column', '*', true);
DeleteFileMask('C:\ProgramData\CaphAnchor-daf74178-9f6b-4f6e-997d-d1b9561a2055', '*', true); DeleteFileMask('c:\program files\wproxy', '*', true);
DeleteDirectory('c:\program files\wproxy');
DeleteDirectory('c:\programdata\behave-column');
DeleteDirectory('C:\ProgramData\CaphAnchor-daf74178-9f6b-4f6e-997d-d1b9561a2055');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\EvntAgntSvc_c8f6a9\Parameters', 'ServiceDll', '64');
DeleteSchedulerTask('tabulate-S-1-5-21-4164730020-623376525-3126225281-1001');
DeleteSchedulerTask('WProxy\WinProxy');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 3, 3, true);
RebootWindows(true);
end.
Компьютер перезагрузится.