begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
TerminateProcessByName('c:\windows\system32\1c.exe');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\1c.exe', '');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Info.hta', '');
QuarantineFile('C:\Users\slavatr\AppData\Roaming\1c.exe', '');
QuarantineFile('C:\Users\slavatr\AppData\Roaming\Info.hta', '');
QuarantineFile('C:\Users\slavatr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1c.exe', '');
QuarantineFile('C:\Users\slavatr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Info.hta', '');
QuarantineFile('C:\Users\кладовщик\AppData\Roaming\Info.hta', '');
QuarantineFile('c:\windows\system32\1c.exe', '');
QuarantineFile('C:\Windows\System32\Info.hta', '');
DeleteFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\1c.exe', '64');
DeleteFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Info.hta', '64');
DeleteFile('C:\Users\slavatr\AppData\Roaming\1c.exe', '32');
DeleteFile('C:\Users\slavatr\AppData\Roaming\1c.exe', '64');
DeleteFile('C:\Users\slavatr\AppData\Roaming\Info.hta', '64');
DeleteFile('C:\Users\slavatr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1c.exe', '64');
DeleteFile('C:\Users\slavatr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Info.hta', '64');
DeleteFile('C:\Users\кладовщик\AppData\Roaming\Info.hta', '64');
DeleteFile('c:\windows\system32\1c.exe', '32');
DeleteFile('C:\Windows\System32\Info.hta', '64');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', '1c.exe', '32');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', '1c.exe', '64');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'C:\Users\slavatr\AppData\Roaming\Info.hta', '64');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'C:\Users\кладовщик\AppData\Roaming\Info.hta', '64');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'C:\Windows\System32\Info.hta', '64');
ExecuteSysClean;
end.