Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'RocketDock' = '"%ProgramFiles%\Rocket Dock\RocketDock.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'IDMan' = '%ProgramFiles%\Internet Download Manager\idman.exe /onboot'
- %TEMP%\RarSFX0\IDM.exe
- %TEMP%\RarSFX0\reg32.exe
- %TEMP%\dup2patcher.dll
- %TEMP%\regpatch.reg
- %TEMP%\regpatch.reg
- %TEMP%\dup2patcher.dll
- %TEMP%\RarSFX0\IDM.exe
- %TEMP%\RarSFX0\reg32.exe
- %TEMP%\dup2patcher.dll
- %TEMP%\regpatch.reg
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%TEMP%\RarSFX0\reg32.exe' /Silent
- '%TEMP%\RarSFX0\IDM.exe' /Silent
- '%WINDIR%\regedit.exe' /s "%TEMP%\\regpatch.reg"