Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- [<HKLM>\SOFTWARE\Classes\MSProgramGroup\Shell\Open\Command] '' = '<SYSTEM32>\grpconv.exe %1'
- '<SYSTEM32>\taskkill.exe' /f /t /im "idman.exe"
- %TEMP%\RarSFX0\IDM.inf
- %TEMP%\RarSFX0\IDM.cab
- %TEMP%\RarSFX0\PATCH.CMD
- %TEMP%\RarSFX0\Patch.exe
- %TEMP%\RarSFX0\Profile.exe
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
- '<SYSTEM32>\rundll32.exe' setupapi,InstallHinfSection DefaultInstall 132 %TEMP%\RarSFX0\IDM.inf
- '<SYSTEM32>\rundll32.exe' advpack.dll,LaunchINFSection %TEMP%\RarSFX0\IDM.inf,Install
- '<SYSTEM32>\cmd.exe' /Q /C taskkill /f /t /im "idman.exe"
- '<SYSTEM32>\regsvr32.exe' /u /S %ProgramFiles%\Internet Download Manager\downlWithIDM.dll
- '<SYSTEM32>\runonce.exe' -r
- '<SYSTEM32>\grpconv.exe' -o
- '<SYSTEM32>\regsvr32.exe' /u /S %ProgramFiles%\Internet Download Manager\idmfsa.dll