Техническая информация
- '<SYSTEM32>\taskkill.exe' /F /IM "IDMan.exe"
- %TEMP%\1.tmp\INST.cmd
- %TEMP%\1.tmp\IDMan.exe
- %TEMP%\1.tmp\Key.reg
- %TEMP%\1.tmp\Gracias.vbs
- %ProgramFiles%\Internet Download Manager
- ClassName: '' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\INST.cmd" "
- '%WINDIR%\regedit.exe' /S "Key.reg"
- '<SYSTEM32>\find.exe' /C /I "tonec.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "www.to##c.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "registeridm.com" <DRIVERS>\etc\hosts