Техническая информация
- [HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- [HKLM\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Run] 'IDMan' = '%ProgramFiles(x86)%\Internet Download Manager\IDMan.exe /onboot'
- [HKLM\System\CurrentControlSet\Services\IDMWFP] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\IDMWFP] 'ImagePath' = 'system32\DRIVERS\idmwfp.sys'
- 'IDMWFP' system32\DRIVERS\idmwfp.sys
- '<SYSTEM32>\taskkill.exe' /F /IM "IDM*"
- '<SYSTEM32>\taskkill.exe' /F /IM "IDMGrHlp.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "IEMonitor.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "IDMMsgHost.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "MediumILStart.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "IDMIntegrator64.exe"
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
- %ProgramFiles(x86)%\internet download manager\idman.原件
- %APPDATA%\idm\idmmzcc5\install.rdf
- %APPDATA%\idm\idmmzcc5\install.js
- %APPDATA%\idm\idmmzcc5\icon.png
- %APPDATA%\idm\idmmzcc5\chrome.manifest
- %APPDATA%\idm\idmmzcc5\meta-inf\zigbert.rsa
- %APPDATA%\idm\idmfc.dat
- %APPDATA%\idm\urlexclist.dat
- %APPDATA%\idm\defextmap.dat
- nul
- %ProgramFiles(x86)%\internet download manager\idmwfpaa.sys
- %ProgramFiles(x86)%\internet download manager\idmwfp64.sys
- %ProgramFiles(x86)%\internet download manager\idmwfp32.sys
- %ProgramFiles(x86)%\internet download manager\idmtdi64.sys
- %ProgramFiles(x86)%\internet download manager\idmtdi32.sys
- %ProgramFiles(x86)%\internet download manager\oldjsproxy.dll
- %ProgramFiles(x86)%\internet download manager\libssl.dll
- %ProgramFiles(x86)%\internet download manager\libcrypto.dll
- %ProgramFiles(x86)%\internet download manager\idmvs.dll
- %ProgramFiles(x86)%\internet download manager\idmvmprs64.dll
- %ProgramFiles(x86)%\internet download manager\idmvmprs.dll
- %ProgramFiles(x86)%\internet download manager\idmvconv.dll
- %ProgramFiles(x86)%\internet download manager\idmshellext64.dll
- %ProgramFiles(x86)%\internet download manager\idmshellext.dll
- %ProgramFiles(x86)%\internet download manager\idmnmcl.dll
- %ProgramFiles(x86)%\internet download manager\idmnetmon64.dll
- %APPDATA%\idm\idmmzcc5\chrome\idmmzcc.jar
- %APPDATA%\idm\idmmzcc5\components\idmhelper5.js
- %APPDATA%\idm\idmmzcc5\components\idmmzcc.dll
- %APPDATA%\idm\idmmzcc5\components\iidmhelper5.xpt
- %HOMEPATH%\desktop\internet download manager.lnk
- %ProgramFiles(x86)%\internet download manager\╧┬╖╜╬─╫╓.txt
- %ProgramFiles(x86)%\internet download manager\ias 0.8.cmd
- %WINDIR%\temp\udda614.tmp
- %WINDIR%\temp\udd9e27.tmp
- %APPDATA%\dmcache\settings.bak
- %WINDIR%\temp\udd961b.tmp
- %APPDATA%\idm\scheduler\s_1.dt
- %WINDIR%\temp\udd8dd0.tmp
- %WINDIR%\temp\udd85d4.tmp
- %WINDIR%\temp\udd7dc7.tmp
- <DRIVERS>\set782b.tmp
- %APPDATA%\idm\idmmzcc5\meta-inf\manifest.mf
- %APPDATA%\idm\idmmzcc5\meta-inf\zigbert.sf
- %ProgramFiles(x86)%\internet download manager\idmcchandler2_64.dll
- %APPDATA%\idm\idmmzcc5\components2\idmcchandler2_64.dll
- %ProgramFiles(x86)%\internet download manager\idmcchandler2.dll
- %APPDATA%\idm\idmmzcc5\components2\idmcchandler2.dll
- %APPDATA%\idm\idmmzcc5\components2\iidmmzcc.xpt
- %APPDATA%\idm\idmmzcc5\components2\iidmhelper.xpt
- %APPDATA%\idm\idmmzcc5\components2\idmmzcc64.dll
- %APPDATA%\idm\idmmzcc5\components2\idmmzcc.dll
- %APPDATA%\idm\idmmzcc5\components2\idmhelper.js
- %APPDATA%\idm\idmmzcc5\components12\idmmzcc64.dll
- %APPDATA%\idm\idmmzcc5\components12\idmmzcc.dll
- %APPDATA%\idm\idmmzcc5\components\iidmmzcc.xpt
- %APPDATA%\microsoft\windows\start menu\programs\internet download manager\internet download manager.lnk
- %ProgramFiles(x86)%\internet download manager\idmnetmon.dll
- %ProgramFiles(x86)%\internet download manager\idmmzcc7_64.dll
- %ProgramFiles(x86)%\internet download manager\idmmzcc7.dll
- %ProgramFiles(x86)%\internet download manager\idmwfp.inf
- %ProgramFiles(x86)%\internet download manager\idmtdi.inf
- %ProgramFiles(x86)%\internet download manager\idmftype.dat
- %ProgramFiles(x86)%\internet download manager\idmfc.dat
- %ProgramFiles(x86)%\internet download manager\idmgcext59.crx
- %ProgramFiles(x86)%\internet download manager\idmgcext.crx
- %ProgramFiles(x86)%\internet download manager\idmedgeext.crx
- %ProgramFiles(x86)%\internet download manager\idmwfp.cat
- %ProgramFiles(x86)%\internet download manager\idmtdi.cat
- %ProgramFiles(x86)%\internet download manager\idmantypeinfo.tlb
- %ProgramFiles(x86)%\internet download manager\languages\tips_chn.txt
- %ProgramFiles(x86)%\internet download manager\defexclist.txt
- %ProgramFiles(x86)%\internet download manager\iegetvl2.htm
- %ProgramFiles(x86)%\internet download manager\iegetvl.htm
- %ProgramFiles(x86)%\internet download manager\iegetall.htm
- %ProgramFiles(x86)%\internet download manager\ieext.htm
- %ProgramFiles(x86)%\internet download manager\ias.cmd
- %ProgramFiles(x86)%\internet download manager\!)卸载.cmd
- %ProgramFiles(x86)%\internet download manager\idmmzcc3.xpi
- %ProgramFiles(x86)%\internet download manager\idmmzcc2.xpi
- %ProgramFiles(x86)%\internet download manager\idmmzcc.xpi
- %ProgramFiles(x86)%\internet download manager\idmmzcc-palemoon.xpi
- %ProgramFiles(x86)%\internet download manager\toolbar\faenza_small_normal.bmp
- %ProgramFiles(x86)%\internet download manager\toolbar\faenza_small_hot.bmp
- %ProgramFiles(x86)%\internet download manager\toolbar\faenza_small_disable.bmp
- %ProgramFiles(x86)%\internet download manager\idmmsghost.json
- %ProgramFiles(x86)%\internet download manager\idmmsghostmoz.json
- %ProgramFiles(x86)%\internet download manager\languages\idm_chn2.lng
- %ProgramFiles(x86)%\internet download manager\languages\inst_chn.lng
- %ProgramFiles(x86)%\internet download manager\idmindex.dll
- %ProgramFiles(x86)%\internet download manager\idmiecc64.dll
- %ProgramFiles(x86)%\internet download manager\idmiecc.dll
- %ProgramFiles(x86)%\internet download manager\idmgetall64.dll
- %ProgramFiles(x86)%\internet download manager\idmgetall.dll
- %ProgramFiles(x86)%\internet download manager\idmftype64.dll
- %ProgramFiles(x86)%\internet download manager\idmftype.dll
- %ProgramFiles(x86)%\internet download manager\idmfsa.dll
- %ProgramFiles(x86)%\internet download manager\idmcchandler7_64.dll
- %ProgramFiles(x86)%\internet download manager\idmcchandler7.dll
- %ProgramFiles(x86)%\internet download manager\idmbrbtn64.dll
- %ProgramFiles(x86)%\internet download manager\idmbrbtn.dll
- %ProgramFiles(x86)%\internet download manager\downlwithidm.dll
- %ProgramFiles(x86)%\internet download manager\downlwithidm64.dll
- %ProgramFiles(x86)%\internet download manager\uninstall.exe
- %ProgramFiles(x86)%\internet download manager\mediumilstart.exe
- %ProgramFiles(x86)%\internet download manager\iemonitor.exe
- %ProgramFiles(x86)%\internet download manager\idmmsghost.exe
- %ProgramFiles(x86)%\internet download manager\idmintegrator64.exe
- %ProgramFiles(x86)%\internet download manager\idmgrhlp.exe
- %ProgramFiles(x86)%\internet download manager\idmbroker.exe
- %ProgramFiles(x86)%\internet download manager\idman.exe
- %ProgramFiles(x86)%\internet download manager\!)绿化.cmd
- %ProgramFiles(x86)%\internet download manager\toolbar\faenza.tbi
- %ProgramFiles(x86)%\internet download manager\idmopext.nex
- %ProgramFiles(x86)%\internet download manager\languages\template.lng
- %ProgramFiles(x86)%\internet download manager\idmmkb.dll
- %APPDATA%\microsoft\windows\start menu\programs\internet download manager\uninstall idm.lnk
- %WINDIR%\temp\udd7dc7.tmp
- %WINDIR%\temp\udd85d4.tmp
- %WINDIR%\temp\udd8dd0.tmp
- %WINDIR%\temp\udd961b.tmp
- %WINDIR%\temp\udd9e27.tmp
- %WINDIR%\temp\udda614.tmp
- %ProgramFiles(x86)%\internet download manager\ias.cmd
- %ProgramFiles(x86)%\internet download manager\╧┬╖╜╬─╫╓.txt
- <DRIVERS>\set782b.tmp в <DRIVERS>\idmwfp.sys
- %LOCALAPPDATA%\microsoft\windows\explorer\explorerstartuplog_runonce.etl
- %ProgramFiles(x86)%\internet download manager\ias.cmd
- %ProgramFiles(x86)%\internet download manager\ias 0.8.cmd
- DNS ASK te##.#####netdownloadmanager.com
- DNS ASK se####.###ernetdownloadmanager.com
- DNS ASK in######downloadmanager.com
- DNS ASK mi#####.##ternetdownloadmanager.com
- DNS ASK re###teridm.com
- ClassName: '' WindowName: ''
- '%ProgramFiles(x86)%\internet download manager\idmbroker.exe' -RegServer
- '%ProgramFiles(x86)%\internet download manager\idman.exe' /onsilentsetup /s /q
- '%ProgramFiles(x86)%\internet download manager\uninstall.exe' -instdriv
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles(x86)%\Internet Download Manager\!)绿化.cmd" "
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Internet Download Manager" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\DownloadManager" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Download Manager" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Internet Download Manager" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "MData"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "LName"
- '<SYSTEM32>\reg.exe' delete "HKCU" /f /v "Therad"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "FName"
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Download Manager" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "Serial"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "tvfrdt"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "radxcnt"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "LstCheck"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "ptrk_scdt"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "LastCheckQU"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "CheckUpdtVM"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "Email"
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\DownloadManager" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "scansk"
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\DownloadManager" /f
- '<SYSTEM32>\reg.exe' delete "HKCU" /f /v "Model"
- '<SYSTEM32>\reg.exe' delete "HKCU" /f /v "MData"
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM" /f /ve
- '<SYSTEM32>\reg.exe' delete "HKLM" /f /v "MData"
- '<SYSTEM32>\reg.exe' delete "HKLM" /f /v "Model"
- '<SYSTEM32>\reg.exe' delete "HKLM" /f /v "Therad"
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU" /f /ve
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Download Manager" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "IDMan"
- '<SYSTEM32>\rundll32.exe' SETUPAPI.DLL,InstallHinfSection DefaultInstall 128 %ProgramFiles(x86)%\Internet Download Manager\idmwfp.inf (со скрытым окном)
- '<SYSTEM32>\runonce.exe' -r
- '<SYSTEM32>\grpconv.exe' -o
- '%WINDIR%\syswow64\net.exe' start IDMWFP (со скрытым окном)
- '%WINDIR%\syswow64\net1.exe' start IDMWFP
- '<SYSTEM32>\findstr.exe' /c:"mshta vbscript:createobject" "IAS 0.8.cmd"
- '<SYSTEM32>\cmd.exe' /c findstr /n ".*" "IAS.cmd"
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\Internet Download Manager\IDMShellExt64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\Internet Download Manager\IDMShellExt64.dll"
- '<SYSTEM32>\findstr.exe' /n ".*" "IAS.cmd"
- '<SYSTEM32>\find.exe' /n /v ""
- '<SYSTEM32>\mshta.exe' VBScript:Execute("Set a=CreateObject(""WScript.Shell""):Set b=a.CreateShortcut(a.SpecialFolders(""Desktop"") & ""\Internet Download Manager.lnk""):b.TargetPath=""C:\PROGRA~2\INTERN~2\IDMan.exe"...
- '<SYSTEM32>\find.exe' /i " 6"
- '<SYSTEM32>\find.exe' /i " 5"
- '<SYSTEM32>\cmd.exe' /c reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" /v "Programs"
- '<SYSTEM32>\reg.exe' query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" /v "Programs"
- '<SYSTEM32>\mshta.exe' VBScript:Execute("Set a=CreateObject(""WScript.Shell""):Set b=a.CreateShortcut(a.SpecialFolders(""Programs"") & ""\Internet Download Manager\Internet Download Manager.lnk""):b.TargetPath=""%Pro...
- '<SYSTEM32>\findstr.exe' /c:"IDMan.cra && ren" "IAS.cmd"
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\find.exe /n /v ""<IAS.cmd
- '<SYSTEM32>\regsvr32.exe' /s downlWithIDM64.dll
- '<SYSTEM32>\regsvr32.exe' /s IDMIECC64.dll
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "IDMan" /reg:32
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "FName" /d "Tonec"
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "LName" /d "Inc."
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "Email" /d "info@tonec.com"
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "Serial" /d "AV6L9-VPYMI-06HZY-E4D8Y"
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "AdvIntDriverEnabled2" /t REG_DWORD /d "1"
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Internet Download Manager" /f /v "FName" /d "Tonec" /reg:32
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Internet Download Manager" /f /v "LName" /d "Inc." /reg:32
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Internet Download Manager" /f /v "Email" /d "info@tonec.com" /reg:32
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Internet Download Manager" /f /v "Serial" /d "AV6L9-VPYMI-06HZY-E4D8Y" /reg:32
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Internet Download Manager" /f /v "AdvIntDriverEnabled2" /t REG_DWORD /d "1" /reg:32
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "LanguageID" /t REG_DWORD /d "2052"
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "ToolbarStyle" /d "Faenza"
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "TipStartUp" /t REG_DWORD /d "1"
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "LaunchOnStart" /t REG_DWORD /d "0"
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\DownloadManager" /f /v "Extensions" /d "3GP 7Z AAC ACE AIF ARJ ASF AVI BIN BZ2 EXE GZ GZIP IMG ISO LZH M4A M4V MKV MOV MP3 MP4 MPA MPE MPEG MPG MSI MSU OGG OGV PDF PLJ PPS PP...
- '<SYSTEM32>\regsvr32.exe' /s IDMShellExt64.dll
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\DownloadManager" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "IDMan"
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Download Manager" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{D0FB58BB-2C07-492F-8BD0-A587E4874B4E}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f /reg:32
- '<SYSTEM32>\cmd.exe' /c ver
- '<SYSTEM32>\find.exe' "5."
- '<SYSTEM32>\reg.exe' QUERY "HKU\S-1-5-19"
- '<SYSTEM32>\cmd.exe' /c wmic userAccount where "Name='user'" get SID /value
- '<SYSTEM32>\wbem\wmic.exe' userAccount where "Name='user'" get SID /value
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "MData"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "LName"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "FName"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "Email"
- '<SYSTEM32>\cmd.exe' /S /D /c" ver"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "Serial"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "tvfrdt"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "radxcnt"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "LstCheck"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "ptrk_scdt"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "LastCheckQU"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "CheckUpdtVM"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "scansk"
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{D0FB58BB-2C07-492F-8BD0-A587E4874B4E}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{0F947660-8606-420A-BAC6-51B84DD22A47}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{0F947660-8606-420A-BAC6-51B84DD22A47}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{C950922F-897A-4E13-BA38-66C8AF2E0BF7}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{C950922F-897A-4E13-BA38-66C8AF2E0BF7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}" /f
- '<SYSTEM32>\regsvr32.exe' /s IDMGetAll64.dll
- '<SYSTEM32>\mshta.exe' VBScript:Execute("Set a=CreateObject(""WScript.Shell""):Set b=a.CreateShortcut(a.SpecialFolders(""Programs"") & ""\Internet Download Manager\Uninstall IDM.lnk""):b.TargetPath=""%ProgramFiles(x8...
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{84797876-C678-1780-A556-0CD06786780F}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{84797876-C678-1780-A556-0CD06786780F}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{84797876-C678-1780-A556-0CD06786780F}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{84797876-C678-1780-A556-0CD06786780F}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}" /f
- '<SYSTEM32>\timeout.exe' /t 0