Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRun' = '00000000'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'DisallowRun' = '00000000'
- %TEMP%\rarsfx0\idm_6.4x_crack_v20.4.exe
- %TEMP%\idm_updt.vbs
- %TEMP%\crk_updt.vbs
- %ProgramFiles%\winrar\rarreg.key
- %APPDATA%\winrar\rarreg.key
- 'id#.0dy.ir':443
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a4##############
- 'id#.0dy.ir':443
- DNS ASK id#.0dy.ir
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\rarsfx0\idm_6.4x_crack_v20.4.exe'
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\\CRK_UPDT.vbs" "https://idm.0dy.ir/" "Version" "Download_URL" "20.4" "Crack" "%ProgramFiles%\Mozilla Firefox\firefox.exe" silent