Technical Information
- [HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- [HKLM\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Run] 'IDMan' = '%ProgramFiles(x86)%\Internet Download Manager\IDMan.exe /onboot'
- [HKLM\System\CurrentControlSet\Services\IDMWFP] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\IDMWFP] 'ImagePath' = 'system32\DRIVERS\idmwfp.sys'
- 'IDMWFP' system32\DRIVERS\idmwfp.sys
- '<SYSTEM32>\taskkill.exe' /F /IM "IDM*"
- '<SYSTEM32>\taskkill.exe' /F /IM "IDMGrHlp.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "IEMonitor.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "IDMMsgHost.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "MediumILStart.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "IDMIntegrator64.exe"
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
- %ProgramFiles(x86)%\internet download manager\idman.原件
- %APPDATA%\idm\idmmzcc5\install.rdf
- %APPDATA%\idm\idmmzcc5\install.js
- %APPDATA%\idm\idmmzcc5\icon.png
- %APPDATA%\idm\idmmzcc5\chrome.manifest
- %APPDATA%\idm\idmmzcc5\meta-inf\zigbert.rsa
- %APPDATA%\idm\idmfc.dat
- %APPDATA%\idm\urlexclist.dat
- %APPDATA%\idm\defextmap.dat
- nul
- %ProgramFiles(x86)%\internet download manager\idmwfpaa.sys
- %ProgramFiles(x86)%\internet download manager\idmwfp64.sys
- %ProgramFiles(x86)%\internet download manager\idmwfp32.sys
- %ProgramFiles(x86)%\internet download manager\idmtdi64.sys
- %ProgramFiles(x86)%\internet download manager\idmtdi32.sys
- %ProgramFiles(x86)%\internet download manager\oldjsproxy.dll
- %ProgramFiles(x86)%\internet download manager\libssl.dll
- %ProgramFiles(x86)%\internet download manager\libcrypto.dll
- %ProgramFiles(x86)%\internet download manager\idmvs.dll
- %ProgramFiles(x86)%\internet download manager\idmvmprs64.dll
- %ProgramFiles(x86)%\internet download manager\idmvmprs.dll
- %ProgramFiles(x86)%\internet download manager\idmvconv.dll
- %ProgramFiles(x86)%\internet download manager\idmshellext64.dll
- %ProgramFiles(x86)%\internet download manager\idmshellext.dll
- %ProgramFiles(x86)%\internet download manager\idmnmcl.dll
- %ProgramFiles(x86)%\internet download manager\idmnetmon64.dll
- %APPDATA%\idm\idmmzcc5\chrome\idmmzcc.jar
- %APPDATA%\idm\idmmzcc5\components\idmhelper5.js
- %APPDATA%\idm\idmmzcc5\components\idmmzcc.dll
- %APPDATA%\idm\idmmzcc5\components\iidmhelper5.xpt
- %HOMEPATH%\desktop\internet download manager.lnk
- %ProgramFiles(x86)%\internet download manager\╧┬╖╜╬─╫╓.txt
- %ProgramFiles(x86)%\internet download manager\ias 0.8.cmd
- %WINDIR%\temp\udda614.tmp
- %WINDIR%\temp\udd9e27.tmp
- %APPDATA%\dmcache\settings.bak
- %WINDIR%\temp\udd961b.tmp
- %APPDATA%\idm\scheduler\s_1.dt
- %WINDIR%\temp\udd8dd0.tmp
- %WINDIR%\temp\udd85d4.tmp
- %WINDIR%\temp\udd7dc7.tmp
- <DRIVERS>\set782b.tmp
- %APPDATA%\idm\idmmzcc5\meta-inf\manifest.mf
- %APPDATA%\idm\idmmzcc5\meta-inf\zigbert.sf
- %ProgramFiles(x86)%\internet download manager\idmcchandler2_64.dll
- %APPDATA%\idm\idmmzcc5\components2\idmcchandler2_64.dll
- %ProgramFiles(x86)%\internet download manager\idmcchandler2.dll
- %APPDATA%\idm\idmmzcc5\components2\idmcchandler2.dll
- %APPDATA%\idm\idmmzcc5\components2\iidmmzcc.xpt
- %APPDATA%\idm\idmmzcc5\components2\iidmhelper.xpt
- %APPDATA%\idm\idmmzcc5\components2\idmmzcc64.dll
- %APPDATA%\idm\idmmzcc5\components2\idmmzcc.dll
- %APPDATA%\idm\idmmzcc5\components2\idmhelper.js
- %APPDATA%\idm\idmmzcc5\components12\idmmzcc64.dll
- %APPDATA%\idm\idmmzcc5\components12\idmmzcc.dll
- %APPDATA%\idm\idmmzcc5\components\iidmmzcc.xpt
- %APPDATA%\microsoft\windows\start menu\programs\internet download manager\internet download manager.lnk
- %ProgramFiles(x86)%\internet download manager\idmnetmon.dll
- %ProgramFiles(x86)%\internet download manager\idmmzcc7_64.dll
- %ProgramFiles(x86)%\internet download manager\idmmzcc7.dll
- %ProgramFiles(x86)%\internet download manager\idmwfp.inf
- %ProgramFiles(x86)%\internet download manager\idmtdi.inf
- %ProgramFiles(x86)%\internet download manager\idmftype.dat
- %ProgramFiles(x86)%\internet download manager\idmfc.dat
- %ProgramFiles(x86)%\internet download manager\idmgcext59.crx
- %ProgramFiles(x86)%\internet download manager\idmgcext.crx
- %ProgramFiles(x86)%\internet download manager\idmedgeext.crx
- %ProgramFiles(x86)%\internet download manager\idmwfp.cat
- %ProgramFiles(x86)%\internet download manager\idmtdi.cat
- %ProgramFiles(x86)%\internet download manager\idmantypeinfo.tlb
- %ProgramFiles(x86)%\internet download manager\languages\tips_chn.txt
- %ProgramFiles(x86)%\internet download manager\defexclist.txt
- %ProgramFiles(x86)%\internet download manager\iegetvl2.htm
- %ProgramFiles(x86)%\internet download manager\iegetvl.htm
- %ProgramFiles(x86)%\internet download manager\iegetall.htm
- %ProgramFiles(x86)%\internet download manager\ieext.htm
- %ProgramFiles(x86)%\internet download manager\ias.cmd
- %ProgramFiles(x86)%\internet download manager\!)卸载.cmd
- %ProgramFiles(x86)%\internet download manager\idmmzcc3.xpi
- %ProgramFiles(x86)%\internet download manager\idmmzcc2.xpi
- %ProgramFiles(x86)%\internet download manager\idmmzcc.xpi
- %ProgramFiles(x86)%\internet download manager\idmmzcc-palemoon.xpi
- %ProgramFiles(x86)%\internet download manager\toolbar\faenza_small_normal.bmp
- %ProgramFiles(x86)%\internet download manager\toolbar\faenza_small_hot.bmp
- %ProgramFiles(x86)%\internet download manager\toolbar\faenza_small_disable.bmp
- %ProgramFiles(x86)%\internet download manager\idmmsghost.json
- %ProgramFiles(x86)%\internet download manager\idmmsghostmoz.json
- %ProgramFiles(x86)%\internet download manager\languages\idm_chn2.lng
- %ProgramFiles(x86)%\internet download manager\languages\inst_chn.lng
- %ProgramFiles(x86)%\internet download manager\idmindex.dll
- %ProgramFiles(x86)%\internet download manager\idmiecc64.dll
- %ProgramFiles(x86)%\internet download manager\idmiecc.dll
- %ProgramFiles(x86)%\internet download manager\idmgetall64.dll
- %ProgramFiles(x86)%\internet download manager\idmgetall.dll
- %ProgramFiles(x86)%\internet download manager\idmftype64.dll
- %ProgramFiles(x86)%\internet download manager\idmftype.dll
- %ProgramFiles(x86)%\internet download manager\idmfsa.dll
- %ProgramFiles(x86)%\internet download manager\idmcchandler7_64.dll
- %ProgramFiles(x86)%\internet download manager\idmcchandler7.dll
- %ProgramFiles(x86)%\internet download manager\idmbrbtn64.dll
- %ProgramFiles(x86)%\internet download manager\idmbrbtn.dll
- %ProgramFiles(x86)%\internet download manager\downlwithidm.dll
- %ProgramFiles(x86)%\internet download manager\downlwithidm64.dll
- %ProgramFiles(x86)%\internet download manager\uninstall.exe
- %ProgramFiles(x86)%\internet download manager\mediumilstart.exe
- %ProgramFiles(x86)%\internet download manager\iemonitor.exe
- %ProgramFiles(x86)%\internet download manager\idmmsghost.exe
- %ProgramFiles(x86)%\internet download manager\idmintegrator64.exe
- %ProgramFiles(x86)%\internet download manager\idmgrhlp.exe
- %ProgramFiles(x86)%\internet download manager\idmbroker.exe
- %ProgramFiles(x86)%\internet download manager\idman.exe
- %ProgramFiles(x86)%\internet download manager\!)绿化.cmd
- %ProgramFiles(x86)%\internet download manager\toolbar\faenza.tbi
- %ProgramFiles(x86)%\internet download manager\idmopext.nex
- %ProgramFiles(x86)%\internet download manager\languages\template.lng
- %ProgramFiles(x86)%\internet download manager\idmmkb.dll
- %APPDATA%\microsoft\windows\start menu\programs\internet download manager\uninstall idm.lnk
- %WINDIR%\temp\udd7dc7.tmp
- %WINDIR%\temp\udd85d4.tmp
- %WINDIR%\temp\udd8dd0.tmp
- %WINDIR%\temp\udd961b.tmp
- %WINDIR%\temp\udd9e27.tmp
- %WINDIR%\temp\udda614.tmp
- %ProgramFiles(x86)%\internet download manager\ias.cmd
- %ProgramFiles(x86)%\internet download manager\╧┬╖╜╬─╫╓.txt
- from <DRIVERS>\set782b.tmp to <DRIVERS>\idmwfp.sys
- %LOCALAPPDATA%\microsoft\windows\explorer\explorerstartuplog_runonce.etl
- %ProgramFiles(x86)%\internet download manager\ias.cmd
- %ProgramFiles(x86)%\internet download manager\ias 0.8.cmd
- DNS ASK te##.#####netdownloadmanager.com
- DNS ASK se####.###ernetdownloadmanager.com
- DNS ASK in######downloadmanager.com
- DNS ASK mi#####.##ternetdownloadmanager.com
- DNS ASK re###teridm.com
- ClassName: '' WindowName: ''
- '%ProgramFiles(x86)%\internet download manager\idmbroker.exe' -RegServer
- '%ProgramFiles(x86)%\internet download manager\idman.exe' /onsilentsetup /s /q
- '%ProgramFiles(x86)%\internet download manager\uninstall.exe' -instdriv
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles(x86)%\Internet Download Manager\!)绿化.cmd" "
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Internet Download Manager" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\DownloadManager" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Download Manager" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Internet Download Manager" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "MData"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "LName"
- '<SYSTEM32>\reg.exe' delete "HKCU" /f /v "Therad"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "FName"
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Download Manager" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "Serial"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "tvfrdt"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "radxcnt"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "LstCheck"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "ptrk_scdt"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "LastCheckQU"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "CheckUpdtVM"
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "Email"
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\DownloadManager" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\DownloadManager" /f /v "scansk"
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\DownloadManager" /f
- '<SYSTEM32>\reg.exe' delete "HKCU" /f /v "Model"
- '<SYSTEM32>\reg.exe' delete "HKCU" /f /v "MData"
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM" /f /ve
- '<SYSTEM32>\reg.exe' delete "HKLM" /f /v "MData"
- '<SYSTEM32>\reg.exe' delete "HKLM" /f /v "Model"
- '<SYSTEM32>\reg.exe' delete "HKLM" /f /v "Therad"
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU" /f /ve
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Download Manager" /f
- '<SYSTEM32>\regsvr32.exe' /s IDMIECC64.dll
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "IDMan"
- '<SYSTEM32>\runonce.exe' -r
- '<SYSTEM32>\grpconv.exe' -o
- '%WINDIR%\syswow64\net.exe' start IDMWFP
- '%WINDIR%\syswow64\net1.exe' start IDMWFP
- '<SYSTEM32>\findstr.exe' /c:"mshta vbscript:createobject" "IAS 0.8.cmd"
- '<SYSTEM32>\cmd.exe' /c findstr /n ".*" "IAS.cmd"
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\Internet Download Manager\IDMShellExt64.dll"
- '<SYSTEM32>\findstr.exe' /n ".*" "IAS.cmd"
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\find.exe /n /v ""<IAS.cmd
- '<SYSTEM32>\find.exe' /n /v ""
- '<SYSTEM32>\mshta.exe' VBScript:Execute("Set a=CreateObject(""WScript.Shell""):Set b=a.CreateShortcut(a.SpecialFolders(""Desktop"") & ""\Internet Download Manager.lnk""):b.TargetPath=""C:\PROGRA~2\INTERN~2\IDMan.exe"...
- '<SYSTEM32>\find.exe' /i " 6"
- '<SYSTEM32>\find.exe' /i " 5"
- '<SYSTEM32>\cmd.exe' /c reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" /v "Programs"
- '<SYSTEM32>\reg.exe' query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" /v "Programs"
- '<SYSTEM32>\mshta.exe' VBScript:Execute("Set a=CreateObject(""WScript.Shell""):Set b=a.CreateShortcut(a.SpecialFolders(""Programs"") & ""\Internet Download Manager\Internet Download Manager.lnk""):b.TargetPath=""%Pro...
- '<SYSTEM32>\findstr.exe' /c:"IDMan.cra && ren" "IAS.cmd"
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\DownloadManager" /f /reg:32
- '<SYSTEM32>\mshta.exe' VBScript:Execute("Set a=CreateObject(""WScript.Shell""):Set b=a.CreateShortcut(a.SpecialFolders(""Programs"") & ""\Internet Download Manager\Uninstall IDM.lnk""):b.TargetPath=""%ProgramFiles(x8...
- '<SYSTEM32>\rundll32.exe' SETUPAPI.DLL,InstallHinfSection DefaultInstall 128 %ProgramFiles(x86)%\Internet Download Manager\idmwfp.inf
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\Internet Download Manager\IDMShellExt64.dll"
- '<SYSTEM32>\regsvr32.exe' /s IDMGetAll64.dll
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "IDMan" /reg:32
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "FName" /d "Tonec"
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "LName" /d "Inc."
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "Email" /d "info@tonec.com"
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "Serial" /d "AV6L9-VPYMI-06HZY-E4D8Y"
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "AdvIntDriverEnabled2" /t REG_DWORD /d "1"
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Internet Download Manager" /f /v "FName" /d "Tonec" /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "IDMan"
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Internet Download Manager" /f /v "LName" /d "Inc." /reg:32
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Internet Download Manager" /f /v "Serial" /d "AV6L9-VPYMI-06HZY-E4D8Y" /reg:32
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Internet Download Manager" /f /v "AdvIntDriverEnabled2" /t REG_DWORD /d "1" /reg:32
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "LanguageID" /t REG_DWORD /d "2052"
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "ToolbarStyle" /d "Faenza"
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "TipStartUp" /t REG_DWORD /d "1"
- '<SYSTEM32>\reg.exe' add "HKCU\Software\DownloadManager" /f /v "LaunchOnStart" /t REG_DWORD /d "0"
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\DownloadManager" /f /v "Extensions" /d "3GP 7Z AAC ACE AIF ARJ ASF AVI BIN BZ2 EXE GZ GZIP IMG ISO LZH M4A M4V MKV MOV MP3 MP4 MPA MPE MPEG MPG MSI MSU OGG OGV PDF PLJ PPS PP...
- '<SYSTEM32>\regsvr32.exe' /s IDMShellExt64.dll
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Internet Download Manager" /f /v "Email" /d "info@tonec.com" /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Download Manager" /f /reg:32
- '<SYSTEM32>\regsvr32.exe' /s downlWithIDM64.dll
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{D0FB58BB-2C07-492F-8BD0-A587E4874B4E}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f /reg:32
- '<SYSTEM32>\cmd.exe' /c ver
- '<SYSTEM32>\cmd.exe' /S /D /c" ver"
- '<SYSTEM32>\reg.exe' QUERY "HKU\S-1-5-19"
- '<SYSTEM32>\cmd.exe' /c wmic userAccount where "Name='user'" get SID /value
- '<SYSTEM32>\wbem\wmic.exe' userAccount where "Name='user'" get SID /value
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "MData"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "LName"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "FName"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "Email"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "Serial"
- '<SYSTEM32>\find.exe' "5."
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "scansk"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "radxcnt"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "LstCheck"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "ptrk_scdt"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "LastCheckQU"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "CheckUpdtVM"
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKU\.DEFAULT\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}" /f
- '<SYSTEM32>\reg.exe' delete "HKU\S-1-5-21-3150914307-1777937420-491476919-1000\Software\DownloadManager" /f /v "tvfrdt"
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{D0FB58BB-2C07-492F-8BD0-A587E4874B4E}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{0F947660-8606-420A-BAC6-51B84DD22A47}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{0F947660-8606-420A-BAC6-51B84DD22A47}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{C950922F-897A-4E13-BA38-66C8AF2E0BF7}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{C950922F-897A-4E13-BA38-66C8AF2E0BF7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Classes\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{84797876-C678-1780-A556-0CD06786780F}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{84797876-C678-1780-A556-0CD06786780F}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{84797876-C678-1780-A556-0CD06786780F}" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{84797876-C678-1780-A556-0CD06786780F}" /f /reg:32
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}" /f /reg:32
- '<SYSTEM32>\timeout.exe' /t 0
- '<SYSTEM32>\reg.exe' delete "HKLM\Software\Classes\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Software\Classes\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}" /f
- '%WINDIR%\syswow64\net.exe' start IDMWFP' (with hidden window)
- '<SYSTEM32>\rundll32.exe' SETUPAPI.DLL,InstallHinfSection DefaultInstall 128 %ProgramFiles(x86)%\Internet Download Manager\idmwfp.inf' (with hidden window)