Техническая информация
- '%TEMP%\2.tmp\KMS.exe' LogLevel=0 Port=2025 Office2010=Random Office2013=Random Windows=Random RenewalInterval=43200 ActivationInterval=43200
- '%TEMP%\1.tmp\Install.exe'
- '%TEMP%\1.tmp\KMS.exe'
- '<SYSTEM32>\wbem\wmic.exe' path SoftwareLicensingProduct where (Description like '%KMSCLIENT%') get Name /format:list
- '<SYSTEM32>\openfiles.exe'
- '<SYSTEM32>\findstr.exe' /i Office
- '<SYSTEM32>\wbem\wmic.exe' path OfficeSoftwareProtectionService get version /format:list
- '<SYSTEM32>\findstr.exe' /i Windows
- '<SYSTEM32>\cacls.exe' "<SYSTEM32>\config\system"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\create.cmd" "
- '<SYSTEM32>\schtasks.exe' /Create /TN "KMS Aktivasyon" /TR "%WINDIR%\KMS.exe" /SC DAILY /RU SYSTEM /RL Highest /F
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\2.tmp\Activation.cmd" "
- '<SYSTEM32>\schtasks.exe' /Create /TN "KMS Aktivasyon " /TR "%WINDIR%\KMS.exe" /SC ONSTART /RU SYSTEM /RL Highest /F
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp3.tmp
- <SYSTEM32>\wbem\Logs\WMIC.LOG
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp5.tmp
- %TEMP%\1.tmp\Install.exe
- %TEMP%\1.tmp\KMS.exe
- %TEMP%\1.tmp\create.cmd
- %TEMP%\2.tmp\KMS.exe
- %TEMP%\2.tmp\Activation.cmd
- %WINDIR%\KMS.exe
- %TEMP%\tmp5.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\tmp3.tmp
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''