Техническая информация
- <SYSTEM32>\wbem\wmic.exe path OfficeSoftwareProtectionService where version='' call ClearKeyManagementServiceMachine
- <SYSTEM32>\wbem\wmic.exe path OfficeSoftwareProtectionService get version /format:list
- <SYSTEM32>\wbem\wmic.exe path SoftwareLicensingService where version='' call DisableKeyManagementServiceHostCaching 1
- <SYSTEM32>\find.exe /I /N "KMSServer.exe"
- <SYSTEM32>\tasklist.exe /FI "IMAGENAME eq KMSServer.exe"
- <SYSTEM32>\taskkill.exe /t /f /im KMSServer.exe
- <SYSTEM32>\wbem\wmic.exe path SoftwareLicensingService get version /format:list
- <SYSTEM32>\cacls.exe "<SYSTEM32>\config\system"
- <SYSTEM32>\cmd.exe /c ""%TEMP%\KMS\KMS.cmd" "
- <SYSTEM32>\wbem\wmic.exe path SoftwareLicensingService where version='' call DisableKeyManagementServiceDnsPublishing 1
- <SYSTEM32>\wbem\wmic.exe path SoftwareLicensingService where version='' call ClearKeyManagementServiceListeningPort
- <SYSTEM32>\wbem\wmic.exe path SoftwareLicensingService where version='' call ClearKeyManagementServiceMachine
- %TEMP%\tmp3.tmp
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- <SYSTEM32>\wbem\Logs\WMIC.LOG
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\KMS\KMSServer.exe
- %TEMP%\KMS\KMS.cmd
- %TEMP%\tmp2.tmp
- %TEMP%\tmp1.tmp
- %TEMP%\tmp3.tmp
- %TEMP%\tmp2.tmp
- %TEMP%\tmp1.tmp
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''