Техническая информация
- %TEMP%\6170.tmp\6181.tmp\6182.bat
- nul
- %TEMP%\6170.tmp\6181.tmp\6182.bat
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\6170.tmp\6181.tmp\6182.bat <Полный путь к файлу>"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\6170.tmp\6181.tmp\6182.bat <Полный путь к файлу>"
- '<SYSTEM32>\cmd.exe' /c reg query "HKLM\SOFTWARE\ACD Systems\ACDSee Ultimate\160" /v InstallDir 2>nul
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\ACD Systems\ACDSee Ultimate\160" /v InstallDir
- '<SYSTEM32>\xcopy.exe' /s /e /r /y /k "J_Crack\*.*" ""
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\ACD Systems\ACDSee Ultimate\160\LClient" /v "iid" /t REG_DWORD /d "18621140" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\ACD Systems\ACDSee Ultimate\160\LClient" /v "pid2" /t REG_BINARY /d "6fa80845258c8b7e3d1464cb4f0eab4f2fa1383e11ca2bc7" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\ACD Systems\ACDSee Ultimate\160\LClient" /v "md" /t REG_BINARY /d "db32a58e8aee8c0032b1637ee2f375aa760c107c9436f67c939e0fca99916bd21ff39ed300b85d297c854458e768ea41f2b8064b984...
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\ACD Systems\RBC" /v "MachineGuid" /t REG_SZ /d "05f0f65f-b1b7-4eaa-b330-f20c01118802" /f
- '<SYSTEM32>\find.exe' "127.0.0.1 acdid.acdsystems.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' "127.0.0.1 acdidserver.acdsee.cn" <DRIVERS>\etc\hosts
- '<SYSTEM32>\ipconfig.exe' /flushdns