Техническая информация
- <SYSTEM32>\tasks\wingtr
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %APPDATA%\windows activator\kmsautolite.ini
- %APPDATA%\windows activator\key.txt
- %APPDATA%\windows activator\kmsauto.exe
- %WINDIR%\wingtr.exe
- %WINDIR%\dfygx.cou
- %WINDIR%\useridfile
- %WINDIR%\wingtrst.bat
- %WINDIR%\ncoet
- %WINDIR%\temp\kmsauto\bin.dat
- %WINDIR%\temp\kmsauto\bin\kmsss.exe
- %WINDIR%\temp\kmsauto\bin\kmsactivator.vbs
- %WINDIR%\useridfile
- %WINDIR%\wingtrst.bat
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %WINDIR%\dfygx.cou
- %WINDIR%\ncoet
- %WINDIR%\temp\kmsauto\bin.dat
- 'ip##pi.com':80
- 'wh##.amung.us':80
- http://ip##pi.com/csv
- http://wh##.amung.us/pingjs/?k=########
- DNS ASK ip##pi.com
- DNS ASK wh##.amung.us
- DNS ASK pi###soop.xyz
- '%APPDATA%\windows activator\kmsauto.exe'
- '%WINDIR%\wingtr.exe'
- '%WINDIR%\temp\kmsauto\bin.dat' -y -pkmsauto
- '<SYSTEM32>\cmd.exe' /c copy <SYSTEM32>\Tasks\KMSAuto "%TEMP%\KMSAuto.tmp" /Y (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%WINDIR%\wingtrst.bat" " (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c bin.dat -y -pkmsauto (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /create /sc onlogon /f /tn wingtr /rl highest /tr "%WINDIR%\wingtr.exe"