Technical Information
- '<SYSTEM32>\net.exe' stop sppsvc /y
- '<SYSTEM32>\net.exe' stop osppsvc /y
- %TEMP%\nsrbdc4.tmp
- %TEMP%\activate.cmd
- %TEMP%\bin\cleanosppx64.exe
- %TEMP%\bin\cleanosppx86.exe
- nul
- %WINDIR%\temp\sppchk.txt
- %WINDIR%\temp\sppchk.txt
- DNS ASK wi#.kms.pub
- DNS ASK km#.#oli.beer
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\Activate.cmd" /KMS-Office
- '<SYSTEM32>\wbem\wmic.exe' path OfficeSoftwareProtectionProduct where (ApplicationID='0ff1ce15-a989-479d-af46-f275c6370663' AND NOT Name like '%O365%' ) get Name /value
- '<SYSTEM32>\find.exe' /i "Office 14" "%WINDIR%\Temp\sppchk.txt"
- '<SYSTEM32>\find.exe' /i "Office 15" "%WINDIR%\Temp\sppchk.txt"
- '<SYSTEM32>\find.exe' /i "Office 16" "%WINDIR%\Temp\sppchk.txt"
- '<SYSTEM32>\find.exe' /i "Office 19" "%WINDIR%\Temp\sppchk.txt"
- '<SYSTEM32>\find.exe' /i "Office 21" "%WINDIR%\Temp\sppchk.txt"
- '<SYSTEM32>\wbem\wmic.exe' path OfficeSoftwareProtectionProduct where (Description like '%KMSCLIENT%' AND NOT Name like '%MondoR_KMS_Automation%' ) get Name /value
- '<SYSTEM32>\net1.exe' start osppsvc /y
- '<SYSTEM32>\net.exe' start osppsvc /y
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform" /f /v KeyManagementServicePort /t REG_SZ /d "1688"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform" /f /v KeyManagementServiceName /t REG_SZ /d "20.222.16.243"
- '<SYSTEM32>\wbem\wmic.exe' path SoftwareLicensingService get Version /value
- '<SYSTEM32>\cmd.exe' /c "wmic path SoftwareLicensingService get Version /value"
- '<SYSTEM32>\findstr.exe' /i Windows
- '<SYSTEM32>\wbem\wmic.exe' path SoftwareLicensingProduct where (Description like '%KMSCLIENT%' ) get Name /value
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\16.0\Common\InstallRoot /v Path
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\16.0\Common\InstallRoot /v Path" 2>nul
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\Office\16.0\Common\InstallRoot /v Path
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Microsoft\Office\16.0\Common\InstallRoot /v Path" 2>nul
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\15.0\Common\InstallRoot /v Path
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\15.0\Common\InstallRoot /v Path" 2>nul
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\Office\15.0\Common\InstallRoot /v Path
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Microsoft\Office\15.0\Common\InstallRoot /v Path" 2>nul
- '<SYSTEM32>\find.exe' /i "R_Retail" "%WINDIR%\Temp\sppchk.txt"
- '<SYSTEM32>\find.exe' /i "Office 19"
- '<SYSTEM32>\net1.exe' stop osppsvc /y
- '<SYSTEM32>\find.exe' /i "Office 16"
- '<SYSTEM32>\net1.exe' stop sppsvc /y
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform" /f /v KeyManagementServiceName /t REG_SZ /d "150.230.215.84"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform" /f /v KeyManagementServiceName /t REG_SZ /d "150.230.215.84"
- '<SYSTEM32>\ping.exe' -4 -n 1 kms.wxlost.com
- '<SYSTEM32>\cmd.exe' /c ping -4 -n 1 kms.wxlost.com 2>nul
- '<SYSTEM32>\wbem\wmic.exe' path OfficeSoftwareProtectionProduct where (ID='6f327760-8c5c-417c-9b61-836a98287e0c') get GracePeriodRemaining /value
- '<SYSTEM32>\cmd.exe' /c "wmic path OfficeSoftwareProtectionProduct where (ID='6f327760-8c5c-417c-9b61-836a98287e0c') get GracePeriodRemaining /value"
- '<SYSTEM32>\wbem\wmic.exe' path OfficeSoftwareProtectionProduct where ID='6f327760-8c5c-417c-9b61-836a98287e0c' call Activate
- '<SYSTEM32>\cmd.exe' /c "wmic path OfficeSoftwareProtectionProduct where (ID='6f327760-8c5c-417c-9b61-836a98287e0c') get Name /value"
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform\0ff1ce15-a989-479d-af46-f275c6370663\6f327760-8c5c-417c-9b61-836a98287e0c" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform\59a52881-a989-479d-af46-f275c6370663\6f327760-8c5c-417c-9b61-836a98287e0c" /f
- '<SYSTEM32>\findstr.exe' /i "6f327760-8c5c-417c-9b61-836a98287e0c"
- '<SYSTEM32>\wbem\wmic.exe' path OfficeSoftwareProtectionProduct where (PartialProductKey is not NULL) get ID /value
- '<SYSTEM32>\wbem\wmic.exe' path OfficeSoftwareProtectionProduct where (ID='6f327760-8c5c-417c-9b61-836a98287e0c') get Name /value
- '<SYSTEM32>\wbem\wmic.exe' path OfficeSoftwareProtectionProduct where (Description like '%KMSCLIENT%' ) get ID /value
- '<SYSTEM32>\cmd.exe' /c "wmic path OfficeSoftwareProtectionProduct where (Description like '%KMSCLIENT%' ) get ID /value"
- '<SYSTEM32>\wbem\wmic.exe' path OfficeSoftwareProtectionService get Version /value
- '<SYSTEM32>\cmd.exe' /c "wmic path OfficeSoftwareProtectionService get Version /value" 2>nul
- '<SYSTEM32>\wbem\wmic.exe' path OfficeSoftwareProtectionProduct where (LicenseFamily='OfficeVisioPro-MAK') get LicenseStatus /value
- '<SYSTEM32>\cmd.exe' /c "wmic path OfficeSoftwareProtectionProduct where (LicenseFamily='OfficeVisioPro-MAK') get LicenseStatus /value" 2>nul
- '<SYSTEM32>\wbem\wmic.exe' path OfficeSoftwareProtectionProduct where (LicenseFamily='OfficeVisioPrem-MAK') get LicenseStatus /value
- '<SYSTEM32>\cmd.exe' /c "wmic path OfficeSoftwareProtectionProduct where (LicenseFamily='OfficeVisioPrem-MAK') get LicenseStatus /value" 2>nul
- '<SYSTEM32>\find.exe' /i "Office 15"
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\14.0\Common\InstallRoot /v Path
- '<SYSTEM32>\find.exe' /i "Office 21"
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\14.0\Common\InstallRoot /v Path" 2>nul
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform" /f /v KeyManagementServiceName
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform" /f /v DisableKeyManagementServiceHostCaching
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform" /f /v DisableDnsPublishing
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform" /f /v KeyManagementServicePort
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform" /f /v KeyManagementServiceName
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\osppsvc.exe" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sppsvc.exe" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SppExtComObj.exe" /f
- '<SYSTEM32>\find.exe' /i "\Online_KMS_Activation_Script-Renewal"
- '<SYSTEM32>\find.exe' /i "\Activation-Renewal"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\taskcache\tasks" /f Path /s
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings" /v Enabled
- '<SYSTEM32>\find.exe' /i "0x0"
- '<SYSTEM32>\reg.exe' query "HKCU\SOFTWARE\Microsoft\Windows Script Host\Settings" /v Enabled
- '<SYSTEM32>\find.exe' /i "ComputerSystem"
- '<SYSTEM32>\wbem\wmic.exe' path Win32_ComputerSystem get CreationClassName /value
- '<SYSTEM32>\reg.exe' query "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Environment" /v PROCESSOR_ARCHITECTURE
- '<SYSTEM32>\cmd.exe' /c reg query "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Environment" /v PROCESSOR_ARCHITECTURE
- '<SYSTEM32>\fltmc.exe'
- '<SYSTEM32>\find.exe' /i "%LOCALAPPDATA%\Temp"
- '<SYSTEM32>\cmd.exe' /S /D /c" echo "%TEMP%\Activate.cmd" "
- '<SYSTEM32>\cmd.exe' /c "prompt $H&for %B in (1) do rem"
- '<SYSTEM32>\cmd.exe' /c ver
- '<SYSTEM32>\findstr.exe' /rxc:".*" "Activate.cmd"
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\55c92734-d682-4d71-983e-d6ec3f16059f" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform" /f /v KeyManagementServicePort
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Microsoft\Office\14.0\Common\InstallRoot /v Path" 2>nul
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform" /f /v DisableDnsPublishing
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\14.0\CVH /f Click2run /k
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\Office\15.0\ClickToRun /v InstallPath
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\WOW6432Node\Microsoft\Office\ClickToRun /v InstallPath
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\Office\ClickToRun /v InstallPath
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName
- '<SYSTEM32>\cmd.exe' /c reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName 2>nul
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform" /f /v KeyManagementServicePort /t REG_SZ /d "1688"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform" /f /v KeyManagementServiceName /t REG_SZ /d "20.222.16.243"
- '<SYSTEM32>\find.exe' /i "STOPPED"
- '<SYSTEM32>\sc.exe' query sppsvc
- '<SYSTEM32>\cmd.exe' /c dir /b /ad <SYSTEM32>\spp\tokens\channels
- '<SYSTEM32>\sc.exe' query osppsvc
- '<SYSTEM32>\cmd.exe' /c dir /b /ad <SYSTEM32>\spp\tokens\skus
- '<SYSTEM32>\ping.exe' -4 -n 1 kms.loli.beer
- '<SYSTEM32>\cmd.exe' /c ping -4 -n 1 kms.loli.beer 2>nul
- '<SYSTEM32>\ping.exe' -n 1 win.kms.pub
- '<SYSTEM32>\cmd.exe' /c ping -n 1 win.kms.pub
- '<SYSTEM32>\reg.exe' query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" /v Desktop
- '<SYSTEM32>\cmd.exe' /c reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" /v Desktop
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\55c92734-d682-4d71-983e-d6ec3f16059f"
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform\0ff1ce15-a989-479d-af46-f275c6370663" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform\59a52881-a989-479d-af46-f275c6370663" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform" /f /v DisableKeyManagementServiceHostCaching
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\Office\14.0\Common\InstallRoot /v Path
- '<SYSTEM32>\sc.exe' start sppsvc trigger=timer;sessionid=0