Technical Information
- <SYSTEM32>\windowspowershell\v1.0\powershell.exe
- C:\lisans\hwid_activation.cmd
- C:\lisans\ohook_activation_aio.cmd
- C:\lisans\setupcomplete.cmd
- C:\lisans\tsforge_activation.cmd
- nul
- DNS ASK ac###ated.win
- DNS ASK up######eck33.activated.win
- ClassName: 'Edit' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""C:\Lisans\SetupComplete.cmd" "
- '<SYSTEM32>\sc.exe' query OfficeSvc
- '<SYSTEM32>\reg.exe' query "HKLM\SYSTEM\CurrentControlSet\Control\ProductOptions" /v ProductType
- '<SYSTEM32>\find.exe' /i "WinNT"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v EditionID
- '<SYSTEM32>\find.exe' /i "Server"
- '<SYSTEM32>\cmd.exe' /c "wmic path OfficeSoftwareProtectionProduct where (ApplicationID='59a52881-a989-479d-af46-f275c6370663') get ID /VALUE" 2>nul
- '<SYSTEM32>\wbem\wmic.exe' path OfficeSoftwareProtectionProduct where (ApplicationID='59a52881-a989-479d-af46-f275c6370663') get ID /VALUE
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Microsoft\Office\14.0\Common\ProductVersion /v LastProduct" 2>nul
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\Office\14.0\Common\ProductVersion /v LastProduct
- '<SYSTEM32>\cmd.exe' /S /D /c" echo "HKLM\SOFTWARE\Microsoft\Office\14.0" "
- '<SYSTEM32>\find.exe' /i "Wow6432Node"
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform /v Path" 2>nul
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\OfficeSoftwareProtectionPlatform /v Path
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{4d463c2c-0505-4626-8cdb-a4da82e2d8ed}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-0015-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{745fb377-0a59-4ca9-b9a9-c359557a2c4e}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-001C-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{95ab3ec8-4106-4f9d-b632-03c019d1d23f}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{4eaff0d0-c6cb-4187-94f3-c7656d49a0aa}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-0016-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{71dc86ff-f056-40d0-8ffb-9592705c9b76}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{7004b7f0-6407-4f45-8eac-966e5f868bde}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-00BA-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{fdad0dfa-417d-4b4f-93e4-64ea8867b7fd}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{7b7d1f17-fdcb-4820-9789-9bec6e377821}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-0013-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{19316117-30a8-4773-8fd9-7f7231f4e060}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-011E-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{09e2d37e-474b-4121-8626-58ad9be5776f}" /v ProductCode
- '<SYSTEM32>\sc.exe' query ClickToRunSvc
- '<SYSTEM32>\find.exe' /i "-002F-"
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\Office\14.0\Common\InstallRoot /v Path
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\14.0\Common\InstallRoot /v Path
- '<SYSTEM32>\reg.exe' query "HKU\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SppExtComObj.exe"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SLsvc.exe"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sppsvc.exe"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sppsvc.exe\PerfOptions"
- '<SYSTEM32>\cmd.exe' /c reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform" /v "SkipRearm" 2>nul
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform" /v "SkipRearm"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0" /f ba02fed39662 /d
- '<SYSTEM32>\cmd.exe' /c reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform" /v TokenStore 2>nul
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform" /v TokenStore
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\Office\14.0\CVH /f Click2run /k
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\14.0\CVH /f Click2run /k
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\ClickToRun /v InstallPath" 2>nul
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\ClickToRun /v InstallPath
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Microsoft\Office\ClickToRun /v InstallPath" 2>nul
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\Office\ClickToRun /v InstallPath
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\15.0\ClickToRun /v InstallPath" 2>nul
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\15.0\ClickToRun /v InstallPath
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Microsoft\Office\15.0\ClickToRun /v InstallPath" 2>nul
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\Office\15.0\ClickToRun /v InstallPath
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\16.0\Common\InstallRoot /v Path" 2>nul
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\16.0\Common\InstallRoot /v Path
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Microsoft\Office\16.0\Common\InstallRoot /v Path" 2>nul
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\Office\16.0\Common\InstallRoot /v Path
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\15.0\Common\InstallRoot /v Path" 2>nul
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\15.0\Common\InstallRoot /v Path
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Microsoft\Office\15.0\Common\InstallRoot /v Path" 2>nul
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\Office\15.0\Common\InstallRoot /v Path
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\14.0\Common\InstallRoot /v Path" 2>nul
- '<SYSTEM32>\cmd.exe' /c "reg query HKLM\SOFTWARE\Microsoft\Office\14.0\Common\InstallRoot /v Path" 2>nul
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{fdf3ecb9-b56f-43b2-a9b8-1b48b6bae1a7}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3691498038-2086406363-2140527554-1000" /v ProfileImagePath
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{85e22450-b741-430c-a172-a37962c938af}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-0019-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{3d014759-b128-4466-9018-e80f6320d9d0}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{dbe3aee0-5183-4ff7-8142-66050173cb01}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-008B-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{8090771e-d41a-4482-929e-de87f1f47e46}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{b78df69e-0966-40b1-ae85-30a5134dedd0}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-0017-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{d3422cfb-8d8b-4ead-99f9-eab0ccd990d7}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-0012-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{1f76e346-e0be-49bc-9954-70ec53a4fcfe}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{2745e581-565a-4670-ae90-6bf7c57ffe43}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-0066-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{66cad568-c2dc-459d-93ec-2f3cb967ee34}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-0057-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{36756cb8-8e69-4d11-9522-68899507cd6a}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{db3bbc9c-ce52-41d1-a46f-1a1d68059119}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-001B-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{98d4050e-9c98-49bf-9be1-85e12eb3ab13}" /v ProductCode
- '<SYSTEM32>\cmd.exe' /S /D /c" echo ProPlusVL "
- '<SYSTEM32>\find.exe' /i "2024"
- '<SYSTEM32>\cmd.exe' /S /D /c" echo "191301d3-a579-428c-b0c7-d7988500f9e3 6f327760-8c5c-417c-9b61-836a98287e0c fdf3ecb9-b56f-43b2-a9b8-1b48b6bae1a7" "
- '<SYSTEM32>\find.exe' /i "fdf3ecb9-b56f-43b2-a9b8-1b48b6bae1a7"
- '<SYSTEM32>\wbem\wmic.exe' path OfficeSoftwareProtectionService where __CLASS='OfficeSoftwareProtectionService' call InstallProductKey ProductKey="6CD6C-9R8PB-T2D9Y-8RKKX-W7DFK"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -c "$f=[io.file]::ReadAllText('C:\Lisans\Ohook_Activation_AIO.cmd') -split ':sppc64.dll\:.*';$encoded = ($f[1]) -replace '-', 'A' -replace '_', 'a';$bytes = [Convert]::FromBase64String($en...
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\WindowsPowerShell\v1.0\powershell.exe -nop -c "$p = 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList'; Get-ChildItem $p | ForEach-Object { $pi = (Get-ItemProperty "...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -c "$p = 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList'; Get-ChildItem $p | ForEach-Object { $pi = (Get-ItemProperty """"$p\$($_.PSChildName)"""").ProfileImagePath; if ($...
- '<SYSTEM32>\reg.exe' query HKU\S-1-5-21-3691498038-2086406363-2140527554-1000\Software
- '<SYSTEM32>\reg.exe' delete HKU\S-1-5-21-3691498038-2086406363-2140527554-1000\Software\Microsoft\Office\15.0\Common\Licensing /f
- '<SYSTEM32>\cmd.exe' /c "reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3691498038-2086406363-2140527554-1000" /v ProfileImagePath" 2>nul
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{98677603-a668-4fa4-9980-3f1f05f78f69}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ClipSVC\Volatile\PersistedSystemState"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Common\InstalledPackages"
- '<SYSTEM32>\find.exe' /i "-011D-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{14f5946a-debc-4716-babc-7e2c240fec08}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-000F-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{533b656a-4425-480b-8e30-1a2358898350}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{c1ceda8b-c578-4d5d-a4aa-23626be4e234}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-003D-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{3f7aa693-9a7e-44fc-9309-bb3d8e604925}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-00A1-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{6860b31f-6a67-48b8-84b9-e312b3485c4b}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{fbf4ac36-31c8-4340-8666-79873129cf40}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-001A-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{a9aeabd8-63b8-4079-a28e-f531807fd6b8}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{acb51361-c0db-4895-9497-1831c41f31a6}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-0033-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{133c8359-4e93-4241-8118-30bb18737ea0}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-0018-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{38252940-718c-4aa6-81a4-135398e53851}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{8b559c37-0117-413e-921b-b853aeb6e210}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-0014-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{725714d7-d58f-4d12-9fa8-35873c6f7215}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-003B-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{4d06f72e-fd50-4bc2-a24b-d448d7f17ef2}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-011F-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{1cf57a59-c532-4e56-9a7d-ffa2fe94b474}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{688f6589-2bd9-424e-a152-b13f36aa6de1}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-003A-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{11b39439-6b93-4642-9570-f2eb81be2238}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{71af7e84-93e6-4363-9b69-699e04e74071}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-0011-"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{e98ef0c0-71c4-42ce-8305-287d8721e26c}" /v ProductCode
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Office\14.0\Registration\{ef1da464-01c8-43a6-91af-e4e5713744f9}" /v ProductCode
- '<SYSTEM32>\find.exe' /i "-0044-"
- '<SYSTEM32>\reg.exe' query "HKU\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\PersistedTSReArmed"
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\WindowsPowerShell\v1.0\powershell.exe -nop -c "$f=[io.file]::ReadAllText('C:\Lisans\Ohook_Activation_AIO.cmd') -split ':wpatest\:.*';iex ($f[1])" 2>nul
- '<SYSTEM32>\find.exe' /i "Windows"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -c "$job = Start-Job { (Get-WmiObject -Query 'SELECT * FROM SoftwareLicensingService').Version }; if (-not (Wait-Job $job -Timeout 30)) {write-host 'sppsvc is not working correctly. Check ...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -s -NoLogo -NoProfile
- '<SYSTEM32>\cmd.exe' /c reg query "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Environment" /v PROCESSOR_ARCHITECTURE
- '<SYSTEM32>\reg.exe' query "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Environment" /v PROCESSOR_ARCHITECTURE
- '<SYSTEM32>\cmd.exe' /c "reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v UBR" 2>nul
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v UBR
- '<SYSTEM32>\cmd.exe' /c reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v BuildLabEx
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v BuildLabEx
- '<SYSTEM32>\sc.exe' query sppsvc
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\sppsvc /v DependOnService
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\sppsvc /v Description
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\sppsvc /v DisplayName
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\sppsvc /v ErrorControl
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\sppsvc /v ImagePath
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\sppsvc /v ObjectName
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\sppsvc /v Start
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\sppsvc /v Type
- '<SYSTEM32>\sc.exe' start Winmgmt
- '<SYSTEM32>\sc.exe' query Winmgmt
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt /v DependOnService
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt /v Description
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt /v DisplayName
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt /v ErrorControl
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt /v ImagePath
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt /v ObjectName
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt /v Start
- '<SYSTEM32>\reg.exe' query HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt /v Type
- '<SYSTEM32>\cmd.exe' /c reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\State" /v ImageState
- '<SYSTEM32>\cmd.exe' /S /D /c" echo "Windows 7 Enterprise" "
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\State" /v ImageState
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -c $AssemblyBuilder = [AppDomain]::CurrentDomain.DefineDynamicAssembly(4, 1); $ModuleBuilder = $AssemblyBuilder.DefineDynamicModule(2, $False); $TypeBuilder = $ModuleBuilder.DefineType(0);...
- '<SYSTEM32>\findstr.exe' "577 225"
- '<SYSTEM32>\fltmc.exe'
- '<SYSTEM32>\sc.exe' query Null
- '<SYSTEM32>\find.exe' /i "RUNNING"
- '<SYSTEM32>\findstr.exe' /v "$" "HWID_Activation.cmd"
- '<SYSTEM32>\cmd.exe' /c ver
- '<SYSTEM32>\cmd.exe' /S /D /c" echo "AMD64 " "
- '<SYSTEM32>\find.exe' /i "ARM64"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -c write-host -back '"Red"' -fore '"white"' '"==== ERROR ===="'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -c write-host -back '"Blue"' -fore '"white"' '"Use TSforge activation option from the main menu."'
- '<SYSTEM32>\timeout.exe' /t 2
- '<SYSTEM32>\findstr.exe' /v "$" "Ohook_Activation_AIO.cmd"
- '<SYSTEM32>\cmd.exe' /S /D /c" echo "C:\Lisans\Ohook_Activation_AIO.cmd" "
- '<SYSTEM32>\find.exe' /i "%LOCALAPPDATA%\Temp"
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\WindowsPowerShell\v1.0\powershell.exe -nop -c "if ($PSVersionTable.PSEdition -ne 'Core') {$f=[io.file]::ReadAllText('C:\Lisans\Ohook_Activation_AIO.cmd') -split ':pstst';iex ($f[1...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -c "if ($PSVersionTable.PSEdition -ne 'Core') {$f=[io.file]::ReadAllText('C:\Lisans\Ohook_Activation_AIO.cmd') -split ':pstst';iex ($f[1])}"
- '<SYSTEM32>\cmd.exe' /c ping -n 1 activated.win
- '<SYSTEM32>\ping.exe' -n 1 activated.win
- '<SYSTEM32>\cmd.exe' /c ping -n 1 updatecheck33.activated.win
- '<SYSTEM32>\ping.exe' -n 1 updatecheck33.activated.win
- '<SYSTEM32>\mode.com' 140, 32
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -c "&{$W=$Host.UI.RawUI.WindowSize;$B=$Host.UI.RawUI.BufferSize;$W.Height=32;$B.Height=300;$Host.UI.RawUI.WindowSize=$W;$Host.UI.RawUI.BufferSize=$B;}"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\taskcache\tasks" /f Path /s
- '<SYSTEM32>\find.exe' /i "AutoPico"
- '<SYSTEM32>\find.exe' /i "avira.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /i "kaspersky.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /i "virustotal.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /i "mcafee.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\sc.exe' start sppsvc
- '<SYSTEM32>\cmd.exe' /S /D /c" echo "1056" "
- '<SYSTEM32>\cmd.exe' /c "<SYSTEM32>\WindowsPowerShell\v1.0\powershell.exe -nop -c $AssemblyBuilder = [AppDomain]::CurrentDomain.DefineDynamicAssembly(4, 1); $ModuleBuilder = $AssemblyBuilder.DefineDynamicModule(2, ...
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-4 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\cmd.exe' /S /D /c" echo "0" "
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -c "$f=[io.file]::ReadAllText('C:\Lisans\Ohook_Activation_AIO.cmd') -split ':wpatest\:.*';iex ($f[1])"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-5 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-6 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-6 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-7 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-7 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-8 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-8 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-9 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-9 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-a /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-a /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-b /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-b /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-c /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-c /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-d /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-d /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-e /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-e /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-f /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-f /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /S /D /c" echo "27" "
- '<SYSTEM32>\find.exe' /i "Error Found"
- '<SYSTEM32>\cmd.exe' /c "wmic path SoftwareLicensingProduct where (ApplicationID='55c92734-d682-4d71-983e-d6ec3f16059f' AND LicenseDependsOn is NULL AND PartialProductKey IS NOT NULL) get LicenseFamily /VALUE" 2>nu...
- '<SYSTEM32>\wbem\wmic.exe' path SoftwareLicensingProduct where (ApplicationID='55c92734-d682-4d71-983e-d6ec3f16059f' AND LicenseDependsOn is NULL AND PartialProductKey IS NOT NULL) get LicenseFamily /VALUE
- '<SYSTEM32>\wbem\wmic.exe' path SoftwareLicensingService get Version
- '<SYSTEM32>\cmd.exe' /c exit /b 0
- '<SYSTEM32>\wbem\wmic.exe' path Win32_ComputerSystem get CreationClassName /value
- '<SYSTEM32>\find.exe' /i "computersystem"
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-5 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\findstr.exe' /i "0x800410 0x800440 0x80131501"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-4 /ve /t REG_BINARY
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-3 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-0 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-0 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-1 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-1 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-10 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-10 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-11 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-11 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-12 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-12 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-13 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-13 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-14 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-14 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-15 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-15 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-16 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-16 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-17 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-17 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-18 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-18 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-19 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-19 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-1a /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-1a /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-2 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-2 /ve /t REG_BINARY
- '<SYSTEM32>\cmd.exe' /c "reg query " "HKLM\SYSTEM\WPA\8DEC0AF1-0341-4b93-85CD-72606C2DF94C-5P-3 /ve /t REG_BINARY >nul 2>&1"
- '<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinPE" /v InstRoot
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Office\15.0\Common\Licensing" /f