就下面这个评判,请教一下:
5 KMSAuto Lite Portable win激活/office激活 较安全级别
7 KMS pico win激活/office激活 较危险级别
其中5号软件的详细测试是
⑤号工具:
产生的多个进程:
- "wmic.exe" path OfficeSoftwareProtectionProduct where (Name LIKE 'Office%%' And PartialProductKey is Not NULL) get Name, Description, ID, PartialProductKey, LicenseStatus, KeyManagementServiceMachine, KeyManagementServicePort, VLRenewalInterval, VLActivationIn
- "C:\Windows\System32\cmd.exe" /c copy C:\Windows\system32\Tasks\KMSAuto "C:\Users\ADMINI~1\AppData\Local\Temp\KMSAuto.tmp" /Y
- "wmic.exe" path OfficeSoftwareProtectionProduct where (Name LIKE 'Office%%' And PartialProductKey is Not NULL) get Name, Description /FORMAT:List
- "wmic.exe" path Win32_NetworkAdapter get ServiceName /value /FORMAT:List
- "wmic.exe" path SoftwareLicensingProduct where (Name LIKE 'Office%%' And PartialProductKey is Not NULL) get Name, Description /FORMAT:List
- "wmic.exe" path SoftwareLicensingProduct where (Name LIKE 'Office%%' And PartialProductKey is Not NULL) get Name, Description, ID, PartialProductKey, LicenseStatus, KeyManagementServiceMachine, KeyManagementServicePort, VLRenewalInterval, VLActivationInterval,
[color=rgb(51, 102, 153) !important]复制代码
分配了可读,可写,可执行的内存空间,恢复了一个远程进程中一个挂起的线程,表明远程注入,
其中包含的部分网页:
- http://crl.usertrust.com/UTN-USERFirst-Object.crl05
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://forum.ru-board.com/topic.cgi?forum=2
- http://ocsp.usertrust.com0
- http://www.usertrust.com1
有远端注入。
而7号软件的详细测试是
⑦号工具:
可发现与KMSAuto Lite Portable相似其释放的文件
[color=rgb(51, 102, 153) !important]复制代码
为获得微软激活码数据库的配置文件
- _setup.tmp
- idp.dll
- _shfoldr.dll
- is-UJL6E.tmp
- is-4CVLV.tmp
- KMSpico-setup.tmp
- is-JDHF8.tmp
- _setup64.tmp
- _setup64.tmp
[color=rgb(51, 102, 153) !important]复制代码
为生成的针对不同机型的激活配置文件,位于C盘生成的文件夹中
- setup log 2020-10-17 #001.txt
[color=rgb(51, 102, 153) !important]复制代码
为每周期激活的日志文件
同样通过开机自启动实施激活
- "schtasks.exe" /Create /F /SC WEEKLY /D WED,SUN /ST 12:00 /RL HIGHEST /TN "Optimize Thumbnail Cache" /TR ""C:\Program Files (x86)\Common Files\installshield\engine\8\intel 32\isupdate.exe"
- cmdline
- "schtasks.exe" /Create /F /SC ONLOGON /RL HIGHEST /TN "KMSpico Automatic Update Scheduler" /TR ""C:\Program Files\KMSpico\KMSUPD.exe"
[color=rgb(51, 102, 153) !important]复制代码
此文件为激活密钥接入点
- %HOMEPATH%\AppData\Local\Temp\is-43O7F.tmp\idp.dll
- %HOMEPATH%\AppData\Local\Temp\is-FO10K.tmp\idp.dll
- %HOMEPATH%\AppData\Local\Temp\is-SN6OJ.tmp\_isetup\_shfoldr.dll
- %HOMEPATH%\AppData\Local\Temp\is-43O7F.tmp\idp.dll
- %HOMEPATH%\AppData\Local\Temp\is-FO10K.tmp\idp.dll
那么,为什么5号反而会比7号安全呢?
|