Technical Information
- %TEMP%\aut78d7.tmp
- %TEMP%\rarsfx0\host.cmd
- %TEMP%\c2cq4pla.cmd
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\host.exe
- %TEMP%\autb60c.tmp
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\clean.exe
- %TEMP%\autb5cd.tmp
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\acrotray.exe
- %TEMP%\autb38b.tmp
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\acrodistdll.dll
- %TEMP%\autb0eb.tmp
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\acrobat.dll
- %TEMP%\aut7ffb.tmp
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\patch86.exe
- %TEMP%\aut7f5e.tmp
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\patch64.exe
- %TEMP%\aut7ea2.tmp
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\vidbanner.mp4
- %TEMP%\rarsfx0\host.vbs
- %ProgramFiles(x86)%\adobe\acrobat dc\acrobat\amtlib.dll
- %TEMP%\aut78d7.tmp
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\patch64.exe
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\host.exe
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\clean.exe
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\acrotray.exe
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\acrodistdll.dll
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\acrobat.dll
- %TEMP%\c2cq4pla.cmd
- <SYSTEM32>\tasks\adobe acrobat update task
- %TEMP%\autb60c.tmp
- %TEMP%\autb5cd.tmp
- %TEMP%\autb38b.tmp
- %TEMP%\autb0eb.tmp
- %TEMP%\aut7ffb.tmp
- %TEMP%\aut7f5e.tmp
- %TEMP%\aut7ea2.tmp
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\patch86.exe
- C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\vidbanner.mp4
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- 'C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\clean.exe'
- 'C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\host.exe'
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\RarSFX0\host.vbs"
- 'C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\patch64.exe'
- '%WINDIR%\syswow64\cmd.exe' /C sc.exe stop AGSService' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C sc.exe delete AGSService' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C sc.exe stop AGMService' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C sc.exe delete AGMService' (with hidden window)
- 'C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\clean.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\C2CQ4PLA.cmd" C:\Users\Default\AppData\Local\Microsoft\Windows\History\installfiles\install\\clean.exe"' (with hidden window)
- 'C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\host.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c host.cmd' (with hidden window)
- 'C:\users\default\appdata\local\microsoft\windows\history\installfiles\install\patch64.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C sc.exe stop AGSService
- '%WINDIR%\syswow64\find.exe' /C /I "practivate.adobe.*" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "practivate.adobe" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "hl2rcv.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "ereg.wip4.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "ereg.wip3.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "ereg.wip2.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "ereg.wip1.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "ereg.wip.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "practivate.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "ereg.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "crl.verisign.net" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "adobeereg.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "adobe.activate.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "adobe-dns.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "adobe-dns-4.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "adobe-dns-3.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "adobe-dns-2.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "adobe-dns-1.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "CRL.VERISIGN.NET.*" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "practivate.adobe.ipp" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "practivate.adobe.newoa" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "practivate.adobe.ntp" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "uds.licenses.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "practivate-da1.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "lm-prd-da1.licenses.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "prod.adobegenuine.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "genuine.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "hlrcv.stage.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "na1r.services.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "lmlicenses.wip4.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "lm.licenses.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "www.wi##.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "www.wi#.#dobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "www.ad###ereg.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "wwis-dubc1-vip60.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "wip4.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "wip3.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "wip2.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "wip1.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "wip.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "tss-geotrust-crl.thawte.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "activate.wip4.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "license.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "activate.wip3.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "activate.wip1.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "209.34.83.67:43" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "209.34.83.67:443" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "209.34.83.73" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "209.34.83.73:43" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "209.34.83.73:443" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\cmd.exe' /c host.cmd
- '<SYSTEM32>\schtasks.exe' /delete /tn "Adobe Acrobat Update Task" /f
- '<SYSTEM32>\cmd.exe' /S /D /c" echo y"
- '%WINDIR%\syswow64\find.exe' /C /I "209.34.83.67" <DRIVERS>\etc\hosts
- '<SYSTEM32>\schtasks.exe' /change /tn "Adobe Acrobat Update Task" /disable
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\C2CQ4PLA.cmd" C:\Users\Default\AppData\Local\Microsoft\Windows\History\installfiles\install\\clean.exe"
- '%WINDIR%\syswow64\sc.exe' delete AGMService
- '%WINDIR%\syswow64\cmd.exe' /C sc.exe delete AGMService
- '%WINDIR%\syswow64\sc.exe' stop AGMService
- '%WINDIR%\syswow64\cmd.exe' /C sc.exe stop AGMService
- '%WINDIR%\syswow64\sc.exe' delete AGSService
- '%WINDIR%\syswow64\cmd.exe' /C sc.exe delete AGSService
- '%WINDIR%\syswow64\sc.exe' stop AGSService
- '<SYSTEM32>\sc.exe' delete AdobeARMservice
- '%WINDIR%\syswow64\find.exe' /C /I "ood.opsource.net" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "199.7.52.190:80" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "199.7.52.190" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "activate.wip.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "activate.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "activate-sjc0.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "activate-sea.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "3dns-4.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "3dns-3.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "3dns-2.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "3dns.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "3dns-1.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "209-34-83-73.ood.opsource.net" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "192.150.8.118" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "192.150.8.100" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "192.150.22.40" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "192.150.18.108" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "192.150.18.101" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "192.150.14.69" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "199.7.54.72" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "199.7.54.72:80" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "OCSP.SPO1.VERISIGN.COM" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "activate.wip2.adobe.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "helpexamples.com" <DRIVERS>\etc\hosts