Техническая информация
- [HKLM\System\CurrentControlSet\Services\Sainboxx] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Sainboxx] 'ImagePath' = '%CommonProgramFiles(x86)%\Microsoft Shared\svchost.exe -auto'
- [HKLM\SYSTEM\CurrentControlSet\Services\QAssist] 'Start' = '00000001'
- [HKLM\SYSTEM\CurrentControlSet\Services\QAssist] 'ImagePath' = 'system32\DRIVERS\QAssist.sys'
- 'Sainboxx' %CommonProgramFiles(x86)%\Microsoft Shared\svchost.exe -auto
- [HKLM\SYSTEM\CurrentControlSet\Services\QAssist] 'Group' = 'FSFilter Activity Monitor'
- ClassName: 'OLLYDBG', WindowName: ''
- %CommonProgramFiles(x86)%\microsoft shared\svchost.exe
- <DRIVERS>\qassist.sys
- nul
- '10#.#35.174.64':8080
- '%CommonProgramFiles(x86)%\microsoft shared\svchost.exe' -auto
- '%CommonProgramFiles(x86)%\microsoft shared\svchost.exe' -acsi
- '%WINDIR%\syswow64\cmd.exe' /c ping -n 2 127.0.0.1 > nul && del <Полный путь к файлу> > nul (со скрытым окном)
- '%WINDIR%\syswow64\ping.exe' -n 2 127.0.0.1