Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\DErpAgentManagerService] 'ImagePath' = 'C:\Douzone\DERP\DErpAgentManagerService.exe'
- [<HKLM>\System\CurrentControlSet\Services\DErpAgentStartService] 'ImagePath' = 'C:\Douzone\DERP\WindowsService1.exe'
- [<HKLM>\System\CurrentControlSet\Services\DErpAgentManagerService] 'Start' = '00000002'
- 'DErpAgentManagerService' C:\Douzone\DERP\DErpAgentManagerService.exe
- 'DErpAgentStartService' C:\Douzone\DERP\WindowsService1.exe
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\certutil.exe' -f -p duzon1! -importpfx C:\Douzone\DERP\Server.pfx NoRoot
- '<SYSTEM32>\certutil.exe' -addstore -f ROOT C:\Douzone\DERP\root_ca.crt
- '<SYSTEM32>\netsh.exe' http add sslcert ipport=127.0.0.1:8235 certhash= appid={"AF5DF604-441E-49F6-9046-0CC186E03A35"}
- '<SYSTEM32>\sc.exe' create DErpAgentManagerService binPath= C:\Douzone\DERP\DErpAgentManagerService.exe
- '<SYSTEM32>\sc.exe' create DErpAgentStartService binPath= C:\Douzone\DERP\WindowsService1.exe
- '<SYSTEM32>\sc.exe' config DErpAgentManagerService start= auto
- '<SYSTEM32>\sc.exe' config DErpAgentStartService start=auto
- '<SYSTEM32>\sc.exe' start DErpAgentStartService
- '<SYSTEM32>\sc.exe' start DErpAgentManagerService