Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Network service] 'Start' = '00000002'
- '<SYSTEM32>\lsserv.exe'
- '<SYSTEM32>\sc.exe' config "Network service" start= auto
- '<SYSTEM32>\sc.exe' create "Network service" binPath= "<SYSTEM32>\lsserv.exe" start= auto error= ignore
- %ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\RSA\S-1-5-18\0cc8c8516d3f254095d9a42f6f4f8e26_23ef5514-3059-436f-a4a7-4cefaab20eb1
- <SYSTEM32>\Microsoft\Protect\S-1-5-18\User\080924d0-0221-4d97-b95d-a5319686430b
- <SYSTEM32>\lsserv.exe
- 'dn###date3.net':3000
- 'dn###date3.com':3000
- DNS ASK dn###date3.net
- DNS ASK dn###date3.com