Technical Information
- [<HKLM>\System\CurrentControlSet\Services\ntwscsvc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\ntwscsvc] 'ImagePath' = '<SYSTEM32>\wscsvc.exe -service'
- 'ntwscsvc' <SYSTEM32>\wscsvc.exe -service
- %WINDIR%\syswow64\wscsvc.exe
- %WINDIR%\ntshell.log
- 'mn###.vicp.net':7070
- '<LOCALNET>.0.23':7070
- DNS ASK mn###.vicp.net
- '%WINDIR%\syswow64\wscsvc.exe' -service