fedmich / Malware-Research

MIT License
0 stars 0 forks source link

dasHost.exe keeps running #3

Closed fedmich closed 1 year ago

fedmich commented 1 year ago

Service.msc says Device Association Service Enables pairing between the system and wired or wireless devices.

Executes:

C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p

image

fedmich commented 1 year ago

I think its just a normal persistent service and not the Trojan/ Coin Miner mentioned in the internet. I'll just disable it to run from startup, I hope it's fine, I'll monitor if it causes other issue.