2.5.3 Registry changes

Often, we can see registry changes related to a run entry or other activities, such as disabling Task Manager in the memory:

Registry entry strings in memory

The strings in the preceding image show that the malware wants to disable Task Manager and password changes. Also, there is a registry key related to a run entry.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.21.158.148