- Some additional information now that this is turning out to be a success : Simply thanx you on behalf of the entire team (h44t33_Anon on Twitter)
- ! But you may not need to do this !
- IT IS CLEAR TO US THAT WITH THIS 'LULZROOTKIT' (IF YOU LIKE BECAUSE OF HOW IT WAS OBTAINED AND MODIFIED DELETING and then again adding THE KEY LASTTASKRUN ) AND SUBSTITUTING CRYPTOGRAPHY.RNG FOR SCHEDULINGAGENT AND THEN FOR CRYPTOGRAPHY/RNG.LASTTASKRUN and schedulingagent.lasttaskrun etcetera (!yes this was all accepted by the registry) (because we dumped the rootkits added and found the four below(deleted!) eventually of which the second is only of interest to you------------->>> copy it here paste in notepad call it whatever you like hell even keep it and add to registry by using the extension dotreg so that's .reg for example lulzrootkit.reg(the second one between asteriksis) But make sure you double click it then when prompted say yes
- XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
- Windows Registry Editor Version 5.00
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG.LastTaskRun]
- "Seed"=hex:1d,e1,fe,db,09,ab,f4,6f,34,ca,60,bd,31,4c,0b,a1,40,47,d3,7b,ec,71,\
- 71,75,8f,80,bb,1c,c7,95,c4,a7,8a,0b,e7,11,dc,0c,37,8e,ba,eb,dd,c9,7e,40,8c,\
- fc,83,93,fa,79,6c,f9,26,ec,1f,53,ab,8e,28,7f,f4,0a,f8,25,1a,ae,bc,62,06,bc,\
- ee,4f,73,cd,6e,15,e3,80
- XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
- DLL HELL BY TEAM h44t33_Anon
