Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\manera] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\manera] 'ImagePath' = 'C:\manera\manera.exe'
- 'manera' C:\manera\manera.exe
- Windows Task Manager (Taskmgr)
- '<SYSTEM32>\taskkill.exe' /IM explorer.exe /F
- %WINDIR%\explorer.exe
- C:\manera\manera.exe
- C:\manera\manera_start.bat
- C:\manera\manera_end.bat
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c C:\manera\manera_start.bat
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableCAD /t REG_DWORD /d 1 /f
- '<SYSTEM32>\sc.exe' create manera binPath= "C:\manera\manera.exe" DisplayName= "manera system lock" start= auto
- '<SYSTEM32>\cmd.exe' /c C:\manera\manera_start.bat' (with hidden window)