Profiling a rootkit: Hacker Defender Section 2
Registry Tracking with RegMon: 2712 56.77157974 hxdef100.exe:448 OpenKey HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution Optionshxdef100.exe NOT FOUND 2713 56.77293015 hxdef100.exe:448 OpenKey HKLMSystemCurrentControlSetControlTerminal...