
mAliCious Code 255
Explorer process. e ShellServiceObjectDelayLoad registry key
contains critical DLLs, such as stobject.dll for the system tray, to
load into the Explorer process for Windows to operate properly. To
use the ShellServiceObjectDelayLoad key for injection, a component
object model (COM) object, used to allow communication between
different pieces of software on the system, must link the DLL to a
unique class identifier. Once the link exists, the class identifier added
to the ShellServiceObjectDelayLoad key will load the DLL into
the Explorer process when the system starts. e full path to the
ShellServiceObjectDelayLoad ...