February 2012
Intermediate to advanced
800 pages
23h 55m
English
This lab includes both a driver and an executable. You can run the executable from anywhere, but in order for the program to work properly, the driver must be placed in the C:\Windows\System32 directory where it was originally found on the victim computer. The executable is Lab10-01.exe, and the driver is Lab10-01.sys.
Q: | 1. Does this program make any direct changes to the registry? (Use procmon to check.) |
Q: | 2. The user-space program calls the |
Q: | 3. What does this program do? |
The file for this lab is Lab10-02.exe.
Q: | 1. Does this program create any files? If so, what are they? ... |