Beyond good ol’ Run key, Part 155
文章探讨了利用GOG游戏平台实现持久性的一种方法。通过修改注册表中与GOG游戏相关的键值(如SOFTWARE\GOG.com\Games\*),将原本指向GOG DLL的值替换为代理DLL,从而在受监控环境中维持存在。 2026-1-3 20:8:27 Author: www.hexacorn.com(查看原文) 阅读量:6 收藏

Leveraging popular software for persistence is a clever way to survive in heavily monitored environments of today. The last post discussed GhostScript, and today I will cover a popular gaming platform called GOG.

Games using GOG use HKLM Registry configuration stored under keys listed below (this is a representative subset, obviously):

  • SOFTWARE\GOG.com\Games\1207662533
  • SOFTWARE\GOG.com\Games\1207664543
  • SOFTWARE\GOG.COM\Games\1207664623
  • SOFTWARE\GOG.com\Games\1207665673
  • SOFTWARE\GOG.COM\GOGADVENTURESSHUGGY
  • SOFTWARE\GOG.COM\GOGANODYNE
  • SOFTWARE\GOG.COM\GOGDARKLANDS
  • SOFTWARE\GOG.COM\GOGEARTH2140D
  • SOFTWARE\GOG.COM\GOGGOBLINS1
  • SOFTWARE\GOG.COM\GOGGOBLINS1FDD
  • SOFTWARE\GOG.COM\GOGGOBLINS2
  • SOFTWARE\GOG.COM\GOGGOBLINS2FDD
  • SOFTWARE\GOG.COM\GOGGOBLINS3
  • SOFTWARE\GOG.COM\GOGGOBLINS3FDD
  • SOFTWARE\GOG.COM\GOGINTERSTATE82
  • SOFTWARE\GOG.COM\GOGLAMULANA
  • SOFTWARE\GOG.COM\GOGRETURNTOKRONDOR
  • SOFTWARE\GOG.COM\GOGT7G

The thing is, that under these keys, there is a Registry ValueName called GOGGAMEDLL that points to a GOG DLL – and as you suspect, this entry can be potentially replaced by a proxy DLL.


文章来源: https://www.hexacorn.com/blog/2026/01/03/beyond-good-ol-run-key-part-155/
如有侵权请联系:admin#unsafe.sh