NtQuerryInformationProcess with ProcessInformationClass = 7 = ProcessDebugPort

The presence of NtSetInformationThread with ThreadInformationClass = 0x11 = ThreadHideFromDebugger means “the debugger will stop receiving debug information or exceptions from this thread.

Malware then checks if Windows was started in Normal boot or in Fail-safe boot. If Fail-safe boot is detected, malware then attempts to reboot the operating system.

https://blog.avast.com/2013/07/24/urausy-lockscreen-your-computer-will-remain-locked-for-3-days-11-hours-and-20-minutes/



🌱 Back to Garden