Quiz 14 Question 11 of 20

An attacker uses the command reg add HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon /v Userinit /d C:\Windows\system32\userinit.exe,C:\Users\Public\backdoor.exe. What persistence mechanism is being established?

Select an answer to reveal the explanation.

Motivation