diff --git a/atomics/T1112/T1112.md b/atomics/T1112/T1112.md index 9382b02d..26fb413a 100644 --- a/atomics/T1112/T1112.md +++ b/atomics/T1112/T1112.md @@ -109,6 +109,7 @@ for ($p = 0; $p -lt ($ProfileList | Measure-Object).count; $p++) Write-Verbose -Message 'Attempting to modify registry keys for each profile' ##################################################################### reg add "HKEY_CURRENT_USER\$($ProfileList[$p].SID)\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /t REG_DWORD /v HideFileExt /d 1 /f + } } } @@ -116,6 +117,7 @@ Write-Verbose 'Unloading Registry hives for all users' # Unload ntuser.dat ### Garbage collection and closing of ntuser.dat ### [gc]::Collect() -reg unload "HKU\$($ProfileList[$p].SID)" +cmd /c start reg unload "HKU\$($ProfileList[$p].SID)" + ```