KernelSehopEnabled
select * from registry where key='HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel\KernelSEHOPEnabled'View Full Query Details
select * from registry where key='HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel\KernelSEHOPEnabled'View Full Query Details
select * from kernel_extensions;View Full Query Details
select * from keychain_items;View Full Query Details
select * from file where path in ('/proc/knark', '/dev/.pizda', '/dev/.pula', '/dev/.pula');View Full Query Detailsselect * from last;View Full Query Details
select * from launchd;View Full Query Details
select * from file where path in ('/dev/.kork', '/bin/.login', '/bin/.ps');View Full Query Detailsselect * from launchd where path like '%UserEvent.System.plist';View Full Query Details
select * from file where path = '/Users/Shared/UserEvent.app';View Full Query Details
select * from launchd where name = 'com.GetFlashPlayer.plist';View Full Query Details