Total Pageviews

Blog Archive

Saturday, 23 August 2014

Sethc.exe



How to delete Sethc



Sethc act as a backdoor to bypass normal authentication.

Sethc is used to enable sticky keys.

C:\Windows\System32 .........sethc.exe

Pressing Shift key 5 times enables the sticky key mode.

But if sethc is replcaed by cmd.exe then instead of sticky keys , cmd.exe gets executed

So deletion of sethc.exe is must.

Many a times it happens while deleting sethc.exe some error comes.

Its generally of trusted supplier.

Now.....

Right Click on sethc - > Properties ->secrity tab ->advanced Tab


Now,

Remove tick marks on all allow and deny permissions of Trusted Installer.


and for admin , give full control.

Trusted installer disappears.

Click on owner tab.

Current Owner Select Administrator.


Apply -> OK

If any Message box is displayed click on Yes or Ok.

Now,

Delete sethc , make copy of cmd and rename it sethc.

Now when windows logon.


Press Shift key 5 times , command prompt appers.
net user (account_name) (new password)


Now the new password is gpt@123



No comments:

Post a Comment