Runexehelper.exe

Launcher process

Paths

  • c:\windows\system32\runexehelper.exe

Commands

Execute

Launches the specified exe. Prerequisites: (1) diagtrack_action_output environment variable must be set to an existing, writable folder; (2) runexewithargs_output.txt file cannot exist in the folder indicated by the variable.

Use case: Executes arbitrary code

Privileges: User

runexehelper.exe {PATH_ABSOLUTE:.exe}

Detection

Resources