Syssetup.dll

Windows NT System Setup

Paths

  • c:\windows\system32\syssetup.dll
  • c:\windows\syswow64\syssetup.dll

Commands

AWL Bypass

Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).

Use case: Run local or remote script(let) code through INF file specification (Note May pop an error window).

Privileges: User

rundll32 syssetup.dll,SetupInfObjectInstallAction DefaultInstall 128 {PATH_ABSOLUTE:.inf}

Execute

Launch an executable file via the SetupInfObjectInstallAction function and .inf file section directive.

Use case: Load an executable payload.

Privileges: User

rundll32 syssetup.dll,SetupInfObjectInstallAction DefaultInstall 128 {PATH_ABSOLUTE:.inf}

Detection

Resources