Yesterday I compiledProgramThe following error occurs: I ran cmd.exe at runtime, and the result window was just a flash.
No way, I can only find the cmd.exe file under the % SystemRoot %/system32directory directory. The result of double-clicking is still a flash in the window.
I copied it to the desktop and changed the file name to run it again.
Then, I run % SystemRoot %/system32/cmd.exe from the shell that can be run. The following result is displayed:
C:/> C:/Windows/system32/cmd.exe (Press ENTER)
C:/Windows/system32/cmd.exe builtin/users: R
Builtin/Power Users: R
Builtin/administrators: F
Nt authority/system: F
How does it obtain permissions? It seems that another command is executed:
C:/> cacls C:/Windows/system32/cmd.exe
I was puzzled. Then I suddenly remembered that this is not the image file execution option (ifeo) image hijacking?
in the registry, set [HKEY_LOCAL_MACHINE/software/Microsoft/Windows NT/CurrentVersion/Image File Execution options/CMD. EXE]
"Debugger" = "C: // windows // system32 // cacls.exe" is deleted, and the problem is solved.