<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Playing with utilman.exe</title>
	<atom:link href="http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Wed, 08 Feb 2012 19:23:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: dooshy</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-46806</link>
		<dc:creator><![CDATA[dooshy]]></dc:creator>
		<pubDate>Tue, 25 Oct 2011 22:29:02 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-46806</guid>
		<description><![CDATA[This is very interesting, I will probably use this to run some nifty shortcuts or make a useless nuke button or maybe even a lockdown......

I made it more stealthy and efficient by adding a command that takes ownership of files along with xcopy, after that it issues the &quot;shutdown -r -f -t 00&quot; which is very hx0rish.... Slightly dumb and stupid, yes. Cool factor 10. I like the http://www.howtogeek.com/howto/windows-vista/change-your-forgotten-windows-password-with-the-linux-system-rescue-cd/ article to make a guest account admin privileges.....

Sad part is if you have Heirens boot cd on a usb than you just boot click create admin and restart....]]></description>
		<content:encoded><![CDATA[<p>This is very interesting, I will probably use this to run some nifty shortcuts or make a useless nuke button or maybe even a lockdown&#8230;&#8230;</p>
<p>I made it more stealthy and efficient by adding a command that takes ownership of files along with xcopy, after that it issues the &#8220;shutdown -r -f -t 00&#8243; which is very hx0rish&#8230;. Slightly dumb and stupid, yes. Cool factor 10. I like the <a href="http://www.howtogeek.com/howto/windows-vista/change-your-forgotten-windows-password-with-the-linux-system-rescue-cd/" rel="nofollow">http://www.howtogeek.com/howto/windows-vista/change-your-forgotten-windows-password-with-the-linux-system-rescue-cd/</a> article to make a guest account admin privileges&#8230;..</p>
<p>Sad part is if you have Heirens boot cd on a usb than you just boot click create admin and restart&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-43589</link>
		<dc:creator><![CDATA[Anonymous]]></dc:creator>
		<pubDate>Sat, 11 Jun 2011 14:57:54 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-43589</guid>
		<description><![CDATA[nice idea]]></description>
		<content:encoded><![CDATA[<p>nice idea</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: qwertyoruiop</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-39112</link>
		<dc:creator><![CDATA[qwertyoruiop]]></dc:creator>
		<pubDate>Fri, 16 Jul 2010 13:40:26 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-39112</guid>
		<description><![CDATA[I know this post is outdated, but a way to hack WFP is:

type hack.exe &gt; utilman.exe

:D]]></description>
		<content:encoded><![CDATA[<p>I know this post is outdated, but a way to hack WFP is:</p>
<p>type hack.exe &gt; utilman.exe<br />
 <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-38971</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Mon, 21 Jun 2010 16:26:00 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-38971</guid>
		<description><![CDATA[@prashant Interesting, but note that your simple solution must work on XP. Doing this on Vista or Win 7 is trivial.]]></description>
		<content:encoded><![CDATA[<p>@prashant Interesting, but note that your simple solution must work on XP. Doing this on Vista or Win 7 is trivial.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: prashant</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-38969</link>
		<dc:creator><![CDATA[prashant]]></dc:creator>
		<pubDate>Mon, 21 Jun 2010 05:34:41 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-38969</guid>
		<description><![CDATA[guys  i can provide u much more simple way to replace utilman.exe as well as get entry into windows..

 which is quite easy ..


jus wait for my next post.. i ll provide u link of my blog..]]></description>
		<content:encoded><![CDATA[<p>guys  i can provide u much more simple way to replace utilman.exe as well as get entry into windows..</p>
<p> which is quite easy ..</p>
<p>jus wait for my next post.. i ll provide u link of my blog..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-38120</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Mon, 05 Apr 2010 07:37:21 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-38120</guid>
		<description><![CDATA[@Aman Khan http://blog.didierstevens.com/2006/08/31/my-second-playdate-with-utilmanexe/]]></description>
		<content:encoded><![CDATA[<p>@Aman Khan <a href="http://blog.didierstevens.com/2006/08/31/my-second-playdate-with-utilmanexe/" rel="nofollow">http://blog.didierstevens.com/2006/08/31/my-second-playdate-with-utilmanexe/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aman Khan</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-38119</link>
		<dc:creator><![CDATA[Aman Khan]]></dc:creator>
		<pubDate>Mon, 05 Apr 2010 05:07:42 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-38119</guid>
		<description><![CDATA[When I used Windows Logo Key + U utility manager comes. In which 
* Magnifier is not running
* Narrator is running
* On screen Keyboard is not running
Options comes.

Please tell me how can I get CMD window.]]></description>
		<content:encoded><![CDATA[<p>When I used Windows Logo Key + U utility manager comes. In which<br />
* Magnifier is not running<br />
* Narrator is running<br />
* On screen Keyboard is not running<br />
Options comes.</p>
<p>Please tell me how can I get CMD window.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-35875</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Tue, 06 Oct 2009 19:06:00 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-35875</guid>
		<description><![CDATA[And you&#039;ve done the necessary to prevent Windows File Protection from restoring the original utilman.exe?

You can try what&#039;s explained in comment #16 as an alternative to circumventing WFP.]]></description>
		<content:encoded><![CDATA[<p>And you&#8217;ve done the necessary to prevent Windows File Protection from restoring the original utilman.exe?</p>
<p>You can try what&#8217;s explained in comment #16 as an alternative to circumventing WFP.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MF</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-35869</link>
		<dc:creator><![CDATA[MF]]></dc:creator>
		<pubDate>Tue, 06 Oct 2009 06:13:33 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-35869</guid>
		<description><![CDATA[Yes, I compiled the third example and replaced the &quot;Default&quot;-Desktop with &quot;Winlogon&quot;.

Still not working...]]></description>
		<content:encoded><![CDATA[<p>Yes, I compiled the third example and replaced the &#8220;Default&#8221;-Desktop with &#8220;Winlogon&#8221;.</p>
<p>Still not working&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-35865</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Mon, 05 Oct 2009 16:28:59 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-35865</guid>
		<description><![CDATA[It only works if you compile the program and replace utilman.exe with it.]]></description>
		<content:encoded><![CDATA[<p>It only works if you compile the program and replace utilman.exe with it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

