Tendvane

← All articles

SecuritySeptember 12, 2026

Windows just deleted a tool ransomware used to wipe out your restore points

Type wmic into a Command Prompt on a PC that has installed the September update and you get an error. The command had shipped with Windows since 2000. As of this month it is gone, and that is the point.

WMIC was the command-line front end to Windows Management Instrumentation, the machinery that lets software ask Windows about itself: which disks are attached, which processes are running, what the serial number is. Administrators wrote scripts with it. Ransomware found another use. Because wmic.exe is a genuine Microsoft-signed component, running it does not look like an unknown program launching, and a single line of it would delete every Volume Shadow Copy on the drive. Shadow copies are what Previous Versions and System Restore are built on, so wiping them is how encrypting malware made sure you could not simply roll the machine back. TeslaCrypt and WannaCry both did it, and plenty have since.

Microsoft deprecated the tool in 2021 and has been dismantling it in stages ever since. KB5124008, the 8 September update, finishes the job on Windows 11 24H2, 25H2 and 26H1, where it is no longer even available as an optional Windows feature. There is a script on Microsoft's support page for anyone whose old software still depends on it, published alongside a blunt suggestion to stop depending on it. WMI itself is untouched and still supported, so nothing you actually use day to day is disappearing.

This closes one door rather than the building, and it is worth remembering what shadow copies always were: a convenience living on the same drive as the files they restore. A dead disk or a determined attacker takes both at once. The copy that saves you is the one on separate hardware, which is what Tendvane's one-click backup of Documents, Pictures and Desktop is for.

Sources

Download Tendvane