I summon the collective #DFIR wisdom of Twitter. User attempts to launch Windows Explorer and another program starts instead. I'm assuming a registry setting, but which one?

Oct 15, 2020 · 8:32 PM UTC

15
6
10
Replying to @hal_pomeranz
Which explorer? The main desktop process or the file manager?
1
Replying to @hal_pomeranz
Debugger value under Image File Execution Options key? Just brainstorming. blog.malwarebytes.com/101/20…
1
3
Good idea, not the execution mechanism in this case
2
Replying to @hal_pomeranz
Recmd with SA parameter across all hives and search for the executable that launched? Then review the keys individually. May get lucky!
1
2
Yeah, that's basically what I'm down to at this point
Good thought, but I'm not finding any