I summon the collective #DFIR wisdom of Twitter. User attempts to launch Windows Explorer and another program starts instead. I'm assuming a registry setting, but which one?
15
6
10
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
2
6
Replying to @MalwareJake
Sadly, Shell is set to explorer.exe

Oct 15, 2020 · 9:26 PM UTC

1
1
Replying to @hal_pomeranz
Then I'd guess HKCR with the possibility of a shell handler override in HKCU
1