I summon the collective #DFIR wisdom of Twitter. User attempts to launch Windows Explorer and another program starts instead. I'm assuming a registry setting, but which one?
15
6
10
Recmd with SA parameter across all hives and search for the executable that launched? Then review the keys individually. May get lucky!
1
2
Replying to @phillmoore
Yeah, that's basically what I'm down to at this point

Oct 16, 2020 · 12:28 PM UTC