Beyond good ol’ Run key, Part 127 + TestHooks bonus
https://www.hexacorn.com/blog/2020/09/06/beyond-good-ol-run-key-part-127-testhooks-bonus/ …
Test entries in Windows Update Registry config can potentially mod the way Windows works
#DFIR
-
-
Replying to @Hexacorn
dude-ive seen that name before...i think by default it tries to load it from c:\windows\installer
1 reply 0 retweets 0 likes -
Replying to @jonasLyk
hmm if that's the case, could possibly copy -- the only obstacle is the timestamp inside... always easier than spending hours in IDA which I am facing atm
1 reply 0 retweets 0 likes
Replying to @Hexacorn
i think its installer- i just know i myself have seen that file attempted loaded many times
11:25 AM - 6 Sep 2020
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.