Looks like it's the WPBT ACPI table again. Lenovo was caught doing the same back in 2015: <a href="https://www.theregister.co.uk/2015/08/12/lenovo_firmware_nasty/" rel="nofollow">https://www.theregister.co.uk/2015/08/12/lenovo_firmware_nas...</a><p>Windows will just blindly execute the binary from the WPBT table on boot. Specifically, it's done by the Session Manager, the first user-mode process (%SystemRoot%\System32\smss.exe).<p>The WPBT table is dumped as %SystemRoot%\System32\wppbin.exe and then executed.<p>This behavior can apparently be disabled by a registry setting:<p>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager]<p>"DisableWpbtExecution"=dword:00000001<p>The previous time this happened, didn't Microsoft promise to keep this behavior on by default only in a corporate setting? Or maybe I'm misremembering.<p>(Edited to add more details.)