- HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows contains a Run Key.
- A similar structure is in HKEY_USERS\.DEFAULT.
- Additionally, HKLM\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon will have a Shell Key. Be very
careful here. The default entry contains EXPLORER.EXE. A comma separates
any additional data. If you edit this entry, be sure to remove the referencing
file, and the comma just preceding it.
Another Key in this same area is UserInit. Again, be very cautious, the default entry is USERINIT, NDDEAGNT.EXE. Do not remove this value.