HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [EnableGoodbye] HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [EnableGoodbye] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableCad] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ScreenSaverGracePeriod] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeCaption] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeText] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableLockWorkstation] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ReportControllerMissing] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [AutoRestartShell] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [PasswordExpiryWarning] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [NoDebugThread] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableCad] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [cachedlogonscount] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [USERINIT] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [Shell] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ARSOUserConsent] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\UserARSO\* [*] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [TBALIgnorePolicyTestHook] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ForceAutoLockOnLogon] HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon [Shell] MigXmlHelper.DoesObjectExist( "File", "%windir%\system32 [scregedit.wsf]" ) MigXmlHelper.DoesStringContentContain("Registry", "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [Shell]", " & start cmd.exe /k runonce.exe /AlternateShellStartup") HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [Shell] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ScreenSaverGracePeriod] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeCaption] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeText] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableLockWorkstation] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ReportControllerMissing] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [AutoRestartShell] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [PasswordExpiryWarning] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [NoDebugThread] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableCad] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [cachedlogonscount] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [Shell] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ARSOUserConsent] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\UserARSO\* [*] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [TBALIgnorePolicyTestHook] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ForceAutoLockOnLogon] HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon [Shell]