HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableCad] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ScreenSaverGracePeriod] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeCaption] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeText] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableLockWorkstation] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ReportControllerMissing] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [AutoRestartShell] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [PasswordExpiryWarning] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [NoDebugThread] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableCad] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [cachedlogonscount] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [USERINIT] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [Shell] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ARSOUserConsent] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [TBALIgnorePolicyTestHook] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ForceAutoLockOnLogon] MigXmlHelper.DoesObjectExist( "File", "%windir%\system32 [scregedit.wsf]" ) MigXmlHelper.DoesStringContentContain("Registry", "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [Shell]", " & start cmd.exe /k runonce.exe /AlternateShellStartup") HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [Shell] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ScreenSaverGracePeriod] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeCaption] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeText] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableLockWorkstation] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ReportControllerMissing] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [AutoRestartShell] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [PasswordExpiryWarning] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [NoDebugThread] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableCad] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [cachedlogonscount] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [Shell] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ARSOUserConsent] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [TBALIgnorePolicyTestHook] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ForceAutoLockOnLogon]