HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
\”PolicyRun” = “%SystemDrive%\spoolsv32.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
\”winmgmt” = “%SystemDrive%\wmiprvse.exe”
HKEY_USERS\S-1-5-21-1961063573-973683775-492528769-500\Software\Microsoft\Windows
\CurrentVersion\Run\”winmgmt” = “%SystemDrive%\wmiprvse.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
\”Shell” = “Explorer.exe %SystemDrive%\spoolsv32.exe”
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrkWks
\”ImagePath” = “%SystemDrive%\spoolsv32.exe”
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrkWks
\”ImagePath” = “%SystemDrive%\spoolsv32.exe”
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkWks
\”ImagePath” = “%SystemDrive%\spoolsv32.exe”
Bookmarks