| MsConfig Tab | Entry Type | Registry Path/In Folder | User Affected | Usage | Threat scale |
| STARTUP | Folder | %ALLUSERSPROFILE%\Start Menu\Programs\Startup | All | MEDIUM | EASY |
|
STARTUP Only for the current user |
Folder | %USERPROFILE%\Start Menu\Programs\Startup | Current User | MEDIUM | EASY |
| STARTUP | Registry Key |
HKEY_LOCAL_MACHINE\SOFTWARE\ Microsoft\Windows\CurrentVersion\Run |
All | HIGH | EASY |
| STARTUP | Registry Key |
HKEY_LOCAL_MACHINE\SOFTWARE\ Microsoft\Windows\CurrentVersion\RunOnce |
All |
LOW
|
MEDIUM
|
|
STARTUP Only for the current user |
Registry Key | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Run= or Load= | Current User | HIGH | EASY |
| STARTUP | Registry Key/File entry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows Run= or Load= | All | LOW | DANGEROUS |
| SERVICES | Registry Key |
HKEY_LOCAL_MACHINE\SYSTEM\ CURRENTCONTROLSET(001/002)\SERVICES |
All | MEDIUM | DANGEROUS |
| NOT LISTED | Registry Key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\Winlogon; ENTRY: <SHELL=EXPLORER.EXE <THREAT_LOCATION>> or <SHELL= DIFFERENT THAN EXPLORER.EXE> or <Userinit=DIFFERENT THAN C:\WINDOWS\SYSTEM32\USERINIT.EXE> | All |
LOW
|
EXTREME - RUNS IN SAFE MODE |