Mastering Reverse Engineering
上QQ阅读APP看书,第一时间看更新

Startup values

The startup registry value contains the path to a folder which contains files that are executed after the user has logged in. The default folder location is at %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup.

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
    • Startup = [startup folder path]
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
    • Startup = [startup folder path]
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
    • Common Startup = [startup folder path]
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
    • Common Startup = [startup folder path]