Technical Information
- [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, WindowsLogon.exe'
- User Account Control (UAC)
- %WINDIR%\windowslogon
- %LOCALAPPDATA%\microsoft\windows\actioncentercache\windows-systemtoast-securityandmaintenance_10_0.png
- %ALLUSERSPROFILE%\ranede.flag