Explorer\Shell

http://resources.infosecinstitute.com/common-malware-persistence-mechanisms/#gref
$data += [PSObject] @{Path='HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\'; Entries='Shell'}
$data += [PSObject] @{Path='HKCU:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\'; Entries='Shell'}
$data += [PSObject] @{Path='HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\'; Entries='Shell'}
$data += [PSObject] @{Path='HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\System\'; Entries='Shell'}
$data += [PSObject] @{Path='HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\'; Entries='Shell Folders','User Shell Folders'}
$data += [PSObject] @{Path='HKLM:\Software\Microsoft\Windows\CurrentVersion\Explorer\'; Entries='Shell Folders','User Shell Folders'}