Run Keys

https://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Worm%3AWin32%2FPushbot.QV
https://blogs.technet.microsoft.com/askperf/2010/12/10/terminal-services-exploring-the-shadows/
https://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Worm%3AWin32%2FNeubreku.C
$data += [PSObject] @{Path='HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion'; Entries='Run','RunOnce','RunonceEx'}
$data += [PSObject] @{Path='HKCU:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion'; Entries='Run','RunOnce','RunonceEx'}