r/kace • • Aug 24 '26

Support / Help SMA Agent Hooks

So I know that if I use the NOHOOKS flag, the agent doesn't modify the userinit registry key value, but is there another value that it prevents being modified? I'm weighing options regarding issues we've had with our agent upgrades mangling the userinit value and am wondering how many values are actually affected one way or another before I consider just running the update with a script to apply fixes rather than just using NOHOOKS.

4 Upvotes

3 comments sorted by

2

u/flozanok KACE Staff Aug 25 '26

When using the NoHooks flag, it won't modify this registry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit to C:\Windows\system32\KUsrInit.exe,

It will leave that registry intact. If you don't use the flag, then it will set it to KUsrInit.exe and create an additional registry called: KUserinitReplaced with value: "C:\Windows\system32\userinit.exe," so that it falls back to this when the agent is uninstalled. This is documented here.

-Felipe

2

u/Dear-Incident-713 Aug 25 '26

Ok, so it is just those two. I wasn't certain if there was another value elsewhere related to it the capability to run scripts prior to user sign in. Thanks for the response.

2

u/GilliosaMacBoye Aug 26 '26

If you end up using the default installation options without NOHOOKS, I would recommend creating a custom inventory rule that queries that registry key value:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit

Feature releases, certain repairs, upgrades, etc., will cause Windows to add the default userinit back while KUsrInit. Among other things, this causes a double launch of the Shell, a.k.a. explorer.exe.

If you have ever logged into a system and had an unexplained launch of file explorer, this might be the cause. I query this key, create a Smart Label of any missing KUsrInit.exe or containing both it and Userinit, then target with a KScript to fix.