The windows IR blog has a good discussion on the topic, but I found the best answer on Scot's Newsletter. Is it a way for malware to ensure it can persist and get started on reboot? Apparently not. When running programs, and got to wondering what they were. HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache
Recently I was seeing entries being created under