We don't expect Linux to do this, do we? Just use full disk encryption, preferably with pre-boot authentication. TPM if you must, but this will only make the attack somewhat more expensive. Other than that, the hardware is compromised as soon as somebody gets their hands on it. Checking the integrity of a few binaries is mostly security theater.
Besides manipulating executables, the adversary could simply modify or read the user database in C:\Windows\System32\config\SAM. [1]
Alternatively, patch routines directly in memory [2]