Does this fix it?
Does this fix it?
The settings can be changed with bcdedit:
bcdedit /set {default} recoveryenabled No
bcdedit /set {default} bootstatuspolicy ignoreallfailures
Additionally booting from USB/... should be disabled in the BIOS/UEFI options and also access to that should be password secured.Further more because the person has physical access, the computer should be locked away so that the harddrive can't be accessed. Also all cables should be secured so that no sniffer can be plugged in between. This also especially includes the USB ports on the monitor if those are enabled.
To paraphrase another comment from imgur: If the hacker has physical access to the machine, it's now their machine.
Binding sticky keys to CMD is one of the worst ways as it can be detected easily (either via people trying to use Magnifier and getting CMD, hitting shift 5x times, etc), it can be fixed by Windows updates even by accident (and will be fixed via SFC), and could allow other competing "hackers" to access the machine.
I've never seen anyone use this trick in reality and I've certainly never read about "hackers" using it. They typically like to use a tiny single-file VNC server with a hardcoded user/password.