Command Processor AutoRun - Registry Value

This section provides a tutorial example on how to review the HKLM\SOFTWARE\Microsoft\Command Processor registry key. The registry value AutoRun = C:\WINDOWS\system32\sovhst.exe was removed.

While using the command window program, cmd.exe, I noticed a strange error:

Click Start > Run, enter "cmd" and press Enter, the following message shows up:

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.
'C:\WINDOWS\system32\sovhst.exe' is not recognized as an internal 
or external command, operable program or batch file.

My guess was that the PWS Trojan changed the AutoRun registry value. I browsed the registry tree with regedit.exe and found this:

HKLM\SOFTWARE\Microsoft\Command Processor
   AutoRun   C:\WINDOWS\system32\sovhst.exe

I changed the value of AutoRun to blank, and tested "cmd" again. The problem went away.

Last update: 2006.

