Windows Tutorials - Herong's Tutorial Examples - v5.62, by Dr. Herong Yang
Startup Program Configuration - System Registry
This section provides a tutorial example on how to find where startup programs are defined in the Windows system registry in '...\Windows\CurrentVersion\Run'.
Where are the startup program configuration stored on my Windows system? The answer is in the HijackThis report. The startup program configuration is located in two areas:
For example, the following O4 line represents a startup program configuration in the HKEY_CURRENT_USER section of the Windows registry:
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger \YahooMessenger.exe" -quiet
More precisely, startup programs are configured in the Windows registry under two registry keys:
1. "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" - If you export this registry key by following the tutorial described in previous chapters, you will get something like this:
Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier \\GoogleToolbarNotifier.exe" "Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger \\YahooMessenger.exe\" -quiet" "NetZero_uoltray"="C:\\Program Files\\NetZero\\exec.exe regrun"
2. "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" - If you export this registry key by following the tutorial described in previous chapters, you will get something like this:
Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsmqIntCert"="regsvr32 /s mqrt.dll" "SoundMAXPnP"="C:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe" "SoundMAX"="C:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe /tray" "AccelerometerSysTrayApplet"="C:\\WINDOWS\\system32 \\AccelerometerSt.exe" "SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe" "QlbCtrl"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,... "Cpqset"="C:\\Program Files\\HPQ\\Default Settings\\cpqset.exe" "Recguard"="C:\\WINDOWS\\Sminst\\Recguard.exe" "Reminder"="C:\\WINDOWS\\Creator\\Remind_XP.exe" "Scheduler"="C:\\WINDOWS\\SMINST\\Scheduler.exe" "ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay" "ShStatEXE"="\"C:\\Program Files\\Network Associates\\VirusScan \\SHSTAT.EXE\" /STANDALONE" "McAfeeUpdaterUI"="\"C:\\Program Files\\Network Associates\\Common Framework\\UpdaterUI.exe\" /StartedFromRunKey" "KernelFaultCheck"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,... "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_03\\bin \\jusched.exe\"" "BaiduXUpdate"="\"C:\\Program Files\\Baidu\\BaiduX\\MovieUpdate.exe\" --Update" ...
Table of Contents
Introduction to Microsoft Windows
Introduction to Windows Explorer
Introduction to Internet Explorer
"Paint" Program and Computer Graphics
GIMP - GNU Image Manipulation Program
JPEG Image File Format Quality and Size
GIF Image File Format and Transparent Background
"WinZip" - ZIP File Compression Tool
"WinRAR" - RAR and ZIP File Compression Tool
FTP Server, Client and Commands
"FileZilla" - Free FTP Client and Server
Web Server Log Files and Analysis Tool - "Analog"
Spyware Adware Detection and Removal
IE Addon Program Listing and Removal
Vundo (VirtuMonde/VirtuMundo) - vtsts.dll Removal
Trojan and Malware "Puper" Description and Removal
VSToolbar (VSAdd-in.dll) - Description and Removal
Spybot - Spyware Blocker, Detection and Removal
Setting Up and Using Crossover Cable Network
Home Network Gateway - DSL Modem/Wireless Router
Windows Task Manager - The System Performance Tool
"tasklist" Command Line Tool to List Process Information
"msconfig" - System Configuration Tool
Configuring and Managing System Services
Windows Registry Key and Value Management Tools
►Startup Programs Removal for Better System Performance
System Extremely Slow - Bad Startup Programs
Getting a List of Startup Programs Using HijackThis
►Startup Program Configuration - System Registry
Startup Program Configuration - User Startup Folder
Removing ApacheMonitor.exe as a Startup Program
Removing BaiduX.exe as a Startup Program
Removing OpenOffice quickstart.exe as a Startup Program
Removing Microsoft Office OSA9.exe as a Startup Program
Removing GoogleUpdater.exe as a Startup Program
Removing NetZero exec.exe as a Startup Program
Removing YahooMessenger.exe as a Startup Program
Removing GoogleToolbarNotifier.exe as a Startup Program