Startup Program Configuration - System Registry

This section provides a tutorial example on how to find where startup programs are defined in the Windows system registry in '...\Windows\CurrentVersion\Run'.

Where are the startup program configuration stored on my Windows system? The answer is in the HijackThis report. The startup program configuration is located in two areas:

For example, the following O4 line represents a startup program configuration in the HKEY_CURRENT_USER section of the Windows registry:

O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger
                  \YahooMessenger.exe" -quiet

More precisely, startup programs are configured in the Windows registry under two registry keys:

1. "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" - If you export this registry key by following the tutorial described in previous chapters, you will get something like this:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier
   \\GoogleToolbarNotifier.exe"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger
   \\YahooMessenger.exe\" -quiet"
"NetZero_uoltray"="C:\\Program Files\\NetZero\\exec.exe regrun"

2. "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" - If you export this registry key by following the tutorial described in previous chapters, you will get something like this:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="regsvr32 /s mqrt.dll"
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"
"SoundMAX"="C:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe 
   /tray"
"AccelerometerSysTrayApplet"="C:\\WINDOWS\\system32
   \\AccelerometerSt.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"QlbCtrl"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,...
"Cpqset"="C:\\Program Files\\HPQ\\Default Settings\\cpqset.exe"
"Recguard"="C:\\WINDOWS\\Sminst\\Recguard.exe"
"Reminder"="C:\\WINDOWS\\Creator\\Remind_XP.exe"
"Scheduler"="C:\\WINDOWS\\SMINST\\Scheduler.exe"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\"
   runtime -Delay"
"ShStatEXE"="\"C:\\Program Files\\Network Associates\\VirusScan
   \\SHSTAT.EXE\" /STANDALONE"
"McAfeeUpdaterUI"="\"C:\\Program Files\\Network Associates\\Common
   Framework\\UpdaterUI.exe\" /StartedFromRunKey"
"KernelFaultCheck"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,...
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_03\\bin
   \\jusched.exe\""
"BaiduXUpdate"="\"C:\\Program Files\\Baidu\\BaiduX\\MovieUpdate.exe\"
   --Update"
...

Table of Contents

 About This Book

 Introduction to Microsoft Windows

 Introduction to Windows Explorer

 Introduction to Internet Explorer

 "Paint" Program and Computer Graphics

 GIMP - GNU Image Manipulation Program

 JPEG Image File Format Quality and Size

 GIF Image File Format and Transparent Background

 "WinZip" - ZIP File Compression Tool

 "WinRAR" - RAR and ZIP File Compression Tool

 FTP Server, Client and Commands

 "FileZilla" - Free FTP Client and Server

 Web Server Log Files and Analysis Tool - "Analog"

 Spyware Adware Detection and Removal

 IE Addon Program Listing and Removal

 Vundo (VirtuMonde/VirtuMundo) - vtsts.dll Removal

 Trojan and Malware "Puper" Description and Removal

 VSToolbar (VSAdd-in.dll) - Description and Removal

 Spybot - Spyware Blocker, Detection and Removal

 Setting Up and Using Crossover Cable Network

 Home Network Gateway - DSL Modem/Wireless Router

 Windows Task Manager - The System Performance Tool

 "tasklist" Command Line Tool to List Process Information

 "msconfig" - System Configuration Tool

 Configuring and Managing System Services

 Windows Registry Key and Value Management Tools

Startup Programs Removal for Better System Performance

 System Extremely Slow - Bad Startup Programs

 Getting a List of Startup Programs Using HijackThis

Startup Program Configuration - System Registry

 Startup Program Configuration - User Startup Folder

 Removing ApacheMonitor.exe as a Startup Program

 Removing BaiduX.exe as a Startup Program

 Removing OpenOffice quickstart.exe as a Startup Program

 Removing Microsoft Office OSA9.exe as a Startup Program

 Removing GoogleUpdater.exe as a Startup Program

 Removing NetZero exec.exe as a Startup Program

 Removing YahooMessenger.exe as a Startup Program

 Removing GoogleToolbarNotifier.exe as a Startup Program

 Removing Java Update jusched.exe as a Startup Program

 Winsock - Windows Sockets API

 Java on Windows

 Glossary of Terms

 Outdated Tutorials

 References

 Full Version in PDF/ePUB