Home » Reference » Procedures » 

Removing Autostart Entries from the Registry

Removing autostart entries from the registry prevents the malware from executing during startup.

  • Open Registry Editor.
  • To do this, click Start>Run, type Regedit, then press Enter.
  • In the left panel, double-click the following:
    HKEY_LOCAL_MACHINE>
    Software>Microsoft>Windows>CurrentVersion>Run
  • In the right panel, locate and delete the entry:
    SysMonXP = "C:\Windows\SysMonXP.exe"
    Jammer2nd="%Windows%\Jammer2nd.exe"
    Note: %Windows% is the default Windows folder, usually C:\Windows or C:\WINNT.
  • Close Registry Editor.
  • Restart your computer.

 

 


Mail this pageMail this page