Malware Dictionary’s Guide to Modifying Windows Registry Entries

The Windows Operating System Registry is a database designed to store operating system configuration options and settings. Its purpose is to increase the overall speed of the operating system and has information for all system software, user-settings, as well as hardware components. The registry serves as a gateway of sorts for the Operating System Kernel. Unfortunately, the majority of computer malware and viruses will make modifications and changes to the registry of the infected computer. If you desire to manually remove computer malware, it will be necessary to make changes and modifications to the registry of the computer.

How to Backup the Windows Registry

You should always backup the Windows Registry before making any modifications. If you do not, then you run the risk of causing catostrophic damage to your computer’s operating system. The easiest means to make a full copy of the registry is to make a copy of the “System.dat” and “User.dat” files in your Windows directory and save them to a portable media device such as a blank CD or Thumb drive. You can also backup only a portion of the registry by taking the following steps:

- Select the “Start” menu and either “Run” if using a version of Windows that is XP or older, or typing “Command” in the Start Menu text field in Windows Vista.

- Type “Regedit” at the DOS prompt and select the “Ok” menu button.

- Choose “Export Registry File” from the Registry menu.

- Select the folder to save the backup file and type a name for the backup file name. Then choose the save menu option and the backup file will be saved.

Modifying Registry Entries

To make changes to existing registry entries:

1 – Open regedit and backup the key that you are going to change using the directions in the “Registry Backup” section of this article.

2 – Select the registry key to modify by single left clicking the entry. Then, right click the registry entry and choose the “Modify” menu option.

3 – Enter the new value in the “Value Data”box.

4 – Select the “Ok” menu option and then exit the Registry Editor.

Removing Registry Entries

1 – Open the Registry Editor and backup the key you are going to delete using the steps in the “Registry Backup” section of this article.

2 – Select the registry key you are going to delete by single left clicking the key.

3 – Choose the “delete” key on your keyboard or right click the key value and left click the “delete” menu option.

4 – Exit the Registry editor when complete.

Finding Registry References to File Names or Key Words

A number of times when manually removing computer viruses, you will be asked to search the registry for the virus’s common name in order to delete or modify registry keys and values.

1 – Open the Registry editor.

2 – Select “Edit->Find” from the Registry Edit menu. Then, enter the word, filename, or key word you are searching for in the Find text box.

3 – Select the “Next” menu button.

4 – View the first result returned by the Registry Editor. To find the next result of the search, select the “F3″ menu function key.

Related posts:

  1. Windows Guide: What is Error Code 5? Error Code 5 is a Windows Operating System error that...
  2. Windows Guide: Error 1402 A common error that can arise when you try to...
  3. Windows Guide: What is a Media Player c00d11b1 Error? The Windows Media Player has been the standard Microsoft produced...

Related posts brought to you by Yet Another Related Posts Plugin.

2 comments to Malware Dictionary’s Guide to Modifying Windows Registry Entries

Leave a Reply

 

 

 

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>