<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Przemysław Łukawski&#039;s blog &#187; Windows Explorer</title>
	<atom:link href="http://p-lider.lideve.eu/wordpress/?cat=14&#038;feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://p-lider.lideve.eu/wordpress</link>
	<description>Solutions for IT technical problems admins and developers may face with.</description>
	<lastBuildDate>Tue, 23 Sep 2014 18:29:49 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=4.2.22</generator>
	<item>
		<title>Windows registry autorun locations</title>
		<link>http://p-lider.lideve.eu/wordpress/?p=159</link>
		<comments>http://p-lider.lideve.eu/wordpress/?p=159#comments</comments>
		<pubDate>Sun, 17 Nov 2013 12:14:46 +0000</pubDate>
		<dc:creator><![CDATA[p_lider]]></dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[Windows 8]]></category>
		<category><![CDATA[Windows Explorer]]></category>
		<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows Server 2008 and 2008 R2]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://p-lider.lideve.eu/wordpress/?p=159</guid>
		<description><![CDATA[Many times people ask me to check their computers for malware or for the reason it is working slow. The first thing I do is to check all programs that automatically start with windows. Normally I remember 4 or 5 locations in registry where to look for such programs and almost all the time I [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>Many times people ask me to check their computers for malware or for the reason it is working slow. The first thing I do is to check all programs that automatically start with windows. Normally I remember 4 or 5 locations in registry where to look for such programs and almost all the time I must search the internet for another ones. That made me to write this post, which will allow me to always have the full (or almost full) list about the registry locations for auto startup purpose in one place.</p>
<p>In the below table I described all of the registry locations I know which programs are using to start automatically with Windows:</p>
<style>
.descrcell {
	border: 1px solid #000000; 
	padding-top: 0cm; padding-bottom: 0.1cm; padding-left: 0.1cm; padding-right: 0.1cm;
}
.tablecell {
	border: 1px solid #000000;
	padding-top: 0cm;
	padding-bottom: 0.1cm;
	padding-left: 0.1cm;
	padding-right: 0cm;
}
</style>
<div style="overflow: auto; height:500px;">
<table width="707" cellspacing="0" cellpadding="4">
<colgroup>
<col width="15" />
<col width="360" />
<col width="200" /></colgroup>
<tbody>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><b>No.</b></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><b>Registry Location (<span style="color: #0047ff;">blue </span>ones are present in 64bit OS only)</b></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><b>Description</b></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">1</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKML\Software\Microsoft\Windows\CurrentVersion\Run\</span></p>
<p lang="en-US"><span style="color: #0047ff;"><span style="">HKML\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\</span></span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">All values<br />
under this key are executed when any user logs in.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">2</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKML\Software\Microsoft\Windows\CurrentVersion\RunOnce\</span></p>
<p lang="en-US"><span style="color: #0047ff;"><span style="">HKML\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\</span></span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">All values<br />
under this key are executed when any user logs in. After execution<br />
the values are being deleted.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">3</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKML\Software\Microsoft\Windows\CurrentVersion\RunServices\</span></p>
<p lang="en-US"><span style="color: #0047ff;"><span style="">HKML\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices\</span></span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">All values<br />
under this key are executed as services when any user logs in.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">4</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKML\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce\</span></p>
<p lang="en-US"><span style="color: #0047ff;"><span style="">HKML\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce\</span></span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">All values<br />
under this key are executed as services when any user logs in.<br />
After execution the values are being deleted.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">5</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKCU\Software\Microsoft\Windows\CurrentVersion\Run\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">All values<br />
under this key are executed when current user logs in.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">6</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">All values<br />
under this key are executed when current user logs in. After<br />
execution the values are being deleted.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">7</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\Setup\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Used only by<br />
setup. A progress bar is being displayed.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">8</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKU\.Default\Software\Microsoft\Windows\CurrentVersion\Run\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Same as 5 but<br />
applies to LOCAL SYSTEM user only.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">9</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKU\.Default\Software\Microsoft\Windows\CurrentVersion\RunOnce\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Same as 6 but<br />
applies to LOCAL SYSTEM user only.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">10</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\Software\Microsoft\Windows<br />
NT\CurrentVersion\Winlogon\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US">„<span style="">Shell”<br />
and „Userinit” values contain file names separated<br />
with comma which are executed when any user logs in.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">11</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKCU\Software\Microsoft\Windows<br />
NT\CurrentVersion\Winlogon\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US">„<span style="">Shell”<br />
and „Userinit” values contain file names separated<br />
with comma which are executed when current user logs in.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">12</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\Software\Microsoft\Active<br />
Setup\Installed Components\</span></p>
<p lang="en-US"><span style="color: #0047ff;"><span style="">HKLM\Software\Wow6432Node\Microsoft\Active<br />
Setup\Installed Components\</span></span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">All subkeys<br />
are evaluated for execution when any user logs in. The “StubPath”<br />
value under each subkey describes the program being run.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">13</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKCU\Control<br />
Panel\Desktop</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US">„<span style="">SCRNSAVE.EXE”<br />
value is executed when screen saver is being displayed for current<br />
user.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">14</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\System\CurrentControlSet\Control\Session<br />
Manager\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">The<br />
„BootExecute” value is being executed at boot time.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">15</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\System\Control\WOW\cmdline</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Value is<br />
executed when 16 bit application is being run for all users.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">16</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\System\Control\WOW\wowcmdline</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Value is<br />
executed when 16 bit DOS application is being run for all users.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">17</span></p>
</td>
<td sclass="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\</span></p>
<p lang="en-US"><span style="color: #0047ff;"><span style="">HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad\</span></span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Values<br />
contains GUID for COM library which is being run after explorer<br />
finished loading.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">18</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKCU\Software\Microsoft\Windows<br />
NT\CurrentVersion\Windows\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">The „run”<br />
and „load” values are executed when current user logs<br />
in. </span></p>
<p lang="en-US">
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">19</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\Software\Microsoft\Windows<br />
NT\CurrentVersion\Windows\AppInit_DLLs</span></p>
<p lang="en-US"><span style="color: #0047ff;"><span style="">HKLM\Software\Wow6432Node\Microsoft\Windows<br />
NT\CurrentVersion\Windows\AppInit_DLLs</span></span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">AppInit_DLLs<br />
value contains dll file names separated with comma which are being<br />
loaded into every process being run in the system.</span></p>
<p lang="en-US"><span style=""><strong>IMPORTANT</strong>:<br />
Very dangerous entry used by many malware programs.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">20</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Same as 5.<br />
Normally values are named here as numbers starting from „1”.</span></p>
</td>
</tr>
<tr valign="TOP">
<td class="tablecell" width="15">
<p lang="en-US"><span style="">21</span></p>
</td>
<td class="tablecell" width="360">
<p lang="en-US"><span style="">HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run\</span></p>
</td>
<td class="descrcell" width="226">
<p lang="en-US"><span style="">Same as 1.<br />
Normally values are named here as numbers starting from „1”.</span></p>
</td>
</tr>
</tbody>
</table>
</div>
<p>Some information in the above table has been taken from this forum: <a href="https://forums.hak5.org/index.php?/topic/12112-registry-autostart-locations/">Registry AutoStart Locations</a></p>
]]></content:encoded>
			<wfw:commentRss>http://p-lider.lideve.eu/wordpress/?feed=rss2&#038;p=159</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Double clicking the disks icons opens search window instead of their contents</title>
		<link>http://p-lider.lideve.eu/wordpress/?p=87</link>
		<comments>http://p-lider.lideve.eu/wordpress/?p=87#comments</comments>
		<pubDate>Mon, 06 Sep 2010 08:10:25 +0000</pubDate>
		<dc:creator><![CDATA[p_lider]]></dc:creator>
				<category><![CDATA[Windows Explorer]]></category>
		<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://p-lider.rootnode.net/wordpress/?p=87</guid>
		<description><![CDATA[If the default action for disk drives in &#8220;My Computer&#8221; window is &#8220;Search&#8221; instead of &#8220;Open&#8221; and you cannot change this behavior using &#8220;File Types&#8221; tab in &#8220;Folder Options&#8221; then you must set the default value for HKCR\Drive\Shell registry key to none and restart the explorer.exe process. Mentioned problem sometimes arises after some malware installation &#8211; the disinfection [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>If the default action for disk drives in &#8220;My Computer&#8221; window is &#8220;Search&#8221; instead of &#8220;Open&#8221; and you cannot change this behavior using &#8220;File Types&#8221; tab in &#8220;Folder Options&#8221; then you must set the default value for <span style="white-space: nowrap; color: #00aa66; font-size: 12px; font-weight: bold;">HKCR\Drive\Shell</span> registry key to <span style="white-space: nowrap; color: #00aa66; font-size: 12px; font-weight: bold;">none</span> and restart the <em>explorer.exe</em> process.</p>
<p>Mentioned problem sometimes arises after some malware installation &#8211; the disinfection not always repairs that problem automatically.</p>
]]></content:encoded>
			<wfw:commentRss>http://p-lider.lideve.eu/wordpress/?feed=rss2&#038;p=87</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
