Goto Registry Editor by typing
regedit in
Run command.
Browse to these registry keys:
Code:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
In the right pane, look for the values of [b]Userinit[/b and
Shell keys. It must have values
C:\WINDOWS\system32\userinit.exe and
Explorer.exe respectively. Anything more than that can be safely deleted.
Like suppose possibly if the value is '
C:\WINDOWS\system32\userinit.exe, C:\Windows\System32\VirusRemoval.vbs' then double-click the key to edit and delete
C:\Windows\System32\VirusRemoval.vbs
Also for Startup entries, you can check these keys:
Code:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run