Tips and Tutorials

The same spyware programs are detected even after I delete them.
Keep your system up to date with the latest service packs, updates
Getting rid of junk files on your computer?
Settings to use for Internet Explorer to help block and prevent spyware infection?
Proper settings for ActiveX controls to help prevent Spyware infection?
Disable popup messages delivered by the Windows Messenger Service
Use Add/Remove Programs control panel to remove suspicious programs
Use the Windows Task Manager to locate suspicious programs, services, and processes
The pros and cons of using Windows System Restore to help remove spyware or correct spyware problems
How to boot a computer into safe mode to run a spyware scan
CoolWebSearch has infected my computer, but my spyware removal software doesn’t get rid of it. 
Remove spyware problems related to about:blank and se.dll?
How can I protect my registry from spyware?
Use hosts file to find and fix web page redirects?

 

How does spyware use the registry, and how can I protect my registry from spyware?


The Windows Registry is a collection of information that Windows uses to configure and run your computer.  Windows has its own information in the registry, and almost every program that you install puts its own information there, too.  The registry is a vast repository of cryptic keys and values, and it is very easy for spyware to take advantage of it to perform its irritating tasks.

More dangerous spyware can use the registry to compromise your computer in several ways.  Those that take the form of DLLs, such as about:blank and se:dll, set references to themselves in the registry.  This reference tells Windows where to find the spyware and how to load it into memory.  Other registry entries tell Windows what programs to start when you start your computer.  Spyware often sets references to itself so that it can start invading your privacy as soon as you’ve turned on your machine. 

Editing the registry directly to remove these rogue entries is no small undertaking.  Changing or deleting the wrong values can have very serious consequences, so manually editing the registry should never be taken lightly.  Spyware removal tools generally include as part of their analysis a registry scan.  These programs can find and delete traces of spyware in the registry, so you shouldn’t have to do the searching and editing yourself. 

Once you have removed all spyware from your computer, it is useful to make a registry backup.  If your system becomes infected with spyware, having a copy of the registry as it was before the infection occurred can be useful in eliminating entries made by offending programs.  The previous article about using System Restore to eliminate spyware is the easiest way to return the registry to an uninfected state.  If you wish to have a little “extra insurance” by making a separate registry backup, take the following steps: 

1.   Click the “Start” button.  The Start Menu appears. 

2.   Click “Run.”  The “Run” dialog appears. 

3.   Type “regedit” into the “Open:” combo box. 

4.   Click the “OK” button.  The “Registry Editor” window appears. 

5.   Click “File” on the menu bar. 

6.   Click “Export…”  The “Export Registry File” dialog appears. 

7.   Use the folder list at the top of the window to pick a location for your registry backup file. 

8.   Enter a file name for the registry backup in the “File name:” combo box below the folder list. 

9.   Select the “All” radio button in the “Export range” panel at the bottom of the window. 

10. Click the “Save” button.  Registry Editor makes a backup of the registry in the location that you specified in Steps 7 and 8. 

To restore the registry from a backup that you have previously made, do the following: 

1.   Repeat Steps 1 – 5 above. 

2.   Click “Import…”  The “Import Registry File” dialog opens. 

3.   Locate and click the registry backup file in the folder list at the top of the window.  The name of the backup file appears in the “File name:” combo box. 

4.   Click the “Open” button.  The Registry Editor imports the registry from the backup file that you selected in Step 3. 

Remember that manually dealing with the registry is a serious operation.  If at all possible, you should use tools that edit the registry for you.

 

Back To FAQ and Tutorials

 
*Please email us at staff@SpywareInformer.com if you would like to share your experience with any spyware removers or methods mentioned on this site or any other spyware tools you have come across that you think are worth mentioning to help keep people informed so they can make the best decisions possible.