New ResponseCancelCopy to Archive Copy to ArchiveMove to Archive Move to Archive


Document Library
Main Topic

Kurt Tomicich
2005/12/12



Reference
Subject:Other Spyware location in registry
Category:Malware
Revision Date:2007/11/17 Modified: 2012/10/04
 
OriginatorReviewers
Kurt Tomicich
Apparently this Key gets cached by windows and the key will regenerate if you try to delete it. There are also issues with deleting the file it's pointing at so you should use KillBox to replace the file. Once the machine has been rebooted with the fake file in place, the key and file can be deleted.

HKLM\Software\Microsoft\Windows NT\WinLogon\Notify





All Documents   By Author   By Category   By Alternate Name   Review Status   Help