Is this caused by a malware?

javierperezch

New member
Hi,

Every time y start a session in Windows XP, TeaTimer alerts me of a registry change.

The changed key is:
HKLM\Software\Microsoft\Windows NT\Current Version\WinLogon Shell
The original value was "Explorer.exe" and it's replaced with "Explorer.exe svchost.exe"

If I deny the change, TeaTimer keeps giving the alert again and again.
If I allow the change, and then edit de registry key manually, after a few seconds TeaTimer starts giving alerts again.

I ran Spybot and didn't find anything. Neither did the antivirus.

I'm not sure if this is a problem caused by a malware or if it's something normal (may be after a windows update)

Any help would be appreciated

Thanx
 
Back
Top