It would be extremely helpful in removing malware if TeaTimer would simply show the name of the executable or dll (started with rundll) that tried to change the registry.
TeaTimer does not capture information about what process made the registry change because TeaTimer actually detects that a registry change has occurred after the fact by comparing the current content of the registry with snapshot files of the registry taken earlier.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.