
Originally Posted by
Black Mage
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f
Which instead of removing the key, just made my task manager usable again. I apprecaite the response.
That's basically the same as deleting the key, except you're setting it's value to the default as if it didn't exist in the first place instead.
Norton Antivirus did not pick anything up, but then again, it didn't pick anything up before I ran the file.
I looked at the file in a hex editor, and it looks like the program was written by whoever owns the site you got it off, and just edits the registry and is effectively a nuisance and not actually a virus, so I wouldn't expect a virus scanner to pick it up. If a virus scanner picked up any program that edited the registry, you'd have a hard time running a lot of program installers
And lastly, I've found this in the registry:
pmlzjxgec = C:\WINDOWS\System32\bmulalme.exe
I'm to understand that bmulalame.exe is for Quicktime, and auto-updater of sorts, but what looks suspicious to me is the "pmlzjxgec", which I have no idea what it is.
With such a crappy name like that for both the entry and the program, it doesn't deserve to stay on the system even if it is clean