1
I have a computer with a virus. I've finally located one of the registries that is creating problems. If I change or delete the registry and then delete a particular process, it will recreate the registry key and subsequently the process.
Is there a way I can use this information to my advantage to determine what is recreating the registry? (And then banish it forever)
Thanks.
Process Monitor can do that with proper filtering. Anyway, check How do I get rid of malicious spyware, malware, viruses or rootkits from my PC? if you haven't already. – and31415 – 2014-03-20T11:13:41.707
Your main problem is that you are trying to disinfect an infected running system. If you really want to remove a virus from a system boot a clean system (e.g. from boot cd) and use it for virus scanning and removal. Otherwise you will not succeed as a typical virus consists of multiple of executables checking each other and restarting/restoring them. – Robert – 2014-03-20T12:51:19.383