Jump to content


  • Content Count

  • Joined

  • Last visited

About tjseven

  • Rank
  • Birthday 01/01/1970

Profile Information

  • Interests
  1. Yes, google is my friend. As I found during my past googles that SAS was the only app detecting this. I guess my question would be: Why does SAS say it will remove these and they still return??? Are these legacy or are they being regenerated by something I can't find??? Thank you for you help. TJ
  2. SAS is the only application that detects this and while it says it will remove it...it's always there on the next scan?? Trojan.Windows Overlay Components/SysMon HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_OVERLAY_COMPONENTS HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_OVERLAY_COMPONENTS#N extInstance HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_OVERLAY_COMPONENTS\0 000 HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_OVERLAY_COMPONENTS\0 000#Service HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_OVERLAY_COMPONENTS\0 000#Legacy HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_OVERLAY_COMPONENTS\0 000#ConfigFlags HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_OVERLAY_COMPONENTS\0 000#Class HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_OVERLAY_COMPONENTS\0 000#ClassGUID HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_OVERLAY_COMPONENTS\0 000#DeviceDesc Thanks TJ
  • Create New...