On Jun 3, 12:29 am, Garrot <n...@email.invalid> wrote:
> Hmm, anyone know what this is about? Hopefully the author of SAS can
> come along and explain it. The below is listed under Autostart in the
> Gmer rootkit revealer. Castlecops says it is legit bit I want to know
> what it does.
>
> HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
> !SASWinLogon@DLLName = C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
That's our winlogon handler, it's used to remove hard to detect/remove
spyware/malware. Nothing in SUPERAntiSpyware is harmful.
Nick Skrepetos
SUPERAntiSpyware.com
http://www.superantispyware.com


Reply With Quote