Hi, I downloaded a keygen off of some website, and so I had to turn off the antivirus part of CIS, and when I opened it, DEFENSE+ asked me if this file was ok to modify whatever (I didn’t read, thinking it was the usual with keygens) and now that I look at it, it did these three modifications:
Flag: Modify key, suspicious
Application: crd.exe
Target: HKLM\SYSTEM\ControlSet001\services\eventlog\Application\NVIDIA OpenGL Driver\TypesSupported
In this registry file: 7
Flag: Modify key, suspicious
Application: crd.exe
Target: HKLM\SYSTEM\ControlSet001\services\eventlog\Application\NVIDIA OpenGL Driver\EventMessageFile
In this registry file: %SystemRoot%\System32\nvoglv64.dll
It says the same as 2.
I scanned my registry with comodo and Malwarebyte’s antimalware, it comes up clean.
It also seems that the same moment as the third modification, Logitech Setpoint decided to “access memory” to comodo’s cfp file.
Were these changes harmless, or should I be worried? I’ve had some bad experiences with worms in the past
Thanks in advance