To help cleaning off NTOS NTOS.exe stealth’s itself, sysinternals autorun  http://technet.microsoft.com/en-gb/sysinternals/bb963902 will show an entry in the “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit” section where NTOS.exe is tagged on the end of the usual “C:\WINDOWS\system32\userinit.exe,” but if you set autoruns to remove the entry it will immediately reappear. When you look at the location using windows explorer it will […]