Determining the time a registry key was last updated

Have a dream? Start learning your way toward it with courses from $12.99. Shop now for extra savings1px

When I ran a scan of a Windows System with Spybot Search & Destroy 1.62, it reported it found a Windows registry key associated with GhostMail - it identified GhostMail as adware.

Spybot detected GhostMail

To check the registry key, I typed regedit in the "Type here to search" field at the bottom of the screen and then selected the "Registry Editor" app when it appeared in the list of returned results (you can also open the application by typing regedit and hitting enter at a command prompt. I then navigated to the relevant key. I wanted to determine when the registry was created or at least when it was last modified. You can't see that information in the Windows Registry Editor, but you can create a text file that will contain that information by right-clicking on a key and choosing "Export" to generate a text file - select "Text Files (*.txt)" in the "Save as type" field, not the default value of "Registration Files (*.reg)."

Registry editor - export registy key

The text file will contain the key as well as the time it was last written to:

Key Name:HKEY_USERS\S-1-5-21-3084690208-3888753220-1328190817-1115\Software\Albert Yale
Class Name:<NO CLASS>
Last Write Time:8/16/2019 - 10:54 PM

In this case, the date on the key was months ago, so didn't explain recent problems on the user's PC and since Spybot - Search & Destroy didn't locate anything else, the registry key may have been a remnant of something removed many months ago.