View Single Post
Old 02-25-2007, 07:29 PM   #64 (permalink)
Ried
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,998
OS: WinXP and Vista


They are 'real' malware entries, and the last of what we need to do here.

From Normal Mode:

Navigate to, and delete the following which appears to be a folder:

c:\windows\system32\services <--Careful here. Do not delete the legit services.exe or the services.msc

**If you're not sure which to delete, right click any services entries you see in that path, select 'Properties', bring that info back here for me and I'll guide you.

------------------------------------------------------------

Go to Start->Run and type in regedit and hit OK. Go to File->Export and save the registry somewhere as a backup. Close the Registry Editor now.

Open notepad and copy/paste the text in the quotebox below:
(don't forget to copy and paste REGEDIT4)

Quote:
REGEDIT4

[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}]

Save the file as "delete.reg". Make sure to save it with the quotes. Choose to "Save type as - All Files"
It should look like this:

Double click on the delete.reg file and choose Yes to merge/add it to the registry. You may delete the file afterwards.

------------------------------------------------------------

Reboot your system.

------------------------------------------------------------

Run a full online scan at Panda and post those results here.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline