QUOTE(achok @ Feb 11 2007, 05:59 PM)
hi all,
actually this malware haunted me long enuff. i still cant clean it up.
--- Search result list ---
Command Service: Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService
Command Service: Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService
Command Service: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdService
Open notepad and copy and paste next present in the quotebox below in it:actually this malware haunted me long enuff. i still cant clean it up.
--- Search result list ---
Command Service: Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService
Command Service: Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService
Command Service: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdService
(don't forget to copy and paste REGEDIT4)
QUOTE
REGEDIT4
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdService]
Save this as fix.reg Choose to "Save type as - All Files"[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdService]
It should look like this:

Double click on fix.reg & allow it to merge into the registry.
Restart your computer.
QUOTE(mentos @ Feb 11 2007, 08:49 PM)
piss off I can sayAdded on February 11, 2007, 9:25 pmIf the registry fix fails to remove it, please post a HJT log in your next reply.
This post has been edited by eXPeri3nc3: Feb 11 2007, 09:25 PM
Feb 11 2007, 09:23 PM

Quote
0.0149sec
0.67
6 queries
GZIP Disabled