Hi
I had a PC to repair last night, and it was infected, with what I don't know, All the scanning didn't find anything.
I noticed this in the Services list.
I finally managed to disable it, including on "log on", I have placed a .txt file of the entry that's in the registry called it "strange.txt" here http://homepages.slingshot.co.nz/~crutches/Reg%20ent/
The Bad thing also, creates a new user in the list, Like Administrator, Power users etc. etc. It's seen when changing permissions for say a registry key.
with the user named like "ppgh2675grtsy67bn43....................." Yes just a alphanumerical name
Also interfers with systray icons., appear then not appear, so the Malware must interfer via the "shell32.dll" file or similar
Does anyone know what the entries belong to?? (A name for the infection).
In the end I reinstalled windows for them from the full XP CD, using the upgrade option. All that is left is the registry keys for the service, everything works fine now.
Has just puzzled me.
Quads