Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista General Discussion > Path to services changed

Reply
Thread Tools Display Modes

Path to services changed

 
 
Mark delta P
Guest
Posts: n/a

 
      12-04-2007
Hi All,

I have an interesting issue. My laptop is running Vista Home Premium and has
had AV installed and kept up to date from day one. Recently (don't know when
it changed) a few, not all, of the services have had a "-" inserted before
the path in the registry. The services affected were things like the Adobe
file manager, Apple Ipod service, Sound card manager, Intel Raid monitor and
Sony Event service. I can go into the registry and change them back by
deleting the - from the beginning of the path, but after a while it returns.
I am quite sure it's not some kind of malware (unless it's by-passed the
AV), but its really annoying! Any ideas? The only thing I can see that they
have in common is that the service's executable resides in c:\progam
files\xxx.

Thanks,

Mark
 
Reply With Quote
 
 
 
 
Malke
Guest
Posts: n/a

 
      12-05-2007
Mark delta P wrote:
> Hi All,
>
> I have an interesting issue. My laptop is running Vista Home Premium and has
> had AV installed and kept up to date from day one. Recently (don't know when
> it changed) a few, not all, of the services have had a "-" inserted before
> the path in the registry. The services affected were things like the Adobe
> file manager, Apple Ipod service, Sound card manager, Intel Raid monitor and
> Sony Event service. I can go into the registry and change them back by
> deleting the - from the beginning of the path, but after a while it returns.
> I am quite sure it's not some kind of malware (unless it's by-passed the
> AV), but its really annoying! Any ideas? The only thing I can see that they
> have in common is that the service's executable resides in c:\progam
> files\xxx.


Since services' executables do not reside in C:\Program Files, this is a
pretty sure sign your computer is infected.

Go through these general malware removal steps systematically -
http://www.elephantboycomputers.com/...moving_Malware

Include scanning with David Lipman's Multi_AV and follow instructions to
do all scans in Safe Mode. Please see the special Notes regarding using
Multi_AV in Vista.

http://www.elephantboycomputers.com/page2.html#Multi-AV - instructions
http://www.pctipp.ch/downloads/siche...ning_tool.html
- download site

The site is in German but David's tool is in English so don't let that
worry you. Scroll all the way down to almost the bottom of the page and
you'll see a box titled "Infos Zum Download - Multi-AV Scanning Tool".
You'll see "Download von www pctipp.ch" and the live link to download
Multi_AV.

When all else fails, run HijackThis and post your log in one of the
specialty forums listed at the first link above (not here, please).

Not all tools used will work in Vista and you will need to run them
elevated. Since Vista is so new, it will be a while before removal
techniques and tools are developed. If you are unable to remove the
infection by following the general steps, register at one of the
HijackThis forums as suggested.

Standard caveat: If the procedures look too complex - and there is no
shame in admitting this isn't your cup of tea - take the machine to a
professional computer repair shop (not your local version of
BigComputerStore/GeekSquad). Please be aware that not all local shops
are skilled at removing malware and even if they are, your computer may
be so infested that Windows will need to be clean-installed. Have all
your data backed up before you take the machine into a shop.


Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
UNC Path microsvc Windows Vista General Discussion 0 04-01-2008 05:39 PM
profile path changed strangely Tahir Windows Vista General Discussion 1 02-19-2008 01:12 PM
Changed User name, but User folder name didnt get changed? mbm Windows Vista Administration 2 12-01-2007 05:36 PM
Path is being truncated - help! WendyAlia@gmail.com Windows Vista General Discussion 3 10-08-2007 07:36 PM
path error Arne Windows Vista Installation 9 07-11-2007 03:24 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59