Guest JonnyTwoShoes Posted July 17, 2008 Posted July 17, 2008 Hi there, I recently removed a Worm/Trojan but now everytime windows starts up it say's,"Windows cannot find 'C:\WINDOWS\services.exe'.". I believe this file was associated with the threat which was removed and is now no longer there but the registry key still remains. Before I delete the wrong registry key I would like to know if the following registry key is legit, 'HKLM/Software/Microsoft/Windows/CurrentVersion/Run/C:\WINDOWS\services.exe' - Microsoft Windows Update Client. Is this really the Windows update client reg key which I do not want to delete or the suspected key which is trying to locate and run the threat ..exe? My knowledge of regedit is somewhat limited and I would rather be 100% sure before messing around with the Microsoft XP registry. Thanks and regards, Jonno.
Guest Pegasus \(MVP\) Posted July 17, 2008 Posted July 17, 2008 Re: C:\WINDOWS\services.exe "JonnyTwoShoes" <JonnyTwoShoes@discussions.microsoft.com> wrote in message news:CA16D740-D723-4BE2-8233-A3C6759E3661@microsoft.com... > Hi there, > > I recently removed a Worm/Trojan but now everytime windows starts up it > say's,"Windows cannot find 'C:\WINDOWS\services.exe'.". > > I believe this file was associated with the threat which was removed and > is > now no longer there but the registry key still remains. > > Before I delete the wrong registry key I would like to know if the > following > registry key is legit, > 'HKLM/Software/Microsoft/Windows/CurrentVersion/Run/C:\WINDOWS\services.exe' > - Microsoft Windows Update Client. > > Is this really the Windows update client reg key which I do not want to > delete or the suspected key which is trying to locate and run the threat > .exe? My knowledge of regedit is somewhat limited and I would rather be > 100% > sure before messing around with the Microsoft XP registry. > > Thanks and regards, > Jonno. The "Microsoft Windows Update Client" part is an attempt by the virus writer to deceive you. You can safely delete this value under the Run key.
Recommended Posts