Ok so I was on a service call today for an OS Service. Client had 105 processes running on a windows xp machine completely updated with sp 2 and all. Most of them were viri/spyware. I completely cleaned the machine out of all traces of spyware and tuned it up perfect. I did run into one complication with a spyware program. It would load up in windows logon service in normal and safe mode. I could not delete the file or remove the entry in registry: Local Machine / Software / Microsoft / Windows NT / Current Version / Winlogon / Notify. It would immiately recreate the value I just removed. Everytime I removed the registry entry it would recreate itself under one of these 3 file names: j8n20i5oe8.dll 148mlel11hq.dll chkrds.dll. DLL Compare also showed these programs as the culprit. Is there anyway to remove these files from loading up in the windows logon service so you can delete them without runninng a program like winternals or BartPE? Any advise would be great.
Errol barratt
Errol Barratt
Errol barratt
Errol Barratt