M
Martin Spencer-Ford
Hi group, got asked to help a friends heavily infected machine, which
had too numerous Trojans and ad ware to remember them all, but went to
kaspersky to do an on-line scan, worked through the log killing files
that had been highlighted as infected. All was successful other than one
one file which went by the name guard.tmp. This file wouldn't delete and
was not found in any of the usual places, hijackthis failed to see it
and there was no entry in the process list or in the registry, so i did
the bold move and took ownership of the file removing all inheritance,
and try to delete it that way .... no luck there either.
So feeling confident that it was the only one left to hammer, i thought
that maybe the blighter is called through one of the many dll's i had
already nobbled, and decided a reboot would probably free up the file
for deletion. But now on reboot, I can not get access, winlogon.exe is
terminated in an "unusual way" and the error message displays
"\??\c:\windows\system32\winlogon.exe"
Any body have any advice that may recover this station or is it kill it
and start again. All accounts fail whether in safe mode or normal.
Any help appreciated
Martin Spencer-Ford
(TpwUK)
had too numerous Trojans and ad ware to remember them all, but went to
kaspersky to do an on-line scan, worked through the log killing files
that had been highlighted as infected. All was successful other than one
one file which went by the name guard.tmp. This file wouldn't delete and
was not found in any of the usual places, hijackthis failed to see it
and there was no entry in the process list or in the registry, so i did
the bold move and took ownership of the file removing all inheritance,
and try to delete it that way .... no luck there either.
So feeling confident that it was the only one left to hammer, i thought
that maybe the blighter is called through one of the many dll's i had
already nobbled, and decided a reboot would probably free up the file
for deletion. But now on reboot, I can not get access, winlogon.exe is
terminated in an "unusual way" and the error message displays
"\??\c:\windows\system32\winlogon.exe"
Any body have any advice that may recover this station or is it kill it
and start again. All accounts fail whether in safe mode or normal.
Any help appreciated
Martin Spencer-Ford
(TpwUK)