| 1. |
Solve : Security Software? |
|
Answer» I am confused about the FOLLOWING utility programs, and am wondering if they overlap each other and could cause a problem. They all seam to be similar and trying to attack the same threads. I mean the following programs; Some times you mite get rid of something important so thats not really good ether. And why WOULD I delete something important? it obviously wouldn't work for everyone- but it works for me. This is especially true with those stubborn WinLogon notifier hook dlls- they install a whole bunch of startup item trojans. Deleting the run key's won't help, since the notifier is checking for that and re-creating them as they get deleted. the Winlogon.exe process can't be terminated on account of being a critical system process, and that is what the trojan DLL has loaded under. The trick? Winlogon has a registry key that determines what it LOADS- by default, just the microsoft included GINA, and some anti-virus software installs it's own here as well. looking at the key, one can determine the dll being loaded (usually given away easily by a random Dll name with no description), and delete it. problem? the key will return, because just like with the run key, the notifier is watching that part, too. So the only recourse is to delete the DLL in recovery console. it's also necessary to destroy all the trojan EXE's discovered to be placed in the RUN key by the notifier- otherwise, they might simply reinstall the notifier. Once all is said and done, the registry items in question can be deleted, and the system is clean again.Ones that are sucking the life out of a machine any way. |
|