One of the servers I work is infected with Backdoor.Trojan which put a copy of svchost.exe in the c:\winnt directory. That file should only be in c:\winnt\system32 and I want to delete it. I tried to delete the file and it says access denied, even when I stop all the services. I'm doing this remotely, and I know I can set the boot.ini to restart the machine in safe mode with networking. My question is though, will I be able to connect remotely, or is this a service that will only run in regular mode? I really don't want to reboot the machine into safe mode and then have it stuck there until Tuesday, because it needs to do its job as a server.
Page 1 of 1
Remote Desktop in Safe Mode Can I connect...
#2
Posted 08 March 2004 - 05:12 PM
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "ParseAutoexec"="0"
then in autoexec.bat
type del pathname\filename.extension
and symanctec's website could probably help u get rid of the virus...
and buy a anti-virus program for the server
#3
Posted 09 March 2004 - 12:50 AM
Thanks, one of the problems was that I just picked up that site last week so I'm taking over somebody else's work
Share this topic:
Page 1 of 1



Help
Back to top









