Reboot your PC into SAFE MODE again, ensure your PC is set up to show hidden files.
Using windows explorer locate the following
WINDOWS\system32\winlogon.exe THERE SHOULD BE TWO OF THEM
Take care, one is a valid file! The one you should delete is the other! If you look at the details, the date of the file to delete is 05/25/05, the file size 430,080 bytes!
Ha i've noticed the other one has changed name, we've got it running scared, we'll get it this time
Click Start > Run > and type in:
In the services window find Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I).
Rightclick and choose "Properties". On the "General" tab under "Service Status" click the "Stop" button to stop the service. Beside "Startup Type" in the dropdown menu select "Disabled". Click Apply then OK. Exit the Services utility.
Then rescan with HJT and check the following
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\ntvw32.exe" /s (file missing)
click fix checked
Reboot into normal mode, rescan with HJT and post the log back
Edited by usetobe, 27 May 2005 - 03:18 PM.