thisisu wrote:Then you did something wrong. The same scenario works here.EP_X0FF wrote:Thanks I did try these steps, all successfully except the very last one (delete .DLL)thisisu wrote:How do I stop the hooking :lol:http://www.kernelmode.info/forum/viewto ... 741#p16741
Regarding cacls I got: "Successfully processed %path of dll%", rebooted. Nulled APPINIT_DLLs - OK, reset perms using cacls again - OK. But then the .DLL still failed to delete. And this is all after both eType Manager and IBUpdaterService services were stopped and deleted. Processes killed.
Ring0 - the source of inspiration