Is there a way to use ZwDeleteFile in a boot driver?
A forum for reverse engineering, OS internals and malware analysis
StriderH2 wrote:What to delete: trojan dlls hooked to winlogon.exe. (The ones that prohibit registry changes for the Pending File Rename Operations value).You can try native application. It will be loaded after most of system initialization but before Win32 init.
EP_X0FF wrote:Good idea,I should have seen that earlier hahah.StriderH2 wrote:What to delete: trojan dlls hooked to winlogon.exe. (The ones that prohibit registry changes for the Pending File Rename Operations value).You can try native application. It will be loaded after most of system initialization but before Win32 init.
I.e. have a look on PageDefrag or Autochk.