Slaters Kustum Machines
Well-Known Member
- Reaction score
- 2,498
- Location
- Iowa
My test VM is XP Home. I could set up test VM's for Vista/7 as well if needed.
Last edited:
When I click Destroy Junction I get the following: A directory beneath the reparse point exists! Click YES to delete or NO to explore directory. Clicking no takes me to the Junction listed. Clicking yes gives me "Could not delete the directory." Also my Junction is C:\WINDOWS\$NtUninstallKB47189$ This is in a VM since the one I thought I was getting turned out to be a different issue.
Well done guys that all works nicely.
I'm still confused as to what the reparse point is actually doing. It appears to be a link to the config folder but there is nothing visible in there. When you delete the junction it turns into a normal directory and you can see and delete the files - or is that a normal effect of using that fsutil command - to pull the files from the other end of link into the junction folder?
I did not do the IFEO part, fail on my part. Will revert to snapshot then perform IFEO part then try the junction trick. I am using the variant from this thread.
I ran the IFEO Modifier then restarted and the infected .exe was no longer running then I ran the Junction tool and deleted the junction, but am unable to delete the directory. I did take control of the directory as well.
Foolish, I noticed you stated to select the .exe during the IFEO Modifier part, but when I clicked the drop down menu it wasn't listed? Is it supposed to be listed here? There where other .exes in there. I just typed in what I found in Task Manager and it worked.
p.s @foolish - junction function worked a treat , thanks![]()
Hey ZenTree,Had another one of these today, few changes:
there was a randomly numbered file stored in system32 that I kept being refered to, no file suffix etc, removed easily enough, perhaps this was the file it mounts as an encrypted drive, like truecrypt does for example. Time stamp matched the infection date/time exactly.
It had also infected (or something that came along at the same time) some common file names, I was so busy tracing the tricks above that I overlooked this initially and things kept coming back.
names were:
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe
This one also seemed to be infecting more system files, listed 8 of the usual suspects, though some only came after tried removing it without catching the ADS stream, (forgot).
Still, quick turn around on it. Symptoms were only a few redirects so didn't expect something this fun this morning
p.s @foolish - junction function worked a treat , thanks![]()