Windows Defender Offline detected services.exe
as being infected by Trojan:Win64/Sirefef.Y
. The recommended action was to remove it, which is what i chose to do. But it failed, returning the error code 0x800704ec
(blocked by a group policy).
Is there a way for me to manually overwrite the services.exe file with a healthy copy using my Windows disk?
I am not sure if you can do this just with the windows disc, but you can boot something else than just the infected windows install or the windows DVD and overwrite the file.
E.g. a liveCD with Linux, Hiren's bootCD, sysinternals ERD commander, ....
Or even an other computer (just make sure that that one is up to date so it does not get infected).
User contributions licensed under CC BY-SA 3.0