![]() |
RKR log help |
Post Reply
|
| Author | |
molotov
Moderator Group
Joined: 04 October 2006 Online Status: Offline Posts: 17492 |
Post Options
Quote Reply
Topic: RKR log helpPosted: 04 November 2009 at 11:36am |
|
In that event, as you indicated, the best/easiest option may be to use something like a BartPE disc or a bootable Linux disc, to try to remove the folder.
|
|
|
Daily affirmation:
net helpmsg 4006 |
|
![]() |
|
Luizf
Newbie
Joined: 29 September 2009 Online Status: Offline Posts: 4 |
Post Options
Quote Reply
Posted: 28 October 2009 at 9:34pm |
|
Hello Molotov,
Yes, I am still dealing with this problem. I tried to do as you said, using autocomplete, but I got a message stating the system could not find the specified file. Thanks for you help. Regards, Luiz |
|
![]() |
|
molotov
Moderator Group
Joined: 04 October 2006 Online Status: Offline Posts: 17492 |
Post Options
Quote Reply
Posted: 28 October 2009 at 10:04am |
|
If you're still dealing with this... Can you use autocomplete in the CMD prompt to rename or remove the folder? Have you tried renaming the folder from the CMD prompt?
|
|
|
Daily affirmation:
net helpmsg 4006 |
|
![]() |
|
Luizf
Newbie
Joined: 29 September 2009 Online Status: Offline Posts: 4 |
Post Options
Quote Reply
Posted: 04 October 2009 at 3:01pm |
|
Hello Sven,
Thank you again for your help. I did what you said, but despite chkdsk pointed and fixed some inconsistencies, the problem still remains: I can not delete the folders. Now I am loking for a bootable CD, and try to delete from the comand prompt. Regards, Luiz Edited by Luizf - 04 October 2009 at 3:02pm |
|
![]() |
|
SvenBomwollen
Senior Member
Joined: 29 August 2008 Location: Germany Online Status: Offline Posts: 1400 |
Post Options
Quote Reply
Posted: 04 October 2009 at 12:33am |
|
Hello, Luiz.
Perhaps your file system is damaged? You might schedule a chkdsk run on drive C: for the next reboot. Launch Start => Run: cmd.exe. Type
Windows will wrte the results to the Applications eventlog, too, source=Winlogon on Pre-Vista systems, source=Wininit on Vista. Kind regards, SvenBomwollen |
|
![]() |
|
Luizf
Newbie
Joined: 29 September 2009 Online Status: Offline Posts: 4 |
Post Options
Quote Reply
Posted: 03 October 2009 at 10:28pm |
|
Hi Sven,
I have already tried to remove the folder, but Windows returns an error stating "can not delete the file. cannot read the file or source disk." I have also tried to delete the parents folder, but i got the same error. Also, doing it in safe mode didnt work either. Thanks for the reply. Regards, Luiz Edited by Luizf - 04 October 2009 at 12:20am |
|
![]() |
|
SvenBomwollen
Senior Member
Joined: 29 August 2008 Location: Germany Online Status: Offline Posts: 1400 |
Post Options
Quote Reply
Posted: 03 October 2009 at 12:54am |
|
Hello, Luizf.
Simply try to remove the folder Kind reagrds, |
|
![]() |
|
Luizf
Newbie
Joined: 29 September 2009 Online Status: Offline Posts: 4 |
Post Options
Quote Reply
Posted: 29 September 2009 at 5:43pm |
|
Running RKR I got the following log
HKLM\SECURITY\Policy\Secrets\SAC* 9/9/2004 00:28 0 bytes Key name contains embedded nulls (*) HKLM\SECURITY\Policy\Secrets\SAI* 9/9/2004 00:28 0 bytes Key name contains embedded nulls (*) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQLServer\Parameters 5/6/2009 15:51 0 bytes Security mismatch. HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL10.SQLEXPRESS\Security 5/6/2009 15:51 0 bytes Security mismatch. C:\Documents and Settings\luiz\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\82ZA6P3B\four-thirds.org.\localData.sol 14/5/2009 21:25 48 bytes Hidden from Windows API. C:\Documents and Settings\luiz\Dados de aplicativos\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#four-thirds.org.\settings.sol 14/5/2009 21:25 86 bytes Hidden from Windows API. I guess the first four entries are not a problem. Am I right? But the last two entries, the ones showed "Hidden from Windwos API" is puzzling me. I tried to remove the file, but when I tried to access the folder Windows stated that it points to a not available place on my disk. Could this be a disk directory problem ou could it be a real rootkit. Thanks for any help and suggestion. Edited by Luizf - 04 October 2009 at 12:21am |
|
![]() |
|
Post Reply
|
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |