trant
02-17-2009, 04:24 PM
I am booting Knoppix to try and solve a situation I have with a Windows machine.
This machine was infected with various Trojans and the scanner programs I use can find an infected file under \Windows\System32 as well as several bad registry entries but it is unable to remove any of them.
So I tried doing it in Knoppix. First, I browsed the hard drive for the file under \Windows\System32. It's not there. Knoppix does not see it. But I know it's there because I tried deleting it in Windows but it wouldn't let me with "access denied" error.
Then I tried Knoppix's regedit program to clear the bad keys. I follow the path to the bad key and suddenly realize there are so many entries missing from the tree. I can't find any of the bad keys plus alot of normal keys are not there.
Is there an option to show these hidden files and hidden registry keys which I need to use?
This machine was infected with various Trojans and the scanner programs I use can find an infected file under \Windows\System32 as well as several bad registry entries but it is unable to remove any of them.
So I tried doing it in Knoppix. First, I browsed the hard drive for the file under \Windows\System32. It's not there. Knoppix does not see it. But I know it's there because I tried deleting it in Windows but it wouldn't let me with "access denied" error.
Then I tried Knoppix's regedit program to clear the bad keys. I follow the path to the bad key and suddenly realize there are so many entries missing from the tree. I can't find any of the bad keys plus alot of normal keys are not there.
Is there an option to show these hidden files and hidden registry keys which I need to use?