1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

What file does "FileProtection" want to change?

Discussion in 'Windows XP' started by AndyB, 2008/05/06.

  1. 2008/05/06
    AndyB

    AndyB Inactive Thread Starter

    Joined:
    2008/04/04
    Messages:
    17
    Likes Received:
    0
    Hi,

    In my stupid curiosity I clicked on a dubious link in an e-mail and promptly landed on a **** page. I still noticed a quick opening of a window and closed Firefox to see the pop-up. When there was no window, I quickly hit Reset, suspecting something happening in the background.

    The boot came up with pci.sys corrupted or missing. I inserted the XP CD and started a prompt to check the file. While running up in safe mode, XP informed me that a file had been replaced and, once in DOS, I found the file in the drivers directory. Whether it is the correct size I don't know, but the date matches that of the other .sys files.

    Just to be sure, I read up on this and started WFP (Windows File Protection). After a few minutes it told me to insert the XP CD to copy some files to the DLL Cache.

    Since I can't find any pci.sys in DLLCache I am a bit worried that XP might want to overwrite a totally legitimate file, which does not match its list. And maybe this file was modified by SP2 and XP wants to revert to the original.

    My question: how can I identify, which file the File Protection utility is trying to modify or thinks it is in error?

    Any ideas how to catch this?

    Thanks.
     
  2. 2008/05/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Check Event Viewer.
     

  3. to hide this advert.

  4. 2008/05/06
    AndyB

    AndyB Inactive Thread Starter

    Joined:
    2008/04/04
    Messages:
    17
    Likes Received:
    0
    Nothing that I can see in Event Viewer.

    In System I get some Service Control Manager Errors, but I don't have the experience to read them. Event 7000 or 7036 don't mean much to me. There are also quite some "Service Control Manager" errors with Event numbers 7035 and 7036. In Security and Application there are no unusual entries as far as I can see.

    And no hint on what file the FileProtection utility wants to modify. Only that Windows File Protection started and opened a popup.

    Pity.

    Am I missing something????

    Thanks
     
  5. 2008/05/06
    surferdude2

    surferdude2 Inactive

    Joined:
    2004/07/04
    Messages:
    4,009
    Likes Received:
    23
    I've never had SFC to replace a new file with an older one. I don't think it can do that since it is programmed to search and verify all versions for the correct signature.

    If it does replace anything, you'll see a report in the Eventvwr.msc under System. It won't tell you in advance what it intends to replace.

    I've also never had SFC do me any good but that's another story. ;)
     
  6. 2008/05/07
    AndyB

    AndyB Inactive Thread Starter

    Joined:
    2008/04/04
    Messages:
    17
    Likes Received:
    0
    Thanks for the support.

    As I've said before: I do not trust Microsoft.

    And definitely not with programming. So I'll let this one blow by. To have a change made and then find later that it replaced something valid and valuable - no thank you. :eek:

    And now that I am on a rant: a good OS would tell you what and why it wants to replace. Along with version info and reasons for the suggested change. But then, that would be a good OS. :mad:
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.