Re: Cannot delete file - Unable to remove permissions
- From: prasad.addepalli@xxxxxxxxx
- Date: Tue, 11 Dec 2007 00:15:47 -0800 (PST)
Thank you Dave,
I have not tried the safe mode administrator option..I was able to get
the security tab in the normal mode itself..
I added the following registty key..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Option]
"OptionValue"=dword:00000001
The file appears to be a part of a rootkit type infection...and seems
to have a kernel mode driver protecting it..
CACLS gives the following result for the ACL
USERS:R
Administrator:F
<username>:F
Trying to modify the permission gives a access denied error..
I would be trying the safe mode admin option and I will let you know
the result.
I file is loaded as an Explorer BHO and is injecting itself into
several processes..we are looking at some complex malware here..
Thanks,
Prasad Addepalli
On Dec 10, 1:17 pm, "Dave Patrick" <DSPatr...@xxxxxxxxxxxxxxxx> wrote:
Have you logged on as local administrator from a 'Safe Mode' boot?
--
Regards,
Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]http://www.microsoft.com/protect
"Jamie" wrote:
And what if after clicking <FILE> <PROPERTIES> there is no security tab???
Thank you- Hide quoted text -
- Show quoted text -
.
- Follow-Ups:
- Re: Cannot delete file - Unable to remove permissions
- From: Pegasus \(MVP\)
- Re: Cannot delete file - Unable to remove permissions
- References:
- Cannot delete file - Unable to remove permissions
- From: prasad . addepalli
- Re: Cannot delete file - Unable to remove permissions
- From: Dave Patrick
- Re: Cannot delete file - Unable to remove permissions
- From: Dave Patrick
- Cannot delete file - Unable to remove permissions
- Prev by Date: Re: Cannot copy <filename>: Insufficient system resources
- Next by Date: Re: Cannot delete file - Unable to remove permissions
- Previous by thread: Re: Cannot delete file - Unable to remove permissions
- Next by thread: Re: Cannot delete file - Unable to remove permissions
- Index(es):
Relevant Pages
|
Loading