|
Paul,
Run
FileMon and RegMon (both from SysInternals) while you do those delete
actions you mention, then examine the log file and you may find
something. FileMon makes use of "NTFS Change Journal" which I think
may be behind those process and file/directory re-creations. "NTFS Change
Journal" tracks every action in a NTFS file system. Just google for it for more
info.
Hope
it helps,
Tiago Halm
|
Title: Message
- [Full-Disclosure] Looking for a tool Schmehl, Paul L
- RE: [Full-Disclosure] Looking for... Tremaine Lea
- RE: [Full-Disclosure] Looking for... Nick Jacobsen
- RE: [Full-Disclosure] Looking for... Schmehl, Paul L
- Re: [Full-Disclosure] Looking... Tim
- RE: [Full-Disclosure] Loo... Aditya, ALD [Aditya Lalit Deshmukh]
- RE: [Full-Disclosure]... Harlan Carvey
- RE: [Full-Disclo... Aditya, ALD [Aditya Lalit Deshmukh]
- RE: [Full-Di... Harlan Carvey
- Re: [Full-Disclosure] Looking... Tiago Halm
- Re: [Full-Disclosure] Looking... Lan Guy
- Re: [Full-Disclosure] Loo... Gregh
- Re: [Full-Disclosure]... Dave Howe
- Re: [Full-Disclo... Gregh
- Re: [Full-Di... Dave Howe
- Re: [Ful... Gregh
- RE: [Full-Disclosure] Looking... Tony
- RE: [Full-Disclosure] Loo... Jeremiah Cornelius
- RE: [Full-Disclosure] Looking... Nicob
- RE: [Full-Disclosure] Looking for... axid3j1al axid3j1al
