RE: Win2k file system check on boot

From: Andrew Sheldon (forensicsat_private)
Date: Tue Jul 31 2001 - 12:41:51 PDT


Cameron,

There are a few files that you may want to rename so that such activity can be launched when YOU want it and not when the OS wants it:

The built in Disk Defragger at 
     %SystemRoot%\System32\dfrg.msc

The disk cleanup utility at
    %SystemRoot%\System32\cleanmgr.exe

but mostly, CHKDSK.EXE in the %SystemRoot%\System32\
possibly also found in %SystemRoot%\System32\DLLCACHE 

I believe that it's the CHKDSK.EXE which is launched automagically when you install a new disk. It can play havoc with imaged evidential drives too :-)

I allways rename this (and Scandisk.exe) in all my systems so they cannot launch automatically.

Cheers
shelly
4warn0


-----------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com



This archive was generated by hypermail 2b30 : Tue Jul 31 2001 - 15:17:00 PDT