Link to home
Start Free TrialLog in
Avatar of kvnsdr
kvnsdr

asked on

Core.sys Removal From XP Pro?

Q. How do I remove C:\WINNT\system32\drivers\core.sys?
Avatar of SheharyaarSaahil
SheharyaarSaahil
Flag of United Arab Emirates image

get SuperAntiSpyware
http://www.superantispyware.com/

install and update it
update your antivirus program too
boot under safemode and scan your system with both of them
let them to clean your system and restart back in normal mode to check out the results.
Avatar of r-k
r-k

You can also just boot from the XP CD in recovery console mode and delete the file. Or boot from the UBCD for Windows and do the same etc.

But it might be better to identify and describe the problem befoe deleting files. What are the symptoms and why do you want to delete just this one file?
Avatar of kvnsdr

ASKER

So far my research indicates it's not a Windows file.
Here are a couple of things to try:

(1) Right-click on that file, select Properties and examine date/time. Then click on the Version tab and see who created it.

(2) Submit that file to http://www.virustotal.com/ and/or http://virusscan.jotti.org/
 for analysis.

Did you try Superantispyware as suggested by S.Saahil?

It's possibly part of a rootkit. Download RootkitRevealer from http://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx and scan your hard drive. Save the resulting log to a text file because you may need it later. Copy-and-paste it here if anything interesting. If the log is very long then just post the first 30 lines or so.
Avatar of kvnsdr

ASKER

So far no good, looks like I'll need to reboot and manually delete it.
ASKER CERTIFIED SOLUTION
Avatar of SheharyaarSaahil
SheharyaarSaahil
Flag of United Arab Emirates image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of kvnsdr

ASKER

It's an Windows 2000 Workstation.
okk....so we can still try the safemode removal with it....can't we? :)
Avatar of kvnsdr

ASKER

I'm going to the client sometime soon and let you know...