joshkmartinez Posted May 27, 2017 Author ID:1130678 Share Posted May 27, 2017 I think i know why I have been getting the error im the cmd all the time. Its becasue the floder is in use. This is also why i cannot rename catroot2 to catroot2.old. Link to post Share on other sites More sharing options...
joshkmartinez Posted May 27, 2017 Author ID:1130793 Share Posted May 27, 2017 May I turn on my rainmeter skins? I really miss them. Link to post Share on other sites More sharing options...
Aura Posted May 27, 2017 ID:1130818 Share Posted May 27, 2017 You can turn it on, yes. And you stopped the Cryptographic Service before trying to rename the folder, right? Link to post Share on other sites More sharing options...
joshkmartinez Posted May 27, 2017 Author ID:1130830 Share Posted May 27, 2017 Yep Link to post Share on other sites More sharing options...
Aura Posted May 29, 2017 ID:1131233 Share Posted May 29, 2017 Okay, try to restart your computer before following the renaming procedure. If it doesn't work, let me know and we'll try to disable the service beforehand. Link to post Share on other sites More sharing options...
joshkmartinez Posted May 29, 2017 Author ID:1131259 Share Posted May 29, 2017 I still get the exact same error that the folder is in use by another program. Link to post Share on other sites More sharing options...
joshkmartinez Posted May 31, 2017 Author ID:1131672 Share Posted May 31, 2017 What shall I do now? Link to post Share on other sites More sharing options...
Aura Posted May 31, 2017 ID:1131704 Share Posted May 31, 2017 Alright, press on the Windows + R keys, enter services.msc and press on Enter. In the Services window, look for Cryptographic Services, right-click on it, select Properties and change the Startup Type to Disabled. Once done, restart your computer and try to rename the folder. Link to post Share on other sites More sharing options...
joshkmartinez Posted June 1, 2017 Author ID:1131844 Share Posted June 1, 2017 This is very annoying and unusual. I still get the same error even when the cryptographic service is turned off at start up Link to post Share on other sites More sharing options...
joshkmartinez Posted June 1, 2017 Author ID:1131848 Share Posted June 1, 2017 Should I also activate the service at start up again? Link to post Share on other sites More sharing options...
Aura Posted June 1, 2017 ID:1132107 Share Posted June 1, 2017 Yes, un-do the chance and change the Startup type to "Automatic". I'll see if I can create a fix that will force rename the folder on boot. I've done it once before, I just need to find it in my stuff. Link to post Share on other sites More sharing options...
joshkmartinez Posted June 9, 2017 Author ID:1134233 Share Posted June 9, 2017 (edited) Still with me on this??? I'd like to also fix my windows store problem... Edited June 9, 2017 by joshkmartinez Link to post Share on other sites More sharing options...
Aura Posted June 9, 2017 ID:1134446 Share Posted June 9, 2017 Sorry for the delay, I just found an old post of mine for that issue. In the command prompt (with Admin Rights, of course), before using the ren command to rename the catroot2 folder, enter these commands (1 by 1): net stop wuauserv net stop cryptSvc net stop bits So the full set of commands would be: net stop wuauserv net stop cryptsvc net stop bits ren C:\System32\catroot2 catroot2.old net start bits net start cryptsvc net start wuauserv Link to post Share on other sites More sharing options...
joshkmartinez Posted June 10, 2017 Author ID:1134717 Share Posted June 10, 2017 Ok, what now? Link to post Share on other sites More sharing options...
Aura Posted June 11, 2017 ID:1134761 Share Posted June 11, 2017 Did you rename the catroot2 folder to catroot2.old successfully? Link to post Share on other sites More sharing options...
joshkmartinez Posted June 11, 2017 Author ID:1134798 Share Posted June 11, 2017 Yes Link to post Share on other sites More sharing options...
Aura Posted June 11, 2017 ID:1134799 Share Posted June 11, 2017 Good. Now follow the instructions under the "Verify" paragraph, and give me a screenshot of the command prompt once the esentutl command is done running. https://technet.microsoft.com/en-us/library/cc734083(v=ws.10).aspx?f=255&MSPPError=-2147217396 net stop cryptsvc esentutl /g C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb net start cryptsvc Link to post Share on other sites More sharing options...
joshkmartinez Posted June 12, 2017 Author ID:1134958 Share Posted June 12, 2017 Link to post Share on other sites More sharing options...
Aura Posted June 12, 2017 ID:1134962 Share Posted June 12, 2017 Good Now please run a new scan with FRST and provide me the FRST.txt log afterward. Link to post Share on other sites More sharing options...
joshkmartinez Posted June 12, 2017 Author ID:1135110 Share Posted June 12, 2017 FRST.txt Link to post Share on other sites More sharing options...
joshkmartinez Posted June 15, 2017 Author ID:1135782 Share Posted June 15, 2017 What do you think now? Link to post Share on other sites More sharing options...
Aura Posted June 16, 2017 ID:1136176 Share Posted June 16, 2017 Well, the "issue" is still present, though from my understanding, it probably was before you were infected, as the malware you were infected with doesn't cause it. For now, if it doesn't cause you any issues, it's fine. How's your system behaving now? Are there any other malware-related issues left to address that you can see? Link to post Share on other sites More sharing options...
joshkmartinez Posted June 16, 2017 Author ID:1136266 Share Posted June 16, 2017 No my all of my malware related problems are fixed. Thank you so much for your time and commitment. However, I would like to fix my windows store problem. Link to post Share on other sites More sharing options...
Aura Posted June 16, 2017 ID:1136268 Share Posted June 16, 2017 What's your Windows Store issue? Link to post Share on other sites More sharing options...
joshkmartinez Posted June 16, 2017 Author ID:1136343 Share Posted June 16, 2017 Every solution I have tried online doesn't work Link to post Share on other sites More sharing options...
Recommended Posts