Author Topic: "C:\Windows\system32\CatRoot2" <-- What is that?  (Read 65521 times)

Offline Bracca

  • Comodo Loves me
  • ****
  • Posts: 103
"C:\Windows\system32\CatRoot2" <-- What is that?
« on: October 15, 2008, 08:24:15 AM »
Yeah firewall reposrts that update.exe, signed by microsoft, is trying to update that kind of an directory. The only question i have right now is, what is that thing? CatRoot2? Sounds like a malware to me O.o Although i could be wrong.

Offline LeoniAquila

  • Retired moderator
  • Comodo's Hero
  • *****
  • Posts: 6745
Re: "C:\Windows\system32\CatRoot2" <-- What is that?
« Reply #1 on: October 15, 2008, 09:47:42 AM »
This is a Microsoft folder (I've deleted it myself, but it might not be possible with all default Windows services running), so don't worry about that. Furthermore, if update.exe is signed by Microsoft, there's nothing to worry about, really.

LA

Offline Bracca

  • Comodo Loves me
  • ****
  • Posts: 103
Re: "C:\Windows\system32\CatRoot2" <-- What is that?
« Reply #2 on: October 15, 2008, 11:35:30 AM »
Oh. Thank you  (:HUG) Aand another question. How can i clean my temp folder? eXterminate it! found one trojan from there, and there seems to be a few more malicous looking temporary files.

Offline LeoniAquila

  • Retired moderator
  • Comodo's Hero
  • *****
  • Posts: 6745
Re: "C:\Windows\system32\CatRoot2" <-- What is that?
« Reply #3 on: October 15, 2008, 12:05:05 PM »
No problem :)

Do you mean the Windows\Temp folder? Can you manually delete the stuff in there? If not, I guess you need malware removal assistance. Malware not running can easily be deleted, but if it's running, you have to get rid of it somehow.

LA

Offline Bracca

  • Comodo Loves me
  • ****
  • Posts: 103
Re: "C:\Windows\system32\CatRoot2" <-- What is that?
« Reply #4 on: October 16, 2008, 07:45:16 AM »
Yeah i can manually delete stuff from there. Just wanted to know if it affects my computer in harmful way.  ???

Offline LeoniAquila

  • Retired moderator
  • Comodo's Hero
  • *****
  • Posts: 6745
Re: "C:\Windows\system32\CatRoot2" <-- What is that?
« Reply #5 on: October 16, 2008, 09:52:28 AM »
Yeah i can manually delete stuff from there. Just wanted to know if it affects my computer in harmful way.  ???

As long as it's not executed, it's not harmful. You can safely delete all contents in the temp folder.

LA

Offline Arun S

  • Newbie
  • *
  • Posts: 20
Re: "C:\Windows\system32\CatRoot2" <-- What is that?
« Reply #6 on: March 31, 2009, 04:21:10 AM »
Hi,

C:\Windows\system32\CatRoot2   folder is an impotant folder which helps to fetch regular Windows Updates.  The Catroot2 folder is automatically recreated by Windows once it is deleted. For the most of the windows Updates issues, once you delete or rename the catrrot2 folder wil fix the issue because once you have renamed or deleted the catrroot2 folder it will refresh the update history..

Offline napsterz

  • Computer Security Testing Group
  • Comodo's Hero
  • *****
  • Posts: 396
    • COMODO - Creating Trust Online
Re: "C:\Windows\system32\CatRoot2" <-- What is that?
« Reply #7 on: May 11, 2009, 05:10:40 AM »
Hi,

C:\Windows\system32\CatRoot2   folder is an impotant folder which helps to fetch regular Windows Updates.  The Catroot2 folder is automatically recreated by Windows once it is deleted. For the most of the windows Updates issues, once you delete or rename the catrrot2 folder wil fix the issue because once you have renamed or deleted the catrroot2 folder it will refresh the update history..

Hi,
Just An Added Information To What You Have Mentioned. Its A Folder Which Stores The Signatures Of Windows Update Package And Allows It To Be Installed. The File %windir%\System32\catroot2\edb.log will be updated by the cryptographic services. So Inorder To Delete The Folder The Cryptographic Services Has To Be Stopped First. All The Updates Are Stored Under The Folder %windir%\SoftwareDistribution And Its managed By The Automatic Updates Service.
In Life We All Have An Unspeakable Secret, An Irreversible Regret, An Unreachable Dream And Unforgettable Love...!!!

 

Seo4Smf 2.0 © SmfMod.Com | Smf Destek