Hi Per,
When you delete a file, the complete path and file name is stored in a
hidden file called Info2 in the Recycler folder.
for example, Dc12466.txt
D means Deleted.
c means the dile was deleted from the C: drive.
12466 means it was the 12466th deleted file.
txt means it was a text file, probably testing_2.txt
I wonder why the high number, 12466? INFO2 messed up?
If I paste this into the Run command (Start | Run ) and click OK
C:\RECYCLER\S-1-5-21-1708537768-1580436667-1202660629-1003\info2
the Open With applet comes up.
Select Notepad and click OK or just double click on Notepad from the list.
INFO2 opens.
Or you can do this in a command prompt...
start C:\RECYCLER\S-1-5-21-1708537768-1580436667-1202660629-1003\info2
the Open With applet comes up.
Select Notepad and click OK or just double click on Notepad from the list.
INFO2 opens.
This what's in my INFO2...
C:\Documents and Settings\Wesley P. Vogel\Desktop\278startmenupin.reg
C : \ D o c u m e n t s a n d S e t t i n g s \ W e s l e y P . V o
g e l \ D e s k t o p \ 2 7 8 s t a r t m e n u p i n . r e g
C:\Documents and Settings\Wesley P. Vogel\Desktop\startmenupin.reg
C : \ D o c u m e n t s a n d S e t t i n g s \ W e s l e y P . V o
g e l \ D e s k t o p \ s t a r t m e n u p i n . r e g
C:\Documents and Settings\Wesley P. Vogel\Desktop\pinlistenable.reg
C : \ D o c u m e n t s a n d S e t t i n g s \ W e s l e y P . V o
g e l \ D e s k t o p \ p i n l i s t e n a b l e . r e g
C:\Documents and Settings\Wesley P. Vogel\Desktop\New Text Document.txt
C : \ D o c u m e n t s a n d S e t t i n g s \ W e s l e y P . V o
g e l \ D e s k t o p \ N e w T e x t D o c u m e n t . t x t
------------
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.
C:\>cd C:\RECYCLER\S-1-5-21-1708537768-1580436667-1202660629-1003
C:\RECYCLER\S-1-5-21-1708537768-1580436667-1202660629-1003>dir
Volume in drive C is Local Disk
Volume Serial Number is 901E-9F82
Directory of C:\RECYCLER\S-1-5-21-1708537768-1580436667-1202660629-1003
22-Nov-06 10:46 AM 1,454 Dc1.reg
22-Nov-06 10:43 AM 1,454 Dc2.reg
22-Nov-06 10:45 AM 161 Dc3.reg
22-Nov-06 11:42 AM 0 Dc4.txt
4 File(s) 3,069 bytes
0 Dir(s) 2,128,506,880 bytes free
C:\RECYCLER\S-1-5-21-1708537768-1580436667-1202660629-1003>
--------------
You can see how Dc1.reg, Dc2.reg, Dc3.reg and Dc4.txt relate to
278startmenupin.reg, startmenupin.reg, pinlistenable.reg and New Text
Document.txt.
Also, I'd like to be able to restore the files put in the trashcan
(even if I put them there from the command line).
Would probably be some sort of a Shell function or call. I have no idea
which one and am not going to go look. Most of that stuff is over my head.
But when I look in the trashcan using the standard GUI I cannot see the
file in there. The trashcan looks as if is empty.
[[No files may appear in the Recycle Bin if the files in the Recycled folder
are damaged.]]
Run chkdsk. Reboot. Look at the Recycle Bin again.
INFO2 can become corrupted and if it cannot be fixed it needs to be deleted.
Cannot Delete Any Files in Windows
http://support.microsoft.com/kb/246726
How the Recycle Bin Stores Files
http://support.microsoft.com/kb/136517
Is there perhaps some other exe-file that is run when a user presses
the "delete" button in a regular folder view? and/or generates the info
in INFO2?
My silly wild a** guess would be explorer.exe and shell32.dll.
I just found this one, looks interesting haven't read it yet.
Forensic Analysis of Microsoft Windows Recycle Bin Records
http://www.e-fense.com/helix/Docs/Recycler_Bin_Record_Reconstruction.pdf
or view as html
http://72.14.253.104/search?q=cache...ion.pdf+"INFO2+file"&hl=en&gl=us&ct=clnk&cd=2
--
Hope this helps. Let us know.
Wes
MS-MVP Windows Shell/User
In