White-Listing Files in SFC?

drfsupercenter

New member
Power User
Local time
6:25 AM
Messages
198
OK,

So my new hard drive finally came, I put it in and did a complete clean install of Windows 7.

I just got done replacing Wordpad and Paint with the Windows Vista versions, simply because I hate that stupid Ribbon interface. Unlike last time, it still boots perfectly, and when I run either of those programs it runs the proper Vista versions.

However, if I ever do sfc /scannow it obviously detects something fishy and puts back the original Windows 7 files.

So I'm just curious: Is there some way to tell system file checker "Ignore these files, just scan all the rest"?
 

My Computer

Computer Manufacturer/Model Number
MSI
OS
Windows 7 Ultimate and Ubuntu 9.04
CPU
Intel Core 2 Quad
Memory
4GB DDR3 RAM
Graphics Card(s)
NVIDIA GTS 160M (1GB GPU)
Sound Card
Realtek HD Audio
Screen Resolution
1680x1050
Hard Drives
500GB SATA
No, that would be silly if that was possible. Malware would have an easier time modifying system files if there was a white-list...
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
Aww :(

So can I do a system file check and not check those files manually?
 

My Computer

Computer Manufacturer/Model Number
MSI
OS
Windows 7 Ultimate and Ubuntu 9.04
CPU
Intel Core 2 Quad
Memory
4GB DDR3 RAM
Graphics Card(s)
NVIDIA GTS 160M (1GB GPU)
Sound Card
Realtek HD Audio
Screen Resolution
1680x1050
Hard Drives
500GB SATA
You could install Vista, then those file would no longer be an issue. Or you could just learn to adapt to the Ribbon Interface.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
LOL, the whole point in upgrading to Windows 7 was to not have to put up with Vista...
 

My Computer

Computer Manufacturer/Model Number
MSI
OS
Windows 7 Ultimate and Ubuntu 9.04
CPU
Intel Core 2 Quad
Memory
4GB DDR3 RAM
Graphics Card(s)
NVIDIA GTS 160M (1GB GPU)
Sound Card
Realtek HD Audio
Screen Resolution
1680x1050
Hard Drives
500GB SATA
I'm having a similar issue. Although, instead of wanting to whitelist some files from sfc, I was wondering if it was possible to merely disable the service from automatically running.

I have modded my explorer.exe file and I wouldn't mind just being able to manually run sfc when I need to troubleshoot my system-- I do not need Windows to do this for me!
 

My Computer

OS
Windows 7 x64 Professional
No, that would be silly if that was possible. Malware would have an easier time modifying system files if there was a white-list...
There is nothing silly about an operator being able to control their own computer in the fashion that they wish. This is a question that I have had in the back of my mind for a while, but didn't decide to voice until now.

I know that in XP there was a problem with SFC replacing updated files, even when they were from MS, because it referenced the installation CD. Since the CD is no longer necessary, I assume that this reference is recorded in the installation somewhere, but I know not where?

Previously, it was possible to tell SFC to accept, reject or ignore any particular "problem" that it found, so that it was possible to have some control over the matter, assuming that one went to the trouble of checking them out. This no longer appears to be possible.

Whether the file involved is changed via update or by user changes, there should be a way to prevent SFC from automatically reverting back to the original files. This is one reason that I don't use SFC now, unless I feel that there is no choice.
 

My Computer

Computer Manufacturer/Model Number
DIY
OS
W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
CPU
Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3
Motherboard
ASRock 890FX Deluxe 4/**A8N-SLI
Memory
2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS
Graphics Card(s)
EVGA GTX460 SC/**EVGA 8800GTS
Sound Card
Asus Xonar D2X/**Xonar D1
Monitor(s) Displays
Acer X233H, Dell E152FPc /**LG M237-WD
Screen Resolution
1920x1080 & 1024x768/**1980x1080
Hard Drives
WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black
PSU
CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000
Case
HAF922/**Antec 1040IIB
Cooling
3x200mm, 1x140 and 1x120mm/**5x80mm fans
Keyboard
Logitech Media USB/**Saitek Eclipse
Mouse
Cordless Trackman Wheel/**Ditto
Internet Speed
3.3Mbps
Other Info
SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig)
@seekermeister

One reason that I choose to still use sfc is because it helps me to update files sometimes. As you stated, sfc does reference some sort of library for the files that it checks against clearly because I've modded my explorer.exe version 16385 and sfc replaced the file with version 16450. Windows Update must have released a newer version/fix for explorer, however that file is definitely stored somewhere on the computer.

I do not want sfc to replace my explorer.exe with the correct version automatically, but I do occasionally like to update the file so I would prefer to run it manually or when I troubleshoot.

One interesting thing though is that if sfc is referencing some library for the uncorrupted version of the file, then wouldn't malware just as easily replace the reference file? The only way around this would be to use the CD as the reference. So, you're right, it definitely isn't silly because malware would be able to take advantage of the reference file regardless.
 

My Computer

OS
Windows 7 x64 Professional
Googling, it appears that it is referencing the sfc.dll and/or sfc_os.dll. Googling that, there is a lot of returns indicating that these could be replaced via malware/trojan. So it clearly indicates that SFC is far from foolproof.
 

My Computer

Computer Manufacturer/Model Number
DIY
OS
W7x64 Pro, SuSe 12.1/** W7 x64 Pro, XP MCE
CPU
Phenom II 1090T w/Noctua NH-D14 /**4400+ X2 w/CM Hyper TX 3
Motherboard
ASRock 890FX Deluxe 4/**A8N-SLI
Memory
2 x 2GB Patriot PGS34g1600LLKA/**4x1GB Corsair VS
Graphics Card(s)
EVGA GTX460 SC/**EVGA 8800GTS
Sound Card
Asus Xonar D2X/**Xonar D1
Monitor(s) Displays
Acer X233H, Dell E152FPc /**LG M237-WD
Screen Resolution
1920x1080 & 1024x768/**1980x1080
Hard Drives
WDC 2TB, 1.5TB, 1TB, 500GB,Seagate 500GB , Maxtor 80GB /**500GB Seagate & WDC 1TB Black
PSU
CM RS600 w/ APC BX1000G/**Antec 500 TP w/ APC BX1000
Case
HAF922/**Antec 1040IIB
Cooling
3x200mm, 1x140 and 1x120mm/**5x80mm fans
Keyboard
Logitech Media USB/**Saitek Eclipse
Mouse
Cordless Trackman Wheel/**Ditto
Internet Speed
3.3Mbps
Other Info
SB 560 5.1 w/ Sennheiser RS140/**Creative T20 speakers, Dvico FusionHDTV7 Gold RT, Cisco E3000, HP 5510V AIO, Linksys E3000, Belkin F5U237 hub and **F5D8055 adapter
(** = 2nd rig)
Back
Top