|
-
June 30th, 2009, 03:19 PM
#1
[RESOLVED] Help me delete a file!!
Hi there,
I don't ask many questions here. But I have one today.
I have this file in windows\system32 dir.
It was left there by a computer virus.
I have already been thru all the virus stuff, I just need to delete this file.
This is what I have done so far. All say access denied. (file remains)
Safe mode. no luck
windows repair console same , access denied
winternals boot disk ,, does not see Windows XP home directory. So no good.
I have free dos (NTFSBOOT) disk,, I can drill to the file. no delete.
knoppix doesn't see the hard disk in this laptop.
The laptop runs fine, but maleware bytes and spyware bytes report this file as an issue. I can say ignore to this file, and I see no lingering issue with it.
There is no mention of it in the registry.
hijack this sees the file,, checking it off, does not get it.
In all my years I have never been to a place where a file can't be deleted.
I understand the concept that you may erase a file, but a virus puts it back. Something is locking this file.
I tried several download.com file erasers. they work on the dll, but the end result is , it can't remove the file.
Sorry I am making this a long story.
Give me the magic bullet so I can erase this file.
Thanks
Bill
-
June 30th, 2009, 04:38 PM
#2
Biostar TA790GX A2+ 6.0
AMD Phenom X4 9750 CPU.
4 Gig DDR2 Memory.
ATI HD 5450 PCIe Video
ATI HD 5450 PCIe Video
500 Watt P.S.
LG W2241T Widescreen 22" LCD
ViewSonic VA721 17" LCD
Envision 17" LCD
2 LG DVD Drives
Floppy Disk Drive
Maxtor 120 Gig Windows 7 Home Premium 32 bit
Gateway NV5378-U Windows 7 Home Premium 64 bit
Acer Aspire V3-731 Windows 7 Home Premium 64 bit
-
June 30th, 2009, 04:40 PM
#3
What is the name of the file?
Odds are you'll find it running in Task Manager and can end task on it and then try to delete it.
If you're happy and you know it......it's your meds.
-
June 30th, 2009, 07:51 PM
#4
If Super, and Bytes are not able to delete that file, it means, your computer is still infected.
I suggest, you go to our HJT section, and post all logs there.
-
June 30th, 2009, 08:13 PM
#5
Browse to the file via your command prompt, and just change the attrib permissions on the folder / file
then delete the folder / file.
Make sure system restore has been disabled 1st. 
then once deleted re-enable system restore.
-
June 30th, 2009, 08:21 PM
#6
...
If Super, and Bytes are not able to delete that file, it means, your computer is still infected.
I suggest, you go to our HJT section, and post all logs there.
-
July 1st, 2009, 11:45 AM
#7
Fixed
Thanks so much for the replies.
I had tried these things mentioned here.
The HijackThis was the closest to the fix.
But for whatever, even after repoot the file was still there.
File attrib on this file just showed A
I did try to add -h to the file (attrib -h)
but it came back and said acess denied.
The file name is (was)
C:\windows\system32\upsfeqf.dll
clearly the trigger file (on this laptop) for Trojan.Vundo.H
I didn't want to do it, but I took the drive out of the laptop, 2nd hard disk on my PC.
Drilled down to the file and was able to delete it.
Drive back in laptop,, now nothing found with malwarebytes, and superantspyware.
Reminds me of the 'old days' when you would hack the fat table to get rid of a stubborn file.
Again,,, thanks,
Bill
-
July 1st, 2009, 02:19 PM
#8
It's actually quite simple, but please follow these instructions precisely.
First you download a program called "Pocket Killbox".
Next, do the following:
.
- Check "Show hidden files and folders"
- Uncheck "'Hide protected operating system files (recommended)"
- Uncheck "Hide extensions for known file types"
Next, open Pocket Killbox.
- To the right of the blank box there's a folder icon. Click it.
- Browse to the file you want to delete and select it.
- Check "end Explorer shell while killing file"
- Check "unregister .dll before deleting"
It should delete it. If not, then rather than Standard File kill, check "Delete on Reboot".
If you have a malware program monitoring registry entries, such as spybot, this may not work. Get rid of Spybot anyways, it's useless. Otherwise halt the protection temporarily or perform this action in Safe Mode.
Last edited by SirKenin; July 1st, 2009 at 02:22 PM.
Bash him into the ground, make jokes and call him names while he's alive...Revere him when he dies. Pathetic. 
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|