[RESOLVED] Help me delete a file!!
Results 1 to 8 of 8

Thread: [RESOLVED] Help me delete a file!!

  1. #1
    Join Date
    Jul 2002
    Location
    Sarasota FL
    Posts
    73

    Resolved [RESOLVED] Help me delete a file!!

    Hi there,

    I don't ask many questions here. But I have one today.
    I have this file in windows\system32 dir.
    It was left there by a computer virus.
    I have already been thru all the virus stuff, I just need to delete this file.
    This is what I have done so far. All say access denied. (file remains)

    Safe mode. no luck
    windows repair console same , access denied
    winternals boot disk ,, does not see Windows XP home directory. So no good.

    I have free dos (NTFSBOOT) disk,, I can drill to the file. no delete.

    knoppix doesn't see the hard disk in this laptop.

    The laptop runs fine, but maleware bytes and spyware bytes report this file as an issue. I can say ignore to this file, and I see no lingering issue with it.

    There is no mention of it in the registry.

    hijack this sees the file,, checking it off, does not get it.

    In all my years I have never been to a place where a file can't be deleted.
    I understand the concept that you may erase a file, but a virus puts it back. Something is locking this file.

    I tried several download.com file erasers. they work on the dll, but the end result is , it can't remove the file.
    Sorry I am making this a long story.
    Give me the magic bullet so I can erase this file.

    Thanks
    Bill

  2. #2
    Join Date
    Mar 2000
    Location
    Hyde Park, NY
    Posts
    2,047
    Biostar TA790GX A2+ 6.0
    AMD Phenom X4 9750 CPU.
    4 Gig DDR2 Memory.
    ATI HD 5450 PCIe Video
    ATI HD 5450 PCIe Video
    500 Watt P.S.
    LG W2241T Widescreen 22" LCD
    ViewSonic VA721 17" LCD
    Envision 17" LCD
    2 LG DVD Drives
    Floppy Disk Drive
    Maxtor 120 Gig Windows 7 Home Premium 32 bit
    Gateway NV5378-U Windows 7 Home Premium 64 bit
    Acer Aspire V3-731 Windows 7 Home Premium 64 bit

  3. #3
    Join Date
    Sep 1999
    Location
    Clearwater, Fl.
    Posts
    22,607
    What is the name of the file?

    Odds are you'll find it running in Task Manager and can end task on it and then try to delete it.
    If you're happy and you know it......it's your meds.

  4. #4
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    If Super, and Bytes are not able to delete that file, it means, your computer is still infected.
    I suggest, you go to our HJT section, and post all logs there.

  5. #5
    Join Date
    Jul 2008
    Location
    Australia.
    Posts
    24
    Browse to the file via your command prompt, and just change the attrib permissions on the folder / file

    then delete the folder / file.

    Make sure system restore has been disabled 1st.

    then once deleted re-enable system restore.

  6. #6
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    ...
    If Super, and Bytes are not able to delete that file, it means, your computer is still infected.
    I suggest, you go to our HJT section, and post all logs there.

  7. #7
    Join Date
    Jul 2002
    Location
    Sarasota FL
    Posts
    73

    Fixed

    Thanks so much for the replies.
    I had tried these things mentioned here.
    The HijackThis was the closest to the fix.
    But for whatever, even after repoot the file was still there.
    File attrib on this file just showed A
    I did try to add -h to the file (attrib -h)
    but it came back and said acess denied.

    The file name is (was)
    C:\windows\system32\upsfeqf.dll

    clearly the trigger file (on this laptop) for Trojan.Vundo.H

    I didn't want to do it, but I took the drive out of the laptop, 2nd hard disk on my PC.
    Drilled down to the file and was able to delete it.
    Drive back in laptop,, now nothing found with malwarebytes, and superantspyware.

    Reminds me of the 'old days' when you would hack the fat table to get rid of a stubborn file.

    Again,,, thanks,
    Bill

  8. #8
    Join Date
    Dec 2006
    Location
    Canada
    Posts
    317
    It's actually quite simple, but please follow these instructions precisely.

    First you download a program called "Pocket Killbox".

    Next, do the following:

    • Go into My Computer
    .
    • Click on tools

    • Click on Folder Options

    • Click on the View tab

    • Check "Show hidden files and folders"

    • Uncheck "'Hide protected operating system files (recommended)"

    • Click Yes to confirm

    • Uncheck "Hide extensions for known file types"

    • Click ok



    Next, open Pocket Killbox.

    • To the right of the blank box there's a folder icon. Click it.

    • Browse to the file you want to delete and select it.

    • Check "end Explorer shell while killing file"

    • Check "unregister .dll before deleting"

    • Click the Red X


    It should delete it. If not, then rather than Standard File kill, check "Delete on Reboot".

    If you have a malware program monitoring registry entries, such as spybot, this may not work. Get rid of Spybot anyways, it's useless. Otherwise halt the protection temporarily or perform this action in Safe Mode.
    Last edited by SirKenin; July 1st, 2009 at 02:22 PM.
    Bash him into the ground, make jokes and call him names while he's alive...Revere him when he dies. Pathetic.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •