Help - Search - Members - Calendar
Full Version: Can't Delete This File On An Extra Hd Got Any Ideas?
BleepingComputer.com > Security > Am I infected? What do I do?
   
Travisab1
Here’s where a photo of the file I can’t delete can be seen.

http://us.f13.yahoofs.com/bc/442a2df5m367f...fsSVRFBZduQvIn5

I've tried a lot of Anti-Spy wares, Virus detectors and none recognize it. I was told it was put there by my own computer and without my knowledge. It deleted all my Word doc files in my word doc folder and I can’t write to that folder and I can’t delete it. It is on another one of my 5 HD’s not on my “C” boot drive.

I just woke up one morning, tried to use MS Word, my screen became full of prompts, I went to my doc’s folder and it was empty save for the above file I’ve provided a link to.

If you need any further information please let me know and I’ll be glad to post the necessities to get rid of this problem. I’m not sure if it has or can do further damage to my computer but over 200 Word doc files have met the cyber space monster. Thanks to my back-up CD’s I didn’t lose the info for good.

As always with me you know you have my many thanks for any help given. Who knows? Maybe I too can help someone somewhere in here one day.

Thanks for this forum and to the folks at Yahoo Anti-Spy for showing me how to get here.

Travis

Moderator Edit: Moved topic to more appropriate forum. ~ Animal
quietman7
Have you tried doing your scans and deletion in "SAFE MODE"?

If so and that did not help, then there are several tools you can try.

Download Delete Doctor
alternate site.
After download, double-click on it to start and browse to the location of the files you want to delete. Choose Delete file on System Restart.

Download Unlocker
1. After install, right click the folder or file and select Unlocker from the menu.
2. If the folder or file is locked, a window listing of lockers will appear.
3. Click "Unlock All"
Travisab1
Quiteman:

Neither of them worked. Even on re-boot. I tried to take a picture of the DOS prompt info with PSP but unable to do that. This thing is really hanging in there.

When I can afford yet another HD to put the info left on that HD I'll bet that file will still be there after a complete format.

Have you ever seen such stubborn a file to remove before?

Travis
quietman7
There are other tools that can be used. What's the name of this file and what is its full path location?
Travisab1
The name and location of the file is H:\Word Documents S. There should be a square just before that S.

Here’s where a photo of the file I can’t delete can be seen.

http://us.f13.yahoofs.com/bc/442a2df5m367f...fsSVRFBZduQvIn5

Stubborn File huh?

Travis
quietman7
Go to jotti's virusscan or virustotal.com
In the "File to upload & scan" box, browse to the location of this file and submit [upload] it for scanning/analysis.
Post back with the results of the file analysis.
Travisab1
Quiteman:

As you can see these two sites you’ve given can’t recognize this file. You see in my screen capture of the file that it does have a number of KB’s not zero bytes. There is no square before the S in the file name. Virus total says it’s ___S. So this file isn’t letting programs read it for what it is.

There’s probably a simple explanation of this file but if there is I’m one simple guy that don’t know that simple answer.

I appreciate the help and hope you and the group doesn’t give up until this is resolved.

Thanks again. What do you think of these results?

BTW, these two sites are really involved in helping get rid of hackers and virus/malware.

Travis
http://virusscan.jotti.org/
The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file

http://www.virustotal.com/en/indexx.html
Complete scanning result of "___S", received in VirusTotal at 10.31.2006, 14:20:34 (CET).
Antivirus Version Update Result
AntiVir 7.2.0.34 10.31.2006 no virus found
Authentium 4.93.8 10.31.2006 no virus found
Avast 4.7.892.0 10.30.2006 no virus found
AVG 386 10.31.2006 no virus found
BitDefender 7.2 10.31.2006 no virus found
CAT-QuickHeal 8.00 10.30.2006 no virus found
ClamAV devel-20060426 10.31.2006 no virus found
DrWeb 4.33 10.31.2006 no virus found
eTrust-InoculateIT 23.73.41 10.31.2006 no virus found
eTrust-Vet 30.3.3170 10.31.2006 no virus found
Ewido 4.0 10.31.2006 no virus found
Fortinet 2.82.0.0 10.31.2006 no virus found
F-Prot 3.16f 10.31.2006 no virus found
F-Prot4 4.2.1.29 10.31.2006 no virus found
Ikarus 0.2.65.0 10.31.2006 no virus found
Kaspersky 4.0.2.24 10.31.2006 no virus found
McAfee 4884 10.30.2006 no virus found
Microsoft 1.1609 10.31.2006 no virus found
NOD32v2 1.1844 10.31.2006 no virus found
Norman 5.80.02 10.30.2006 no virus found
Panda 9.0.0.4 10.31.2006 no virus found
Sophos 4.10.0 10.26.2006 no virus found
TheHacker 6.0.1.109 10.30.2006 no virus found
UNA 1.83 10.30.2006 no virus found
VBA32 3.11.1 10.31.2006 no virus found
VirusBuster 4.3.15:9 10.31.2006 no virus found
Aditional Information
File size: 0 bytes
MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
quietman7
The file is probably tied to another file(s) and the unlocker program normally works for this. What information do you get when you right click on this file and look at its properties? What is the file extension? What is the date and do you recall what else you did with your pc on that date? This may provide some clues.
Travisab1
Quiteman:

I clicked on properties and added more information from the view menu. Here is a capture that adds a lot more detail to this file in GIF form.

Hope this helps.

http://us.f13.yahoofs.com/bc/442a2df5m367f...fIK2RFBF2.Vz_3y


This is a little more involved in information wise.

Travis
quietman7
Again, there seems to be a problem with your link. I get "Server not found"...

Can you just write down the info and paste it in your next reply?
Travisab1
This is from Photo Bucket of The File





The read onle is not checked any longer and it still can't be deleted. I don't know why it showed up being checked. Maybe when I passed over it with PSP's photo caption it lit up. Read only has never been checked before as far as I know. I still can't delete this file and hope you folks know I'm trying everything I can to get this resolved and appreciate your time in helping me.

Travis
Travisab1
Quiteman:

As you can see, a picture is worth a thousand words. Look at how the byte rate doesn't match and the date this file was created and modified. This is an impossibility since you can't modify something before it was created. I don't know what brought this sticky file into a different HD other than my boot drive. This is most puzzeling to me.

Travis
quietman7
Can you find out what type of file is this? I don't see an extension. Open Windows Explorer > Tools > Folder Options > View and make sure "Hide extensions..." is unchecked.
Travisab1
OK Quiteman.

I'll do that now. I did have a bad download of IE7 and did an earlier time restoration to get rid of IE7. Some folks think this may have caused problems. I'll undo the hide extensions and place a copy here with all the goodies.

Travis
Travisab1
Quiteman:

Here’s a complete test of what I currently have in GIF form. I’m going to download "windows installer cleanup utility" from Microsoft's site and run it to see what happens. I’ll post the results here afterwards. Let me know if you have any more Ideas if you will. Now, first, I’m going to turn back on my hide file extensions before I really do a nasty. I didn’t see any change and I turned all the view’s on under Choose Details in the view menu. This has got to be an unusual phenomenon.

Travis


quietman7
Another thing you may want to try is renaming the file. I don't know if it will allow a name change but its worth a try.
Travisab1
Quiteman:

After reading all the stuff windows installer cleanup utility uninstalls I’m a little bit leary of using this program. I didn't see anything about IE XX to 7 either. I have a lot of these programs on my computer and would hate to have to re-install and update them all.

Maybe there's another way to get rid of this leach huh?

Travis
Travisab1
QUOTE(quietman7 @ Nov 1 2006, 10:21 AM) *
Another thing you may want to try is renaming the file. I don't know if it will allow a name change but its worth a try.


I can't rename the file. I have no access at all tothis file other than being able to see it.

Travis
quietman7
Does the no access include when your in safe mode?

What do you use this extra HD for and can you confirm that it is an separate hard drive (external, internal) or is it a partition? If its separate and since nothing seems to be working, it may be time to move any important data from that drive and reformat.
Travisab1
Quiteman:

Yes, I can't do a thing with it in the Safe Mode either. Almost the same prompts come up in Safe Mode as well.

I use this HD to store archived programs/updates/videos/audio & some photos repaired.

I’m using 92.2 GB of this separate HD which holds 115 GB of information. I have 5 HD’s, “C” being one of them. I have one HD in the extra space in the tower, another taking the place of a CD writer, (I use my Memorex DVD/CD writer in another bay. I also have two exterior USB port ran HD’s. If all else fails, when I can afford it I’ll buy another USB HD and transfer all info from H to the new HD and re-format “H” HD hoping this gets rid of it.

I can use all folders/programs on the drive that this pest file is on with no problem, (this PEST file is in my used to be Word Documents folder, sort of isolated…I hope), as of now anyway. I’m just hoping that this thing doesn’t come out of its dormant stage and start reeking havoc on the rest of my computer if it is a Virus/Malware/ETC…

Travis
quietman7
It doesn't appear to be anything malware related that I have ever encountered. Of course it would not hurt to back up all your data and/or disconnect the drive until you can get a replacement.
Travisab1
You got a point there Quiteman. I suppose I should turn it off.

This is such an unusual problem that seems only I've had. No-one can relate to it. I've taken everything off it that I'd have a hard time replacing.

If you run across any fixes I'd appreciate it if you'd let me know.

Otherwise, I'm dropping it for now until I can afford another HD and able to transfer and re-format drive H.

Thanks for all the input Quiteman.

Travis
quietman7
Your welcome and good luck. If I learn anything new, I'll get back to you.
Travisab1
Quiteman:

Here's the latest...

Remember Me Losing Word Docs? LOOK AT THIS!!!

I turned on drive H again to see if anything was or had happened. Wellllll, nearly every cartoon, over two hundred of them are corrupt and I’m unable to read all but te ones you see left. The others or either deleted or in these folders I have no access to.

Look out folks. If this can happen to me it can happen to you.

Anybody got any Ideas of how to get rid of this piece of crap???

Here’s what it looks like…



I don’t know how many other files are missing in my drive H but there’s a lot of them gone into cyber-oblivion.

Welllll, I did it. I didn't have that much left on Drive H sooooo, I savead what I could and formated the stupid piece of dung from my HD. Sheesh, What a waste of good material.

That thing what ever it was couldn't withstand a format. I hope you folks can figure out what it was. I also hope it didn't find a way to other HD's on my system. I still have all the pictures of it if they're needed.

There's got to be a way to get rid of that thing without doing a format.

Helpth.

Travis
Travisab1
Quiteman:

I think I’ve figured out why this virus attached to my Word Doc’s Folder but not how. The hacker figured that most people save their doc files to a folder on drive “C”. That being the case, this would have ruined everything on my “BOOT DRIVE C”. This would have made restoring to an earlier date impossible, (not being able to move, delete otherwise get rid of the destructive file without a complete format, {destructive recovery} to the boot drive) rendering drive “C” almost useless. I used drive “H” for my Word Doc Folder. I did lose most everything I had on drive “H”. I had to re-format drive “H” to get rid of the file that eventually ruined drive “H”.

Travis
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.