Question

Undeleteable File

Asked by: plated

Someone compramised my Windows XP Pro machine awhile ago and left two .vbs files in my My Documents folder, I've tried to delete them and I get access denied and I'm administrator.

I've tried booting into Safe Mode and using the actual Administrator account and then trying to delete them, still access denied.

I even get access denied when trying to view the file.

The files name is "entersadman                                                          .vbs"

Any ideas? If you need me to clarify more just let me know.

Thanks,
  Bryan

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2003-12-18 at 21:12:18ID20830218
Tags

undeleteable

,

file

Topic

Windows XP Operating System

Participating Experts
6
Points
125
Comments
15

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Undelete
    Is it possible to search for and list deleted files on Win95/98/ME and select to undelete them using VB6. And if so could the same code be used accross a network to undelete files on a networked PC. Could some one please help me out or point to where I can find information on...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: sunray_2003Posted on 2003-12-18 at 21:13:00ID: 9970033

You need to take ownership of the file


HOW TO: Take Ownership of a File or Folder in Windows XP
http://support.microsoft.com/default.aspx?scid=kb;en-us;308421&sd=tech

HOW TO: Set, View, Change, or Remove File and Folder Permissions in Windows XP
http://support.microsoft.com/default.aspx?scid=kb;en-us;308418

http://support.microsoft.com/default.aspx?scid=kb;en-us;320081

http://www.theeldergeek.com/delete_undeletable_file.htm

Sunray

 

by: shivsaPosted on 2003-12-18 at 21:21:24ID: 9970062

From Windows Explorer, right click on the file and choose properties. Select security and then click the advanced button.  Now change the owner to youself.
and then try to delete it.

 

by: platedPosted on 2003-12-18 at 21:21:47ID: 9970064

Good thinking, but i've already tried to take ownership. When you right click a .vbs script it just has Open, Open With, Open in Command Prompt, Edit, Send To. There is no properties tab.

 

by: sunray_2003Posted on 2003-12-18 at 21:25:26ID: 9970073

Did you check other links in my previous comment ?

Sunray

 

by: shivsaPosted on 2003-12-18 at 21:27:22ID: 9970079

u can try disabling file sharing.
Click Start, and then click My Computer-> On the Tools menu, click Folder Options, and then click the View ->Advanced Settings section, clear the Use simple file sharing (Recommended) check box.

now check if u see the properties.

 

by: shivsaPosted on 2003-12-18 at 21:33:14ID: 9970094

also u can delete file from dos.
Start >Run >cmd
Navigate to the folder the file is in, i.e. if its in c:\folder\yourfile,
cd c:\folder
The coomand prompt shoud change to let you know you are in the correct directory.
dir /x
file will be listed like (enter~1.vbs)
type "del enter~1.vbs"

 

by: pr0m3th1usPosted on 2003-12-18 at 21:34:59ID: 9970103

Hmmmm... that sounds odd. There should be "properties" in a .vbs file - in any file for that matter.

This was taken from one of the links Sunray gave you.. You should READ CAREFULLY..

I noticed the file has a trailing space before the .vbs - this article explains a little on what to do, so read on:

Cause 1:
The File Uses an ACL
You may not be able to delete a file if the file uses an Access Control List (ACL). To resolve this issue, change the permissions on the file. You may have to take ownership of the files to be able to change the permissions.

Administrators have the implicit ability to take ownership of any file even if they have not been explicitly granted any permission to the file. File owners have the implicit ability to modify file permissions even if they are not explicitly granted any permissions to the file. Therefore, you may have to take ownership of a file, give yourself permissions to delete the file, and then delete the file.


You Cannot Use Certain Security Tools to Display or Modify Permissions Because the File Has a Non-Canonical ACL
To work around this issue, use another tool (for example, a later build of Cacls.exe).

The Access Control Entries (ACEs) in an ACL have a certain preferred sequence depending on their type. For example, ACEs that deny access typically come before ACEs that grant access. However, nothing prevents a program from writing an ACL that has ACEs in any arbitrary sequence. In some earlier versions of Windows, issues occurred when Windows tried to read these "non-canonical" ACLs. In some situations, you cannot modify these ACLs correctly by using the Windows Explorer graphical security editor. This issue has been corrected in later versions of Windows. If you are experiencing this issue, use the most recent version of Cacls.exe. Even if you cannot display or edit an ACL in place, you can write a new ACL that permits you to gain access to the file.

Cause 2:
The File Is Being Used
You may not be able to delete a file if the file is being used. To resolve this issue, determine the process that has the open handle, and then close that process.

Depending on how the file is opened (for example, it is open for exclusive access as opposed to shared access), you may not be able to delete a file that is in use. You can use a variety of tools to help you determine the processes that have open handles to files at any time.

For additional information about tools to help the processes that have open handles to files, click the article numbers below to view the articles in the Microsoft Knowledge Base:
242131 How to: Display a List of Processes That Have Files Open

172710 How to Use the OH Tool on the Windows NT 4.0 Resource Kit

The symptoms of this issue may vary. You may be able to use the delete command to delete a file, but the file is not actually deleted until the process that has the file open releases the file. Additionally, you may not be able to access the Security dialog box for a file that is pending deletion. To resolve this issue, determine the process that has the open handle, and then close that process.


Cause 3:
File System Corruption Is Preventing Access to the File
You may not be able to delete the file if the file system is corrupted. To resolve this issue, run the Chkdsk utility on the disk volume to correct any errors.

Bad sectors on the disk, other faulty hardware, or software bugs can corrupt the file system and put files in a problematic state. Typical operations may fail in a variety of ways. When the file system detects corruption, it logs an event to the event log and you typically receive a message that prompts you to run Chkdsk. Depending on the nature of the corruption, Chkdsk may or may not be able to recover file data; however, Chkdsk returns the file system to an internally consistent state.

For additional information about using the Chkdsk utility, click the article numbers below to view the articles in the Microsoft Knowledge Base:
176646 Error Message: The File or Directory Is Corrupt...

187941 An Explanation of CHKDSK and the New /C and /I Switches

Cause 4:
Files Exist in Paths That Are Deeper Than MAX_PATH Characters
You may not be able to open a file if there are issues with the file path.

Resolution 1:
Use an Auto-Generated 8.3 Name to Access the File
To resolve this issue, you may want to use the auto-generated 8.3 name to access the file. This resolution may be the easiest resolution if the path is deep because the folder names are too long. If the 8.3 path is also too long or if 8.3 names have been disabled on the volume, go to Resolution 2.

For additional information about disabling 8.3 file names on NTFS volumes, click the article number below to view the article in the Microsoft Knowledge Base:
121007 How to Disable the 8.3 Name Creation on NTFS Partitions

Resolution 2:
Rename or Move a Deep Folder
To resolve this issue, rename the folder so that the target files that are deeper than the MAX_PATH no longer exist. If you do so, start at the root folder (or any other convenient place), and then rename folders so that they have shorter names. If this step does not resolve this issue (for example, if a file is more than 128 folders deep), go to Resolution 3.
Resolution 3: Use a Network Share That Is As Deep As the Folder
If Resolution 1 or Resolution 2 is not convenient or does not resolve the issue, create a network share that is as deep in the folder tree as you can, and then rename the folders by accessing the share.
Resolution 4: Use a Tool That Can Traverse Deep Paths
Many Windows programs expect the maximum path length to be shorter than 255 characters; therefore, these programs only allocate enough internal storage to accommodate these typical paths. NTFS does not have this limit and it is capable of accommodating much longer paths.

You may experience this issue if you create a share at some point in your folder structure that is already fairly deep, and then create a deep structure below that points by using the share. Some tools that operate locally on the folder tree may not be able to traverse the entire tree starting from the root. You may have to use these tools in a special way so that they can traverse the share. (The CreateFile API documentation describes a method to traverse the entire tree in this situation.)

Typically, you can manage files by using the software that creates them. If you have a program that can create files that are deeper than MAX_PATH, you can typically use that same program to delete or manage the files. You can typically delete files that are created on a share by using the same share.
Cause 4: The File Name Includes a Reserved Name in the Win32 Name Space
If the file name includes a reserved name (for example, "lpt1") in the Win32 name space, you may not be able to delete the file. To resolve this issue, use a non-Win32 program to rename the file. You can use a POSIX tool or any other tool that uses the appropriate internal syntax to use the file.

Additionally, you may be able to use some built-in commands to bypass the typical Win32 reserved name checks if you use a particular syntax to specify the path to the file. For example, if you use the del command in Windows XP, you can delete a file named "lpt1" if you specify the full path to the file by using the following special syntax:
del \\?\c:\path_to_file\lpt1

For additional information about deleting files with reserved names under Windows NT and Windows 2000, click the article number below to view the article in the Microsoft Knowledge Base:
120716 How to Remove Files with Reserved Names in Windows

For additional information about deleting files with reserved names under Windows XP, click the article number below to view the article in the Microsoft Knowledge Base:
315226 How to Remove Files with Reserved Names in Windows XP

If you open a handle to a file by using the typical Win32 CreateFile mechanism, certain file names are reserved for old-style DOS devices. For backward compatibility, these file names are not allowed and they cannot be created by using typical Win32 file calls. However, this issue is not a limitation of NTFS.

You may be able to use a Win32 program to bypass the typical name checks that are performed when a file is created (or deleted) by using the same technique that you use to traverse folders that are deeper than MAX_PATH. Additionally, some POSIX tools are not subject to these name checks.
Cause 5: The File Name Includes an Invalid Name in the Win32 Name Space
You may not be able to delete a file if the file name includes an invalid name (for example, the file name has a trailing space or a trailing period or the file name consists of a space only). To resolve this issue, use a tool that uses the appropriate internal syntax to delete the file. You can use the "\\?\" syntax with some tools to operate on these files, for example:
del "\\?\c:\path_to_file_that contains a trailing space.txt "

The cause of this issue is similar to Cause 4. However, if you use typical Win32 syntax to open a file that has trailing spaces or trailing periods in its name, the trailing spaces or periods are stripped before the actual file is opened. Therefore, if you have two files in the same folder named "AFile.txt" and "AFile.txt " (note the space after the file name), if you try to open the second file by using standard Win32 calls, you open the first file instead. Similarly, if you have a file whose name is just " " (a space character) and you try to open it by using standard Win32 calls, you open the file's parent folder instead. In this situation, if you try to change security settings on these files, you either may not be able to do so or you may unexpectedly change the settings on different files. If this behavior occurs, you may think that you have permission to a file that actually has a restrictive ACL.
Combinations of Causes
In some situations, you may experience combinations of these causes, which can make the procedure to delete a file more complex. For example, if you log on as the computer's administrator, you may experience a combination of Cause 1 (you do not have permissions to delete a file) and Cause 5 (the file name contains a trailing character that causes file access to be redirected to a different or nonexistent file) and you may not be able to delete the file. If you try to resolve Cause 1 by taking ownership of the file and adding permissions, you still may not be able to delete the file because the ACL editor in the user interface cannot access the appropriate file because of Cause 6.

In this situation, you can use the Subinacl utility with the /onlyfile switch (this utility is included in the Resource Kit) to change ownership and permissions on a file that is otherwise inaccessible, for example:
subinacl /onlyfile "\\?\c:\path_to_problem_file" /setowner=domain\administrator /grant=domain\administrator=F

NOTE: This command is a single command line; it has been wrapped for readability.

This sample command line modifies the C:\path_to_problem_file file that contains a trailing space so that the domain\administrator account is the owner of the file and this account has full control over the file. You can now delete this file by using the del command with the same "\\?\" syntax.



Mike

 

by: notch_ur_headPosted on 2003-12-18 at 22:50:03ID: 9970367

Hi plated

If i m not wrong, it is a virus and plz try to scan that file with an anti virus!!
I think this, may be i m worg, but still i hae doubt that it is a VIRUS..

Otherway,
Open Tassk manager, and 'END TASK' the file (if running there) and then try to delete coz i  think i starts running when ever ur system boots, so u cant delet the file even if u r administrator!

u can also check its presense in msconfig, regedit !!

and if u find any traces of this file in 'TASK MANAGER + REGEDIT + MSCONFIG' then it is a virus!

Plzz check for it before it hurts u more!

regards
-notch_ur_head

 

by: pr0m3th1usPosted on 2003-12-19 at 07:17:11ID: 9972573

Sorry, but didn't mention this in my previous post....

Read where it says "Cause 4:".. also try following through with the resolutions it gives.

And yes, I would definately do a virus scan as suggested by notch as vbs scripts can do nasty damage!

Best of luck

Mike

 

by: platedPosted on 2003-12-19 at 13:22:13ID: 9975175

I ran a virus scan, nothing.

When I view the file properties it doesn't have a create date, modified date, owner, size or anything.

Usually files you don't have access to allow you to TRY to rename them and then give you access denied, this file doesn't even let you do that.

I've tried those MSFT help pages, but they didn't help, thanks anyways.

Any other suggestions besides a nice reinstall of WinXP system partition?

 

by: notch_ur_headPosted on 2003-12-21 at 21:19:46ID: 9983443

Hi plated

Try to create a file:
Open the notepad and leave it empty!
Then save that wile with same name and extension like if name is abc and extension is xyz..then Press Save As and in the name text box write "abc.xyz" (i meand, DONT forget to put quotes at start an end)....save at desktop (any where)
and the COPY this file and try to paste in the folder at which the original file that u want to delete is placed..

Then computer will ask u to over-write the  previous file..press YES

and then see its properties, whether both the dates are there or not
+
Then again try to delete this file..from that folder!!

Did it helped????

regards
-n_u_h

 

by: PeteLongPosted on 2003-12-29 at 05:56:07ID: 10010501

Can’t Delete a File

**********
First see if this applies
"Access Denied" When You Delete Folders from a Mounted Drive
http://support.microsoft.com/default.aspx?scid=kb;en-us;243514

**********

You need permissions to delete a file are you a member of the Administrators group? (you need a minimum of {modify} to delete.

**********

Is it telling you the filename is too long?

Delete the file in DOS mode

Start >Run >cmd {enter}
Navigate to the folder the file is in, i.e. if its in c:\folder\anotherfolder\file, type "cd c:\folder\anotherfolder" {enter} The coomand prompt shoud change to let you know you are in the correct directory.
Type "dir /x" {enter}
The offending file will be listed like (filena~1.xxx)
Take note of the name and type "del filena~1.xxx" {enter}

**********
Try to take ownership of the file

Right click the file
Select the security Tab
Select properties
Select Advanced
Select Owner
Find the User or group you wish to give ownership to and select
Click apply

http://support.microsoft.com/default.aspx?scid=kb;en-us;268019

Now try and delete the file

**********
If your hard drive is formatted with FAT32 you can boot with a boot disk and Delete the file from DOS. (del filename.extension)
If you hard drive is formatted with NTFS you can boot with a boot disk and, if you lucky enough to have a copy of NTFSPro from http://www.sysinternals.com/ntw2k/freeware/ntfsdospro.shtml you can boot to DOS mount the NTFS volumes and delete it from there.

**********
Is the file flagged as ‘System’?

Strt > Run > type CMD >Click OK
Navigate to the folder in which the file resides (i.e. cd c:\folder\folder\ {enter})
Type attrib -r -s -a -h filename.extension {enter}
Del filename.extension {enter}

**********
Is the file in use?

If either the OS or another program is using the file you cannot delete it

You can with ZAP Included with the Microsoft SMS 2.0 Resource Guide and the Microsoft BackOffice Resource Kit 4.5. or you can download it here
http://helpdesk.kixtart.org/KixUtilsTasks.asp
WARNING make sure you know what your deleting first!

 

by: SanteIIPosted on 2004-01-05 at 02:37:15ID: 10041329

When you go to the cmd window and try to delete the file it doesnt have spaces between them.
Ie entersadman .vbs

Use ? betwwn the spaces.

entersadman?.vbs

 

by: PeteLongPosted on 2004-01-31 at 12:18:54ID: 10243654

Lots of good info, but no feedback for a while, if the asker does not return suggest PAQ/No Refund

PL

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...