Solved

How can you delete a file (possible infection)

Posted on 2010-11-19
11
961 Views
Last Modified: 2013-11-22
When launching CCleaner the laptop freeze systematically at 75% when clean folder under
C:\Documents and Settings\dsaade\Application Data\Sun\Java\

When launching AVG the laptop freezes when reaching
C:\Documents and Settings\dsaade\Application Data\Sun\Java\Deployment

We did run Malware byte in safe mode
We did Install unlocker1.9.0.exe to delete this *.idx file (1 KB)
Also Installed moveonb.msi to delete this *.idx file at reboot

No success

We did pinpoint the problem as being this *.idx file

C:\Documents and Settings\dsaade\Application Data\Sun\Java\Deployment\cache\6.0\62\7c1e60be-2c033b73.idx

As soon as we touch it (even right click we wanted to open it with notepad) the PC freezes

We did launch Check Disk on the C drive:
checked - Automatically fix system errors
checked - Scan for and attempt recovery of bad sectors

At reboot:
What appear on the screen at chkdsk: file record segment 89044
0
Comment
Question by:havette
  • 2
  • 2
  • 2
  • +5
11 Comments
 
LVL 12

Expert Comment

by:TK-77
ID: 34177102
You could try making a bootable CD with Dr Web Cureit and running a virus scan that way. That may remove the file. It's a free download:

http://www.freedrweb.com/livecd/

TK
0
 
LVL 6

Expert Comment

by:wwakefield
ID: 34177115
Have you tried safe mode with Command Prompt?

BCWIPE demo will allow you to right click and delete then it will do it at boot.
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 34178704
Right click the File>Properties>Security>Advanced Button>Uncheck "Inherit Permissions>Select "Copy" in the pop up box, >Clock OK, and in the users section at the top, remove all but your logged in user and SYSTEM. Set "Deny, Full Control" rights on the file.

Reboot, and then go back into the file properties, and grant yourself Full control, then delete the file......

Basically this method prevents any hidden startup objects from getting a handle lock on teh file you are trying to delete....

0
Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

 
LVL 2

Accepted Solution

by:
ccampbell15 earned 250 total points
ID: 34180089
download gmer from gmer.net.  Expand the tabs at the top and go to files. You should be able to delete this file with Gmer.
0
 
LVL 4

Expert Comment

by:kuzmanovicb
ID: 34181235
use add remove programs
0
 
LVL 9

Assisted Solution

by:bz43
bz43 earned 250 total points
ID: 34184452
Visit http://technet.microsoft.com/en-us/sysinternals/bb897556.aspx and download "PendMoves v1.1 and MoveFile v1.0".

To delete the file run the this command and then reboot.  The "" makes it delete the file at boot:
Movefile C:\Documents and Settings\dsaade\Application Data\Sun\Java\Deployment\cache\6.0\62\7c1e60be-2c033b73.idx ""
0
 
LVL 23

Expert Comment

by:phototropic
ID: 34186274
I would open the Java console (double-click the icon in control panel) and then go to General tab - Temp.int.files - Settings .  Uncheck "Keep temporary files on my computer" and then OK your way out.  Then go back into the console to the same location, and this time click on the "Delete files" button. Check "Trace and log files" and then OK your way out again.

Now try CCleaner again...
0
 

Author Comment

by:havette
ID: 34192635
Well no luck for the moment:
PendMoves -> freezes
Gmer -> freezes
Permission changes, the moment I uncheck "Inherit Permissions" -> freezes
cmd prompt I did try delete (not in safe mode though) -> freezes
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 34193711
May need to pull the drive out, and slave it to another machine to delete the files.....
0
 
LVL 2

Expert Comment

by:ccampbell15
ID: 34193791
Gmer freezes in safe mode?

Have your tried using the misc section of HJT. You can del a file at reboot with that
0
 
LVL 6

Expert Comment

by:wwakefield
ID: 34198126
@ccampbell15Date Good tip...    I did not realize it did that and use the think all the time.
0

Featured Post

Courses: Start Training Online With Pros, Today

Brush up on the basics or master the advanced techniques required to earn essential industry certifications, with Courses. Enroll in a course and start learning today. Training topics range from Android App Dev to the Xen Virtualization Platform.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

OVERVIEW This guide provides information on the process performed when the Symantec Endpoint Protection (SEP) client checks in with the Symantec Endpoint Protection Manager (SEPM). AUDIENCE Information Technology personnel responsible for suppo…
PREFACE The purpose of this guide is to provide information to successfully install the MS SQL client tools for the Symantec Endpoint Protection Manager (SEPM) to function properly when installed on Windows 2008. AUDIENCE Information Technology…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question