cannot delete folders in c:\

G

Guest

I have around 15 directories, directly under c:\, each 55 MB. Contents seems
related to SQL Server installation, but I suspect they are just subproducts
of previous malware infections

I cannot delete them, even using pendmoves and movefiles, they don't appear
in any Process Explorer handle view, as far as I know.

According to KB927977 those files can be safely deleted. But, how?

Might I get some advice on that please?
 
P

Pegasus \(MVP\)

Santiago Torras said:
I have around 15 directories, directly under c:\, each 55 MB. Contents
seems
related to SQL Server installation, but I suspect they are just
subproducts
of previous malware infections

I cannot delete them, even using pendmoves and movefiles, they don't
appear
in any Process Explorer handle view, as far as I know.

According to KB927977 those files can be safely deleted. But, how?

Might I get some advice on that please?

- Can you give some directory names?
- Since you've used movefile.exe, I suppose you've tried
deleting the directories while in Safe Mode but I thought
I should ask regardless.
- Have you tried deleting them after booting the machine
with a Bart PE boot CD?
 
G

Guest

thanks
here you are some names

2af9cfa05dd57230b0a8d5
3e4c009e226a3f8c25e750dcbf6be2
42035c482f55d6f117ae8c
43e5f174e05b5997f69e9845
471ef58536c5b508daef469aa1835524
4c918e0dbd0f7d46ecc52af6be
6b76c706ae7634843b98c7f5
766239a75f94a9b6a7155848c24d38
7e5a0984b488299a7655dd687f5de5
7f7256ce18a6dedb524d212487e4fe16
8312ad7bc0a4ed7611fb5b07
8e356b555bee827a40528f5a80b06b
8f7cac11ac3a6ac22eb03546b3cb0ae7

they are folders, inside seem to be windows update, many of them related to
sQLSERVER 2005, ..
I suppose all of them can and should be deleted.


I don't know what a Bart PE boot CD is..
I haven't tried to delete them in safe mode . I will try
 
P

Pegasus \(MVP\)

Santiago Torras said:
thanks
here you are some names

2af9cfa05dd57230b0a8d5
3e4c009e226a3f8c25e750dcbf6be2
42035c482f55d6f117ae8c
43e5f174e05b5997f69e9845
471ef58536c5b508daef469aa1835524
4c918e0dbd0f7d46ecc52af6be
6b76c706ae7634843b98c7f5
766239a75f94a9b6a7155848c24d38
7e5a0984b488299a7655dd687f5de5
7f7256ce18a6dedb524d212487e4fe16
8312ad7bc0a4ed7611fb5b07
8e356b555bee827a40528f5a80b06b
8f7cac11ac3a6ac22eb03546b3cb0ae7

they are folders, inside seem to be windows update, many of them related
to
sQLSERVER 2005, ..
I suppose all of them can and should be deleted.


I don't know what a Bart PE boot CD is..
I haven't tried to delete them in safe mode . I will try

A Bart CD is a boot CD that allows you to boot into
a Windows XP look-alike environment. You can
download the tools to make one from www.bootdisk.com.
It is a very powerful tool for sysadmins but unfortunately
it takes a few hours to make one.
 
G

Guest

thanks
in safe mode I cannot delete neither the contents of the directories or the
directories themselves. Access denied is the message
So, looks like I will have to deal with the Bart CD
Anyway, it is quite strange that these directories are so "well-protected"
that even Pendmoves is not successful in getting rid of them
 
J

Jim Byrd

Hi Santiago - From my Blog, Defending Your Machine, addy below in my
Signature:


Sometimes the tools below will find files which they are unable to delete
because they are in use.

- A program called Locked Files Wizard (LFW), formerly CopyLock, here,
http://noeld.com/programs.asp?cat=misc
"is a simple assistant that allows you to either replace, move, delete or
rename one or more files or folders which are in use by the system or any
running process. Additionally, you can display and possibly stop the
processes or services that lock a file, and manage files flagged to be
processed by the system on next reboot (e.g. after an installation or an
uninstallation.) The Locked Files Wizard can also help to select some worms
and trojans from the Registry and to quickly remove them from the system."
Copylock2 (now Locked Files Wizard) does request a $12 registration fee in
order to activate some additional _new functions_ in the new version and/or
for installation on multiple computers or commercial usage. However, that
version is available for download at the link on that page without
registration and with full utility of the original capabilities of Copylock
after installation without registration. If you prefer, you can
alternatively download the older v. 1.09 version which involves no
registration at all (but, of course doesn't include the possibility of
upgrade to the paid version) here:
http://copylock.noel-danjou.qarchive.org/_download2.html

- Another is Killbox by Option Explicit, Beta version available here:
http://www.killbox.net/downloads/beta/KillBox.exe
Overview directions are available here:
http://www.killbox.net/help.html#Top
Read carefully - this tool is quite powerful. A Beta version is also
available.

- A third which is a bit different but often very useful is Delete Invalid
File, here:
http://www.purgeie.com/delinv.htm
which handles invalid/UNC file/folder name deleting, rather than the in use
problem. The situation with Delete Invalid Files is similar to that with
Copylock. The latest version adds additional capabilities which are aimed at
the commercial marketplace (but would be useful to an individual user also.)
However, all of the _original file removal functions_ are still freely
available in the download version without registration or payment.

From http://www.purgeie.com/delinv/index.htm:

"As the "Free" version of DelinvFile had become so popular and has been
referenced on many download sites, web forums and newsgroups as being
"Free", the current version does not require a fee to access the original
program functions. The commercial version of DelinvFile makes available
additional functions which require licensing (registration) for them to
work. The additional functions include "Open With..", Renaming Files,
Renaming Folders, and Deleting Files and Folders at Boot."

- A fourth useful program is Unlocker, here:
http://ccollomb.free.fr/unlocker/
" Simply right click the folder or file and select Unlocker. If the folder
or file is locked, a window listing of lockers will appear. Simply select
the lockers and click Unlock and you are done!" Works as advertised and is
particularly helpful in identifying malware components which are
'protecting' each other.

- A fifth is FileASSASSIN, here:
http://www.malwarebytes.org/fileassassin.php
"FileASSASSIN can delete locked malware files on your system. It uses
advanced techniques to unload modules, close remote handles, and terminate
processes to allow the removal of the file."



--
Regards, Jim Byrd,
My Blog, Defending Your Machine,
http://defendingyourmachine2.blogspot.com/



In Santiago Torras <[email protected]> typed:
|| I have around 15 directories, directly under c:\, each 55 MB.
|| Contents seems related to SQL Server installation, but I suspect
|| they are just subproducts of previous malware infections
||
|| I cannot delete them, even using pendmoves and movefiles, they don't
|| appear in any Process Explorer handle view, as far as I know.
||
|| According to KB927977 those files can be safely deleted. But, how?
||
|| Might I get some advice on that please?
||
||
|| --
|| thanks
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top