Suspect File

G

Guest

Hi I downloaded a file from download.com the other day, as it was
completing avast! says its infected and i chose to delete the virus.
the file (called setup.exe) still remained in my download directory, i
couldnt delete because it said it its in use, well i have rebooted,
rebooted in safe mode and still can;t delete it, its not a startup
item, its not referenced anywhere in the regsitry, i have run a boot
time virus scan, full spyware scan with spysweeper, still same message
when i try and delete it, its reporting its size now as 0kb, can't
think of what else to do. i am running a firewall and have carefully
watched outgoing and incoming connections and can't see anything unsual
there so i think its possibly just a file system error..

I have also tried to remove it from dos, however when i choose dos from
the boot menu it just loads xp and gives me a dos prompt (not exactly
the same thing) and because its on a drive partition i can't access it
(can only get c:)

is there a way to get into full dos before xp loads??

Flamer.
 
M

Malke

flamer said:
Hi I downloaded a file from download.com the other day, as it was
completing avast! says its infected and i chose to delete the virus.
the file (called setup.exe) still remained in my download directory, i
couldnt delete because it said it its in use, well i have rebooted,
rebooted in safe mode and still can;t delete it, its not a startup
item, its not referenced anywhere in the regsitry, i have run a boot
time virus scan, full spyware scan with spysweeper, still same message
when i try and delete it, its reporting its size now as 0kb, can't
think of what else to do. i am running a firewall and have carefully
watched outgoing and incoming connections and can't see anything unsual
there so i think its possibly just a file system error..

I have also tried to remove it from dos, however when i choose dos from
the boot menu it just loads xp and gives me a dos prompt (not exactly
the same thing) and because its on a drive partition i can't access it
(can only get c:)

is there a way to get into full dos before xp loads??

First of all, if you are talking about Safe Mode Command Prompt, you can
easily navigate to a different partition or drive. Just type the drive
letter and enter.

Or see - Undeletable Files:
http://aumha.org/a/stubborn.php
http://www.petri.co.il/delete_undeletable_files.htm
http://www.dougknox.com/xp/tips/xp_undeletable_file.htm - Pocket KillBox
http://www.bleepingcomputer.com/files/killbox.php

Malke
 
P

Pegasus \(MVP\)

Hi I downloaded a file from download.com the other day, as it was
completing avast! says its infected and i chose to delete the virus.
the file (called setup.exe) still remained in my download directory, i
couldnt delete because it said it its in use, well i have rebooted,
rebooted in safe mode and still can;t delete it, its not a startup
item, its not referenced anywhere in the regsitry, i have run a boot
time virus scan, full spyware scan with spysweeper, still same message
when i try and delete it, its reporting its size now as 0kb, can't
think of what else to do. i am running a firewall and have carefully
watched outgoing and incoming connections and can't see anything unsual
there so i think its possibly just a file system error..

I have also tried to remove it from dos, however when i choose dos from
the boot menu it just loads xp and gives me a dos prompt (not exactly
the same thing) and because its on a drive partition i can't access it
(can only get c:)

is there a way to get into full dos before xp loads??

Flamer.

Boot the machine with your WinXP CD and select Repair
and Recovery Console. You can now delete the file. And
by the way: Your posts become a lot more readable when
you start your sentences with capital letters instead of just
stringing many sentences along over a whole paragraph. You
would want to make it easy for respondents to read about
your problem, wouldn't you?
 
G

Guest

Malke said:
First of all, if you are talking about Safe Mode Command Prompt, you can
easily navigate to a different partition or drive. Just type the drive
letter and enter.

Or see - Undeletable Files:
http://aumha.org/a/stubborn.php
http://www.petri.co.il/delete_undeletable_files.htm
http://www.dougknox.com/xp/tips/xp_undeletable_file.htm - Pocket KillBox
http://www.bleepingcomputer.com/files/killbox.php

Malke
--
MS-MVP Windows Shell/User
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic"

Thanks for the reply. actually when i enter command prompt and type in
h: enter, it shows 'h' on the next line then goes back to c:\> which is
weird i know.. (i am actually a linux guy who normally works in the cui
so i am familair with the commands ect) i guess i will just try and
download the killbot app when i get home and give that a try, but just
for next time, is there actually a way to get into the full 16bit dos
like with win95 where you could hit restart in msdos mode etc..could be
useful, i dont have a floppy drive in the pc so cant make a boot disk.

Flamer.
 
H

HeyBub

Pegasus said:
Boot the machine with your WinXP CD and select Repair
and Recovery Console. You can now delete the file. And
by the way: Your posts become a lot more readable when
you start your sentences with capital letters instead of just
stringing many sentences along over a whole paragraph. You
would want to make it easy for respondents to read about
your problem, wouldn't you?

Gently. He's a Linux user. Upper/Lower Case is not important.
 
M

Malke

HeyBub said:
Gently. He's a Linux user. Upper/Lower Case is not important.

Other way around, Hey Bub. Case *does* matter to us. This is the reason so
much of *nix is done in lower case - speed and to eliminate the case issue.
However, the OP was just being sloppy here.

Malke
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top