Jump to content

Malwarebytes

Immortal file with no name


15 replies to this topic

#1
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,971 posts
  • Gender:Male
I used Universal Extractor (great tool :) ) to extract the setup file for Secunia PSI (latest version) and it used 7-Zip Extractor to extract the setup files to a folder on my desktop. I opened the folder and much to my surprise, no executables or dll's were in the folder, just files with single character names and one with no name. None of them had file extensions. I knew something obviously went wrong so I tried to delete the files and all of them went quietly except the 10k file with no name. Curiously I can move the folder and rename the folder, but I can't rename or delete the file :) . Here's what I've tried so far (note: I'm on Vista x64 so my options are limited as far as compatible tools go):
  • Manual deletion: results in a strange error message from explorer

    Quote

    Delete Folder

    An unexpected error is preventing the operation. Make a note of this error code, which might be useful if you get additional help to resolve this problem:

    error 0x80070091: The directory is not empty.
  • del and rd commands run from an administrative command prompt have yielded similar results
  • I took ownership of the file and that did not help, the issue seems unrelated to permissions because it shows that I have full control of the file in question
  • I ran chkdsk /r on my C: drive (where the file is stored) per a few postings I found on the web from others that had similar issues, no luck for me unfortunately :)
  • I tried Avenger, no luck (I suspect its driver doesn't work in x64 anyway and it could have trouble with nameless files without file extensions)
  • I tried FileASSASSIN in MBAM, it won't even let me select the file when I browse to it
  • I tried MS D.a.R.T. 6.0 x64, it gives me the same error as when Windows is running so I suspect it's an NTFS issue, similar to what happens with null reg entries when they get locked into place
  • I tried cut/paste to put them on a different drive, it won't let me move them from C:, but I can put them anywhere in C: that I want except of course the Recycle Bin :)

If anyone has any ideas I'm open to them (and yes, I know formatting my drive would remove them, I'm not that desperate :) . I also have System Restore disabled so that's not an option either) :) .

Thanks
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#2
marktreg

    Elite Member

  • Trusted Advisors
  • PipPipPipPipPip
  • 834 posts
Hi exile,

Give these progs a go, mate.

http://lockhunter.com/

and

http://download.cnet.com/EMCO-Unlock-It/30...4-10427650.html

I don't know if they will work or not. But they are both x64 compatible, so they may be worth a try. :)

#3
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,971 posts
  • Gender:Male
Good effort :) . Unfortunately they were a no-go :) . Those are unlocking tools that look for processes that are running and preventing file deletion. I wasn't able to delete the files offline booted from MS D.a.R.T. so these failed for the same reason, it has something to do with the files being completely nameless, not a running process holding it up :) . Thanks for trying though, I do appreciate it :) .
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#4
Marcus

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 592 posts
  • Gender:Male
  • Location:London, UK

View Postexile360, on Oct 27 2009, 01:16 AM, said:

... it has something to do with the files being completely nameless, not a running process...

...uhm...if the file(s) don't have a name how do you know they are there? Or are you deducing that from the folder properties? :)

Sorry I know that sounds a really stupid thing to ask - this is why I'm not an expert! :blush:

#5
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,579 posts
  • Gender:Male
  • Location:US
Hi Exile,

Have you checked all of the ACL permissions? If it were XP the boot CD method would not care, but on Vista and Win7 they seem to honor the ACL of files and folders. I would change the owner on it and then set yourself or Administrators to FULL access and try again. Don't forget to TAKE OWNERSHIP of it.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#6
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,971 posts
  • Gender:Male
@Marcus: I can see the file, that's how I know it's there :) . It looks just like your HOSTS file (a file with no extension) except it has no name, but it's 10kb in size :) .

@AdvancedSetup: Yep, I did Take Ownership several times (I long ago implemented that reg tweak to enable it in the context menu :blush: ). I also manually edited permissions, made myself owner, gave myself full control etc. I discovered a thread about it here. One user claims that Unlocker did the trick, but it doesn't like x64 (even when executed via a 32 bit app like my internet browser) so that was a no go as well :) . According to that thread Linux worked for one user so I'm downloading Knoppix now to give it a shot :) .
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#7
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,579 posts
  • Gender:Male
  • Location:US
See if you can do this.

1. Create C:\JUNK\BadFile
2. Move the file to C:\JUNK\BadFile
3. Map a drive M: to C:\JUNK
\\YOURCOMPUTERNAME\C$\JUNK

Now try to delete the folder BadFile with that file in it. RD /Q /S M:\BadFile
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#8
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,971 posts
  • Gender:Male
Too late, already got it :) . I went back to the Unlocker page to see if there was any news on x64 support and there was, it doesn't support it :blush: . But then I looked at the chart they have comparing its features to those of other somewhat similar softwares and I looked under the column Invalid Names and thought that sounded similar to what I was dealing with (although I know they generally mean file names that are too long) so I checked to see which tools made the grade for that. There weren't many, just DelinvFile and DelFXPFiles. I looked at the DelinvFile site and found they want you to pay for it now :) . I downloaded the trial to see if it at least "thought" it could delete the files (which are now stored in C:\Windows.old under C:\Windows.old\1\file with no name and C:\Windows.old\2\file with no name because I tried to trick Disk Cleanup into deleting them per a certain MS help article describing the same file deletion error :) ). Anyway, it turns out the "trial" is fully functional and allows up to 3 file deletions so I gave it shot, selecting the Windows.old folder I created and it appears to have worked. I can't see the folder at least so I think they're gone now :) .
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#9
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,579 posts
  • Gender:Male
  • Location:US
Well then I'm pretty sure my method would have worked if it was a path issue. Do it again and see if my method will remove it :blush:
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#10
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,971 posts
  • Gender:Male
Heck no, you do it, you can easily replicate it, just use Universal Extractor to extract Secunia PSI and try to delete all the files in its folder :blush: .

I know I don't know nearly as much as you, but how could it be a path issue if I could easily move the folder and file around? Do you mean Windows didn't have a true path to the file because it had no name and no file extension?
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#11
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,579 posts
  • Gender:Male
  • Location:US
The windows redirector service for a network card often acts differently on how it manages files and folders. I don't think it is documented, just one of those odd behavior things you run into.

No problem. Please give me a direct link to the version you used and I'll see how it goes.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#12
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,971 posts
  • Gender:Male
I used Universal Extractor 1.6 (portable of cours :blush: ) and I extracted (er, tried to extract) PSISetup.exe. Have fun :) !
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#13
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,579 posts
  • Gender:Male
  • Location:US
Maybe a Vista issue or x64 issue. XP SP3 extract, no blank files. Folder and files delete just fine. I'll take a look on Win7, don't have a Vista x64
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#14
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,971 posts
  • Gender:Male
I ran Universal Extractor both as non-admin and as admin (that's why I had 2 folders and 2 blank files instead of just one) because sometimes admin privelages are required and I thought perhaps that was why extraction failed the first time. It used 7-Zip as the extraction method as I recall.
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#15
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,579 posts
  • Gender:Male
  • Location:US
Mine doesn't even ask me what to extract it with. It just extracts it. All files seem okay with legit file names. I'm betting you had some type of unexpected extraction or program error that caused it and I probably won't be able to duplicate easily.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#16
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,971 posts
  • Gender:Male
It didn't as, it just started scanning the setup file, then it did the "Deep Scan" and started extracting with 7-Zip (I had to be quick to read it).
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us