Directory that I could remove, is Virus?

Community Forums/General Help/Directory that I could remove, is Virus?

Yue(Posted 2015) [#1]
Hi, while I'm trying to delete a directory, but it is impossible, Windows gives me a message saying the file is impossible to be liminado, that is not found. Within this directory there are several files with ext JS with very strange names. x454545s45d4f54545kdklsjflkdjsflsjflsj56457845.js That's a virus ?, how can I remove it?


GfK(Posted 2015) [#2]
Get Malwarebytes and run it in Safe Mode, would be the best idea.


virtlands(Posted 2015) [#3]
Hi You,...

Here are some strategies for you to try :: a,b,c,d,e,..

(a) Install Eraser, and then through the context menu, highlight & right-click on several *.js files and choose "Erase on Restart".

Eraser link :: http://eraser.heidi.ie/



(b) Run AdwCleaner :: http://bit.ly/13spKsQ
(c) Add "Take Ownership" to Explorer Right-Click Menu :: http://bit.ly/NlHVsK
(Sometimes files can only be deleted if you "Take Ownership" of them first.)
(d) Download and run a trial version of HitMan Pro :: http://bit.ly/15QQpTE
(e), As a last resort, (if everything else fails), then run Combofix :: http://bit.ly/1n7X6H8

{Sometimes Combofix can potentially destroy your internet connection,... }

--------------------------------------------------------------------------
If you are brave enough to run ComboFix, then plan ahead, and download internet restoration software FIRST .

-- Several Tools to Restore Your Internet Connection by Repairing Winsock
--> https://www.raymond.cc/blog/repair-xp-and-vista-internet-connection-problems-with-icr/

--> Complete Internet Repair :: http://bit.ly/1ytMKBe
--> WinSock Fix :: http://bit.ly/15QXKTs
--> Windows Repair, All in One :: http://bit.ly/15QYmIH
--> TCP Optimizer :: http://bit.ly/15QZ0WA
--> Microsoft Fixit 50203 :: http://bit.ly/15QZrQP
--> Connectivity Fixer :: http://bit.ly/15QZRq9
--------------------------------------------------------------------------


virtlands(Posted 2015) [#4]
... OR, download everything in ONE big ZIP :

... Antimalware, Windows, & Internet Repair --> http://bit.ly/1H9qneP

[ all items are recent as of 01-27-2015 ]


GfK(Posted 2015) [#5]
Just as a small note of caution - if you start playing with all that software and don't know what you're doing, you'll be reinstalling Windows this time tomorrow.


RemiD(Posted 2015) [#6]
I hope that you know what a reliable backup is...


Yue(Posted 2015) [#7]
No, I can not delete the directory, the weird thing is that they have no sarchivos size on disk.

Will is a drive error c, bad sectors?


Rick Nasher(Posted 2015) [#8]
The .js is of course a JavaScript extension. Might be something generated by an application. Did you run something Linux related? Like USBkey creation software that's not 100% windows developed. It can leave files that windows can't handle. Or perhaps something copied from another source.

You can try from a command prompt:
dir /X

This will list your files/folders in short name format. Then use the short name exactly as written to delete the file:
del LONGF~1.txt


Also it might have something to do with alternate datastreams, see text below.

"Alternate data streams (ADS):
Alternate data streams allow more than one data stream to be associated with a filename, using the format "filename:streamname" (e.g., "text.txt:extrastream").

NTFS Streams were introduced in Windows NT 3.1, to enable Services for Macintosh (SFM) to store resource forks. Although current versions of Windows Server no longer include SFM, third-party Apple Filing Protocol (AFP) products (such as GroupLogic's ExtremeZ-IP) still use this feature of the file system. Very small ADS (called Zone.Identifier) are added by Internet Explorer and recently by other browsers to mark files downloaded from external sites as possibly unsafe to run; the local shell would then require user confirmation before opening them.[21] When the user indicates that they no longer want this confirmation dialog, this ADS is deleted.

Alternate streams are not listed in Windows Explorer, and their size is not included in the file's size. They are ignored when the file is copied or moved to another file system without ADS support, attached to an e-mail, or uploaded to a website. Thus, using alternate streams for critical data may cause problems. Microsoft provides a tool called Streams[22] to view streams on a selected volume. Starting with Windows PowerShell 3.0, it is possible to manage ADS natively with seven cmdlets: Add-Content, Clear-Content, Get-Content, Get-Item, Out-String, Remove-Item, Set-Content.[23]

Malware has used alternate data streams to hide code.[24] As a result, malware scanners and other special tools now check for alternate data streams."


Makis(Posted 2015) [#9]
Try HitmanPro.