moon Posted December 11, 2003 Report Share Posted December 11, 2003 I downloaded an app. to hide sensitive folders, ran it, hid a folder and the damn app. wont run again. Tried everything. I'll just have to write the folder off ( backup somewhere ) Anyway, I've deleted all references to the app. except I'm stuck with one .dll in the Windows folder which I can't delete or rename . Message is ' Cannot delete or rename. This file is in use by Windows' How do I get rid of the bugger, and if I do, will I be able to see my folder again ? Quote Link to comment Share on other sites More sharing options...
mark2 Posted December 11, 2003 Report Share Posted December 11, 2003 moon ,if you boot into safe mode, you should then be able to delete/rename it. Quote Link to comment Share on other sites More sharing options...
moon Posted December 11, 2003 Author Report Share Posted December 11, 2003 Tried that , Mark, same message. Quote Link to comment Share on other sites More sharing options...
Guest Grim Reaper Posted December 11, 2003 Report Share Posted December 11, 2003 its not a shared dll file is it moon??? Quote Link to comment Share on other sites More sharing options...
-pops- Posted December 11, 2003 Report Share Posted December 11, 2003 Tell us what the rubbish freeware is - so we can avoid it! Quote Link to comment Share on other sites More sharing options...
moon Posted December 11, 2003 Author Report Share Posted December 11, 2003 How would I tell, Grim ? There's nothing in its 'properties' other than read-only/archive/hidden. I've unchecked all those but the 'system' box is locked. It's Akas, -pops-. I should have smelled a rat by the name. :D After you've hidden a file the only window that will open is the 'Buy the Pro version' one. I guess they rely on mugs to go for that in order to make their folders visible again. Neat but nasty.EDIT : Grim, the entire disk has 'sharing' enabled. Quote Link to comment Share on other sites More sharing options...
mark2 Posted December 11, 2003 Report Share Posted December 11, 2003 What's the name of the .dll Quote Link to comment Share on other sites More sharing options...
moon Posted December 11, 2003 Author Report Share Posted December 11, 2003 AkasHook.dllI'm lost when it comes to commands, Mark.EDIT; This is the 98SE machine. Makes sense to test stuff on here. Quote Link to comment Share on other sites More sharing options...
mark2 Posted December 11, 2003 Report Share Posted December 11, 2003 find the full address of the file ie:- C:\Windows\blah\blahreboot into msdos mode and delete from therea google search finds no references to it. Quote Link to comment Share on other sites More sharing options...
Hurdy Posted December 11, 2003 Report Share Posted December 11, 2003 It was me talking about dos commands moon but I deleted my post 'cos there are more knowledgeable people than me to try and help ;) Quote Link to comment Share on other sites More sharing options...
mark2 Posted December 11, 2003 Report Share Posted December 11, 2003 Hurdy there are more knowledgeable people than me makes 2 of us :P never did much in dos myself, maybe best to wait for someone smarter with it :scared: Quote Link to comment Share on other sites More sharing options...
Hurdy Posted December 11, 2003 Report Share Posted December 11, 2003 I'm happy to have a go on my own PC 'cos if I bugger it up then it's my fault :P I'm scared if I mess other peoples up. Quote Link to comment Share on other sites More sharing options...
mark2 Posted December 11, 2003 Report Share Posted December 11, 2003 moon may be worth doing a Hijackthis log, see if Akas shows up in processes.Download Hijack this, unzip it to it's own folder then run it, save the log and copy/paste the resultshijackthis.zip Quote Link to comment Share on other sites More sharing options...
Boris Posted December 11, 2003 Report Share Posted December 11, 2003 moonYour invisible folders is always hidden, including Safe mode, MS-DOS and even when Hide Folder is not running.Don't think DOS is the answer :( .I presume it didn't uninstall properly ?Have you tried re-installing it to see if it'll run once again ?Have you had a look in the help file ? http://www.apihook.com/hidefolder/AKASShp.chmHave you tried emailing them ? - [email protected] Quote Link to comment Share on other sites More sharing options...
Boris Posted December 11, 2003 Report Share Posted December 11, 2003 From a DOS C:\ prompt you could try this ?(if your windows directory is C:\WINDOWSDEL C:\WINDOWS\AkasHook.dll enter - and see what it does ?Then DIR Akas*.* enter- to see if anything else is there ? Quote Link to comment Share on other sites More sharing options...
moon Posted December 12, 2003 Author Report Share Posted December 12, 2003 Thanks chaps.Your penultimate post first, boris, it ran, hid my folder and then vanished. Only the 'buy me' window reappears. As there is no programme to access there are no tools available and the 'help' link is therefore useless. It won't reinstall. Message is ' Uninstall previous versions first' I emailed them beore posting here. No reply. The AkasHook.dll must be one with the info. which keeps my folder hidden and it must be booting because I can't delete it after a reboot ( nor in safemode) C-A-D does not show it as a running app. but it must be a running process. I'll try getting at it with DOS ( bugger) a bit later if anyone is around. Quote Link to comment Share on other sites More sharing options...
moon Posted December 12, 2003 Author Report Share Posted December 12, 2003 Here ya go chaps. Anyone make sense of this lot for me ? Logfile of HijackThis v1.97.2Scan saved at 18:46:49, on 12/12/03Platform: Windows 98 SE (Win9x 4.10.2222A)MSIE: Internet Explorer v6.00 (6.00.2600.0000)Running processes:C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\MPREXE.EXEC:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXEC:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\OUTPOST.EXEC:\WINDOWS\SYSTEM\mmtask.tskC:\WINDOWS\EXPLORER.EXEC:\WINDOWS\SYSTEM\SYSTRAY.EXEC:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXEC:\WINDOWS\STARTUPMONITOR.EXEC:\WINDOWS\SYSTEM\WMIEXE.EXEC:\WINDOWS\SYSTEM\SPOOL32.EXEC:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXEC:\WINDOWS\NOTEPAD.EXEC:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXER0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pcpitstop.ibforums.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCXO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1.1\SDHELPER.DLLO2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [scanRegistry] C:\WINDOWS\scanregw.exe /autorunO4 - HKLM\..\Run: [systemTray] SysTray.ExeO4 - HKLM\..\Run: [AVG_CC] C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startupO4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exeO4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrSchemeO4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\OUTPOST.EXE /waitserviceO4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exeO4 - HKLM\..\RunServices: [Outpost Firewall] C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\OUTPOST.EXE /serviceO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htmO8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htmO8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.htmlO8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.htmlO8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.htmlO8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.htmlO8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.htmlO8 - Extra context menu item: Download using Download &Express - file://C:\Program Files\Download Express\Add_Url.htmO9 - Extra button: Related (HKLM)O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)O9 - Extra button: Trashcan (HKCU)O9 - Extra 'Tools' menuitem: Show Trashcan (HKCU)O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dllO12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dllO12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dllO16 - DPF: Win32 Classes - O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CABO16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://E:\SuperCD\IntraLaunch.CABO16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cabO16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cabO17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = CensoredO17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = Censored Quote Link to comment Share on other sites More sharing options...
mark2 Posted December 12, 2003 Report Share Posted December 12, 2003 Can't see anything in there regarding AkasHook.dll, moon, unless it is linked toO3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)as you have Download express, and, if you no longer use DAP you might like to get rid ofO8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htmO8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htmthese restrictionsO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentI assume you have set using Spybot S & D if not have HJT fix themClose all browser and explorer windows then hit the 'fix checked' button Quote Link to comment Share on other sites More sharing options...
moon Posted December 12, 2003 Author Report Share Posted December 12, 2003 Yes, Mark, I've set the Ie restrictions with Spybot. Very astute :D I'll get rid of 03 and the two 08's and see what transpires. I can always reload DAP if I want to. Back in a bit. Ta. Quote Link to comment Share on other sites More sharing options...
Boris Posted December 12, 2003 Report Share Posted December 12, 2003 I'll try getting at it with DOS ( bugger) a bit later if anyone is around.Any joy with DOS ? Quote Link to comment Share on other sites More sharing options...
moon Posted December 12, 2003 Author Report Share Posted December 12, 2003 No ill effects but still can't shift AkasHook.dll. It's dug in like a Missouri tick. ( Did you see Predator ? Classic :D )Any suggestions ? Quote Link to comment Share on other sites More sharing options...
mark2 Posted December 12, 2003 Report Share Posted December 12, 2003 Perhaps it's time to look in the registry for any references to the software and edit them out ? Back up the registry first tho !! Quote Link to comment Share on other sites More sharing options...
moon Posted December 12, 2003 Author Report Share Posted December 12, 2003 I've looked with JV16 and found nothing. I've seen 'Reg Supreme' praised elsewhere though so I think I'll try the shareware. One guy told me that it turned up over 800 entries that JV16 hadn't found. Quote Link to comment Share on other sites More sharing options...
moon Posted December 13, 2003 Author Report Share Posted December 13, 2003 Tried Reg Supreme. It found 108 invalid entries that JV16 missed so I bought it. Cheap.http://www.macecraft.com/I'm still locked out of my folder though and AkasHook.dll is still unremoveable. Quote Link to comment Share on other sites More sharing options...
Hurdy Posted December 13, 2003 Report Share Posted December 13, 2003 Hi moonI know I'm banging on an old drum but in DOS there is the attrib command.attribattrib filename -rQuote'-R - Use the -R option to change the file protection attribute back to normal (so it can be read, changed, or deleted).'Hope it helps. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.