Show Hidden Files Disabled

Discussion in 'Anti-Virus' started by madunix, Apr 5, 2008.

  1. madunix

    madunix Guest

    Since last week am facing a problem, the show hidden files been
    disabled on my PC, i tried many times to enable it through the
    regedit
    \Hidden\SHOWALL checkedvalue always 0,
    can you help me in this issue i believe i have virus on the PC.

    and found some starnge files on the PC such as qwc.exe and
    autorun.inf



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:41:49 PM, on 05/04/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe
    C:\Program Files\Symantec AntiVirus\SavRoam.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\PROGRA~1\SYMANT~1\VPTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
    C:\ORANT\BIN\ifrun60.EXE
    C:\ORANT\BIN\RWRBE60.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
    http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL
    = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
    http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
    Settings,ProxyServer = 10.5.1.31:3128
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-
    B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX
    \AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:
    \Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core
    \smax4pnp.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Explorer] C:\WINDOWS\system32\Sys\Explorer.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java
    \jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [ISUSPM Startup] C:
    \PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files
    \InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
    Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /
    background
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
    "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
    (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
    (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
    (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
    (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files
    \Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip
    \WZQKPICK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel -
    res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
    - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-
    AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
    C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583}
    - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-
    d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic
    \xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}
    - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-
    BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report
    Viewer Control) - O17 - HKLM\System\CCS\Services\Tcpip\..
    \{179DAE92-31C9-4018-A480-07DEB96FF6AB}: NameServer = 10.5.1.111
    O17 - HKLM\System\CS1\Services\Tcpip\..\{179DAE92-31C9-4018-
    A480-07DEB96FF6AB}: NameServer = 10.5.1.111
    O17 - HKLM\System\CS2\Services\Tcpip\..\{179DAE92-31C9-4018-
    A480-07DEB96FF6AB}: NameServer = 10.5.1.111
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec
    Corporation - C:\Program Files\Common Files\Symantec Shared
    \ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec
    Corporation - C:\Program Files\Common Files\Symantec Shared
    \ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec
    Corporation - C:\Program Files\Common Files\Symantec Shared
    \ccSetMgr.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) -
    Symantec Corporation - C:\Program Files\Symantec AntiVirus
    \DefWatch.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision
    Corporation - C:\Program Files\Common Files\InstallShield\Driver
    \11\Intel 32\IDriverT.exe
    O23 - Service: NetOp Helper ver. 9.00 (2006348) (NetOp Host for NT
    Service) - Danware Data A/S - C:\Program Files\Danware Data\NetOp
    Remote Control\Host\NHOSTSVC.EXE
    O23 - Service: Oracle%ORACLE_HOME_SERVICE%ClientCache80 - Unknown
    owner - C:\ORANT\BIN\ONRSD80.EXE
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool
    \DRIVERS\W32X86\3\HPZipm12.exe
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files
    \Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
    Corporation - C:\Program Files\Common Files\Symantec Shared
    \SNDSrvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program
    Files\Symantec AntiVirus\Rtvscan.exe
     
    madunix, Apr 5, 2008
    #1
    1. Advertisements

  2. From: "madunix" <>

    | Since last week am facing a problem, the show hidden files been
    | disabled on my PC, i tried many times to enable it through the
    | regedit
    | \Hidden\SHOWALL checkedvalue always 0,
    | can you help me in this issue i believe i have virus on the PC.
    |
    | and found some starnge files on the PC such as qwc.exe and
    | autorun.inf
    |

    Please do NOT post HJY logs in this or other Usenet news groups.

    If you had bothered to ask first you would have been told this.



    1. Download and execute HiJack This! (HJT)
    http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe

    2. Disable Notepad's word wrap:
    In Notepad.exe; Format --> uncheck; "Word wrap"

    3. Download/run Deckard's System Scanner:
    http://www.techsupportforum.com/sectools/Deckard/dss.exe

    4. Save the scan results (Main.txt and Extra.txt)

    5. And then post the contents of Main.txt and Extra.txt in your post in one of the below
    expert forums...


    { Please - Do NOT post the HJT and Deckard's System Scanner Logs here ! }

    Forums where you can get expert advice for HiJack This! (HJT) and Deckard's System Scanner
    Logs.

    NOTE: Registration is REQUIRED in any of the below before posting a log

    Suggested primary:
    http://www.thespykiller.co.uk/index.php?board=3.0

    Suggested secondary:
    http://www.bleepingcomputer.com/forums/forum22.html
    http://castlecops.com/forum67.html
    http://www.malwarebytes.org/forums/index.php?showforum=7

    Suggested tertiary:
    http://www.dslreports.com/forum/cleanup
    http://www.cybertechhelp.com/forums/forumdisplay.php?f=25
    http://www.atribune.org/forums/index.php?showforum=9
    http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html
    http://gladiator-antivirus.com/forum/index.php?showforum=170
    http://forum.networktechs.com/forumdisplay.php?f=130
    http://forums.maddoktor2.com/index.php?showforum=17
    http://www.spywarewarrior.com/viewforum.php?f=5
    http://forums.spywareinfo.com/index.php?showforum=18
    http://forums.techguy.org/f54-s.html
    http://forums.tomcoyote.org/index.php?showforum=27
    http://forums.subratam.org/index.php?showforum=7
    http://www.5starsupport.com/ipboard/index.php?showforum=18
    http://aumha.net/viewforum.php?f=30
    http://makephpbb.com/phpbb/viewforum.php?f=2
    http://forums.techguy.org/54-security/
    http://forums.security-central.us/forumdisplay.php?f=13
     
    David H. Lipman, Apr 5, 2008
    #2
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.