Forum     

Go Back   Digit Technology Discussion Forum > Software > Software Q&A
Register FAQ Calendar Mark Forums Read

Software Q&A Having trouble with software? Find solutions here


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 01-01-2008, 12:50 PM   #1 (permalink)
Alpha Geek
 
Ganeshkumar's Avatar
 
Join Date: Dec 2006
Location: 13.04 N, 80.17 E (Chennai)
Posts: 838
Default HELP: I could not c folders in my pendrive?


Hi

After scanning with AVG and removing viruses...
*Trojan Horse Generic_c.DIQ
*Worm/VB.UG
*Worm/Autoit.HL

Now i copuld not find the folders in it.... But i can acces the folder by giving it in address bar!!


Also i saw SMSS.exe running in my task manager.. is that a virus?? i heard like that!!

Thanks..
W8ing for replies!!

I observed... Hidden attribute of the folder is checked and also disabled!
__________________
:)

Last edited by Ganeshkumar; 01-01-2008 at 12:50 PM. Reason: Automerged Doublepost
Ganeshkumar is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 01-01-2008, 01:43 PM   #2 (permalink)
Wise Old Owl
 
hullap's Avatar
 
Join Date: Dec 2006
Location: delhi
Posts: 1,429
Default Re: HELP: I could not c folders in my pendrive?

post ur hijackthis log
hullap is offline  
Old 01-01-2008, 02:52 PM   #3 (permalink)
Kcots Hserf
 
trublu's Avatar
 
Join Date: Dec 2007
Posts: 170
Default Re: HELP: I could not c folders in my pendrive?

smss.exe is not a virus.It is the windows NT session manager.
trublu is offline  
Old 01-01-2008, 04:24 PM   #4 (permalink)
Alpha Geek
 
Ganeshkumar's Avatar
 
Join Date: Dec 2006
Location: 13.04 N, 80.17 E (Chennai)
Posts: 838
Default Re: HELP: I could not c folders in my pendrive?

Oh!! Thanks...
U frnds.. think my pc too would be affected by virus?? I thought only pendrive would be affected!!

Anyway... here is my hijackthis.txt




Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 4:18:52 PM, on 1/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Documents and Settings\Metro-PA\Desktop\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [EPSON Stylus CX1500 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3V 1.EXE /P26 "EPSON Stylus CX1500 Series" /O6 "USB001" /M "Stylus CX1500"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

--
End of file - 6450 bytes
__________________
:)
Ganeshkumar is offline  
Old 01-01-2008, 05:10 PM   #5 (permalink)
Deadman Walking
 
Batistabomb's Avatar
 
Join Date: Feb 2007
Location: Visakhapatnam
Posts: 879
Default Re: HELP: I could not c folders in my pendrive?

Your computer is infected by some worms like avop,auto run e.t.c; this is because of your pen drive,Perform this :

1. First do bootscan for your pc thoroughly using Avast, delete those which you observed

after do these :

2. Start ->Run->regedit->hkey_local_machine->software->microsoft->windows0\>current version->explorer->advanced->folder->hidden->showall,
here on the right side you will observe a key naming CheckedValue,here if you find it's value as 0, then rename it as 1, if such a key not exist create one

3. hkey_current_user->software->microsoft->windows>current version->explorer->advanced, on the right side you will see a key hidden,rename to 1 again, if not create one
__________________
What looks to be nothing,finally that becomes everything...
and what is everything suddenly that changes to nothing...
Learn to live... &
Live to learn...
Batistabomb is offline  
Old 01-01-2008, 05:55 PM   #6 (permalink)
Alpha Geek
 
Ganeshkumar's Avatar
 
Join Date: Dec 2006
Location: 13.04 N, 80.17 E (Chennai)
Posts: 838
Default Re: HELP: I could not c folders in my pendrive?



Thankssss....

Will try it!
just a week b4 i had it formmatted!

let me try the booot scan!!
__________________
:)
Ganeshkumar is offline  
Old 01-01-2008, 06:35 PM   #7 (permalink)
vaibhavtek
Guest
 
Posts: n/a
Default Re: HELP: I could not c folders in my pendrive?

boot scan is a good way
 
Old 01-01-2008, 06:42 PM   #8 (permalink)
Alpha Geek
 
Ganeshkumar's Avatar
 
Join Date: Dec 2006
Location: 13.04 N, 80.17 E (Chennai)
Posts: 838
Default Re: HELP: I could not c folders in my pendrive?

Quote:
Originally Posted by Batistabomb View Post
Your computer is infected by some worms like avop,auto run e.t.c; this is because of your pen drive,Perform this :

1. First do bootscan for your pc thoroughly using Avast, delete those which you observed

after do these :

2. Start ->Run->regedit->hkey_local_machine->software->microsoft->windows0\>current version->explorer->advanced->folder->hidden->showall,
here on the right side you will observe a key naming CheckedValue,here if you find it's value as 0, then rename it as 1, if such a key not exist create one

3. hkey_current_user->software->microsoft->windows>current version->explorer->advanced, on the right side you will see a key hidden,rename to 1 again, if not create one
I tried... wat u said!!
In registry... those values r already 1....

And in the mean time i discovered that...
Wen i allow system to show protected hidden operating system files...
I can c those folders!!


So now tell me wat shld i do next!
__________________
:)
Ganeshkumar is offline  
Old 01-01-2008, 08:06 PM   #9 (permalink)
Right Off the Assembly Line
 
crazydevil's Avatar
 
Join Date: Nov 2006
Location: india
Posts: 46
Default Re: HELP: I could not c folders in my pendrive?

try enabling hidden system files visible
crazydevil is offline  
Old 01-01-2008, 08:15 PM   #10 (permalink)
Alpha Geek
 
Ganeshkumar's Avatar
 
Join Date: Dec 2006
Location: 13.04 N, 80.17 E (Chennai)
Posts: 838
Default Re: HELP: I could not c folders in my pendrive?

But it makes all Protected system files too visible....

I want to cure those folders...
__________________
:)
Ganeshkumar is offline  
Old 02-01-2008, 07:13 PM   #11 (permalink)
Alpha Geek
 
Ganeshkumar's Avatar
 
Join Date: Dec 2006
Location: 13.04 N, 80.17 E (Chennai)
Posts: 838
Default Re: HELP: I could not c folders in my pendrive?

Help me!!


I am waiting for replies to pour
__________________
:)
Ganeshkumar is offline  
Old 02-01-2008, 07:59 PM   #12 (permalink)
Deadman Walking
 
Batistabomb's Avatar
 
Join Date: Feb 2007
Location: Visakhapatnam
Posts: 879
Default Re: HELP: I could not c folders in my pendrive?

try making the third step above , value to 0
__________________
What looks to be nothing,finally that becomes everything...
and what is everything suddenly that changes to nothing...
Learn to live... &
Live to learn...
Batistabomb is offline  
Old 02-01-2008, 08:29 PM   #13 (permalink)
Fresh Stock Since 2005
 
Join Date: Feb 2005
Posts: 1,015
Default Re: HELP: I could not c folders in my pendrive?

save this as reg and merge it to registry:
Code:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden]
"ValueName"="ShowSuperHidden"
"CheckedValue"=dword:00000000
"UncheckedValue"=dword:00000001
"DefaultValue"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN]
"CheckedValue"=dword:00000002
"ValueName"="Hidden"
"DefaultValue"=dword:00000002

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"ValueName"="Hidden"
"DefaultValue"=dword:00000002
"CheckedValue"=dword:00000001
__________________
http://www.khattam.info
khattam_ is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
which is the best pendrive? max_demon Hardware Q&A 44 06-12-2009 07:30 PM
Pendrive raj.singla Hardware Q&A 15 18-12-2007 09:27 PM
Transcend pendrive topcat Hardware Q&A 5 02-10-2006 03:22 PM
using a pendrive on win98 mvishnu Software Q&A 2 15-03-2006 08:53 PM
Price of 512 MB pendrive royal QnA (read only) 6 07-03-2006 02:26 PM

 
Latest Threads
- by chris
- by icebags
- by Tenida
- by Who

Advertisement




All times are GMT +5.5. The time now is 12:26 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2