1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Invisible files!?!?

Discussion in 'Virus & Other Malware Removal' started by Jru, Apr 21, 2004.

Thread Status:
Not open for further replies.
Advertisement
  1. Jru

    Jru Thread Starter

    Joined:
    Apr 21, 2004
    Messages:
    38
    Every folder on my comp that's name starts with "sound" (sound, sounds, soundbombing, etc) have turned invisible! I could only see them in Safe Mode... Even when I delete them in Safe Mode and make new folders (under the same name) they still turn up invisible... The folders aren't set to be Hidden or anything... Could somebody help?
     
  2. Jru

    Jru Thread Starter

    Joined:
    Apr 21, 2004
    Messages:
    38
    help
     
  3. thegreatone

    thegreatone

    Joined:
    Jan 10, 2003
    Messages:
    210
    Go to any folder and open it then go to Tools > Folder Options > View > Make sure there is a check in the Show Hidden Files and Folders box then Apply it to all folders
     
  4. Jru

    Jru Thread Starter

    Joined:
    Apr 21, 2004
    Messages:
    38
    doesn't work :(
     
  5. Jru

    Jru Thread Starter

    Joined:
    Apr 21, 2004
    Messages:
    38
    does anyone have a clue? :)
     
  6. thegreatone

    thegreatone

    Joined:
    Jan 10, 2003
    Messages:
    210
    What OS are you running? Are you logged on under a different user? It could be that the account you are logged in under doen't have access to these fiolders. Let me think about it some more :)
     
  7. Jru

    Jru Thread Starter

    Joined:
    Apr 21, 2004
    Messages:
    38
    I'm runnin WinXP, and there's only one user. I also made the folders available to everyone, but the folders still didn't turn up.
     
  8. thegreatone

    thegreatone

    Joined:
    Jan 10, 2003
    Messages:
    210
    Did you uncheck the two boxes below show hidden files? One is Hide extentions for known files and the other is Hide protected operating system files. Uncheck them and see if you get anything
     
  9. thegreatone

    thegreatone

    Joined:
    Jan 10, 2003
    Messages:
    210
  10. lsc71

    lsc71

    Joined:
    Aug 16, 2003
    Messages:
    5
    Hi,
    Apparently you aren't the only one suffering from this problem. I came across a post on another forum about this same thing, and the guy had finally resolved it. He'd found that the problem was actually caused by certain trojans and worms, and he got rid of it using Avast, which has a free trial. The link to the post is below, if you'd like to read it.

    http://www.train-sim.com/dcforum/DCForumID3/23059.html
     
  11. Jru

    Jru Thread Starter

    Joined:
    Apr 21, 2004
    Messages:
    38
    Thanks guys!
     
  12. Jru

    Jru Thread Starter

    Joined:
    Apr 21, 2004
    Messages:
    38
    Ok avast! revealed some trojans and worms and got rid of them... At least I think so, as the last scan turned up nothing. However the problem persists :(

    After a restart as everything's loading I could see the sound and sounds folder that I made on the desktop to experiment. Then when everything finished loading up the folders disappeared... Does this mean anything?

    edit: HijackThis also closes after a few seconds opened...
     
  13. Jru

    Jru Thread Starter

    Joined:
    Apr 21, 2004
    Messages:
    38
    here's my hijacklog...

    Logfile of HijackThis v1.97.7
    Scan saved at 8:11:26 AM, on 4/25/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\System32\SPOOLSVC.exe
    C:\WINDOWS\SMSS.exe
    C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
    C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
    C:\WINDOWS\System32\syscfg32s.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\aim\aim.exe
    C:\program files\steam\steam.exe
    C:\WINDOWS\System32\SPOOLSVC.exe
    C:\Program Files\BigFix\BigFix.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Kazaa Lite K++\KazaaLite.kpp
    C:\Program Files\Microsoft Money\System\urlmap.exe
    C:\Documents and Settings\J. Dub\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://okayplayer.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
    N2 - Netscape 6: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Documents and Settings\J. Dub\Application Data\Mozilla\Profiles\default\54zy509z.slt\prefs.js)
    O2 - BHO: (no name) - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - (no file)
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {69B84718-6243-4296-8332-19B0A78D567D} - C:\WINDOWS\System32\inetcplcc.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: (no name) - {770C4D3F-1F59-4330-BA64-446A39A32375} - (no file)
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SPOOL Configuration] SPOOLSVC.exe
    O4 - HKLM\..\Run: [Debug ] C:\WINDOWS\SMSS.exe
    O4 - HKLM\..\Run: [Windows Startup Module] C:\WINNT\system32\dllcache\RAD\start.exe
    O4 - HKLM\..\Run: [Windows System Stability Module] C:\WINNT\SYSTEM32\DLLCACHE\SEC\secure.exe
    O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
    O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
    O4 - HKLM\..\Run: [SysConfig32] syscfg32s.exe
    O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\bxxs5.dll,DllRun
    O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
    O4 - HKLM\..\RunServices: [SPOOL Configuration] SPOOLSVC.exe
    O4 - HKLM\..\RunServices: [SysConfig32] syscfg32s.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [SPOOL Configuration] SPOOLSVC.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: ICQ (HKLM)
    O9 - Extra 'Tools' menuitem: ICQ (HKLM)
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: PartyPoker.com (HKLM)
    O9 - Extra 'Tools' menuitem: PartyPoker.com (HKLM)
    O9 - Extra button: MoneySide (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
    O16 - DPF: DigiChat Applet - http://host2.digichat.com/DigiChat/DigiClasses/SignedClient.cab
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_41.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/24dc7f589873fc890402/netzip/RdxIE601.cab
    O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://download.yahoo.com/dl/installs/yab_af.cab
    O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{63607577-22B5-46D9-A860-93904B1D0542}: NameServer = 192.168.0.1,4.2.2.2
     
  14. ~Candy~

    ~Candy~ Retired Administrator

    Joined:
    Jan 27, 2001
    Messages:
    103,706
  15. Jru

    Jru Thread Starter

    Joined:
    Apr 21, 2004
    Messages:
    38
    hmm... i tried getting rid of it through HijackThis, but it keeps coming back... Then I tried regedit, and that closes after a few seconds too... Any suggestions?
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/222804

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice