The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    cant see hidden folders

    Discussion in 'Security and Anti-Virus Software' started by aespinalc, Oct 1, 2008.

  1. aespinalc

    aespinalc Notebook Evangelist

    Reputations:
    45
    Messages:
    303
    Likes Received:
    0
    Trophy Points:
    30
    dunno where to post this
    well... im sure a lot of ppl remembers this virus... but daaammmm... has it evolved?????
    i mean.. i already tried the regedit stuff and went to SHOWALL to change checked to 1... and nothing... after a lot of tries, i realized that when i pressed F5 in regedit, the value instantly changed to 0 again... ive been messing around with this thing and have gone to the point of killing almost every process.. cand delete the vital ones... and still this thingh...

    any suggestion plz?

    thanks a lot!
     
  2. Andy

    Andy Notebook Prophet

    Reputations:
    2,133
    Messages:
    6,399
    Likes Received:
    1
    Trophy Points:
    206
    Tried the same in Safe Mode ?
     
  3. aespinalc

    aespinalc Notebook Evangelist

    Reputations:
    45
    Messages:
    303
    Likes Received:
    0
    Trophy Points:
    30
    yes sir, did... still the same keeps changing the value to 0
     
  4. Shyster1

    Shyster1 Notebook Nobel Laureate

    Reputations:
    6,926
    Messages:
    8,178
    Likes Received:
    0
    Trophy Points:
    205
    What virus is that (hey! Memory is one of the first things to go! :D)? Also, sounds like whatever's gotcha has infected/taken control of regedit, so you may need to try another way. The registry can be edited manually through Powershell which, as far as I know, does not use the services of regedit.exe; if the malware is controlling regedit.exe, that might be a way to circumvent it.
     
  5. aespinalc

    aespinalc Notebook Evangelist

    Reputations:
    45
    Messages:
    303
    Likes Received:
    0
    Trophy Points:
    30
    done with powetshell and still the same thing.. OMG! im going to lose it T.T
     
  6. Baserk

    Baserk Notebook user

    Reputations:
    2,503
    Messages:
    1,794
    Likes Received:
    1
    Trophy Points:
    56
    Or you could try the Remove Restrictions Tool/RRT from Sergiwa software; link and link.
    Remember it will not remove any malware.
    I'd use SUPERAntispyware and/or Malwarebytes'Antimalware for cleaning the infection if your AV can't do the job.
    Cheers.
     
  7. Shyster1

    Shyster1 Notebook Nobel Laureate

    Reputations:
    6,926
    Messages:
    8,178
    Likes Received:
    0
    Trophy Points:
    205
    One thing you might try to use is SysInternals' RegMon, which provides a GUI for monitoring access and changes to the registry.

    It might be possible to start up RegMon, then go into regedit, make the change, have it get changed back, and then use the monitoring history from RegMon to try and identify what bit of nastiness just went in and changed it back.
     
  8. aespinalc

    aespinalc Notebook Evangelist

    Reputations:
    45
    Messages:
    303
    Likes Received:
    0
    Trophy Points:
    30
    so here is what i found with regmon and its xactly what im looking for, opens all the hide foder and hide system files and put 0... then opens KAVa... wich im pretty sure has to do with this kavo.exe and kavo0.dll... but i cant delete em unless i have the hidden folder option again...

    any ideas on whats next?

    [​IMG]
     
  9. KarenA

    KarenA Notebook Evangelist

    Reputations:
    81
    Messages:
    565
    Likes Received:
    0
    Trophy Points:
    30
    The virus that makes us can't see hidden folders... Rontokbro?
     
  10. Baserk

    Baserk Notebook user

    Reputations:
    2,503
    Messages:
    1,794
    Likes Received:
    1
    Trophy Points:
    56
    Aespinalc, have you seen this and this webpage discussing the same problem?
    Maybe either Prevx CSI or ThreatFire can clean your notebook after which you can change the reg values permanently.
    Cheers.
     
  11. aespinalc

    aespinalc Notebook Evangelist

    Reputations:
    45
    Messages:
    303
    Likes Received:
    0
    Trophy Points:
    30
    unfortunatedly i have no idea how i solved the problem... fortunatedly the process that kept changing the register stopped working (dunno why) and i could finally see hidden folders and erase kav0.exe and kavo.dll

    thankls all
     
  12. Aeris

    Aeris Otherworldly

    Reputations:
    474
    Messages:
    805
    Likes Received:
    20
    Trophy Points:
    31
    If it happens again, you can try using this:

    Code:
    On MS-DOS / Command Prompt:
    
    attrib -r -s -h
    The syntax is the following:

    Code:
    On MS-DOS / Command Prompt:
    
    attrib -r -s -h C:\Folder
    attrib -r -s -h C:\Folder\file.exe
    attrib -r -s -h C:\file.exe
    It changes the attributes of files and / or folders that are hidden, individually and does not realy depend on the Windows Registry.

    Source: [LINK.]

    By the way, Comodo Firewall Professional's Quarintined Files module, if you try to add a file to the Quarintine, Comodo's Explorer Shell will pop up, and it will show hidden files of any kind, including boot files that are hidden even further by Windows and are not visible not even by "Show hidden folders and files.".