Hidden files + wireless network problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by On edge, Jun 30, 2008.

  1. On edge

    On edge Corporal

    I recently had another trojan/malware attack. It didn't go far before I nipped it (think I got them all), but either they, or the cleanup, left my hidden files system compromised, which is why I'm posting the question here.

    In particular, even though I choose the 'display hidden files and folders' option, they still remain hidden. Attached is a pic/s that show an example of this problem + my folder view settings.

    Top left: The G:\ drive appears empty.
    Top and bottom right: My 'Folder Options -> View' settings.
    Bottom left: Pop-up window when I Press Ctrl+A (select all).

    This happened to many important folders including 'C:\Windows\System32\drivers', but some of them I got back using command prompt (attrib -h "[folder path]" or something like that).

    Also, my wireless network connection has stopped working, or more specifically I cannot start Windows Zero Configuration utility. More on that later (need to recheck it again after I post this).

    Thanks in advance.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since it is possible that you could still have malware hiding on your PC, it would be best if you did the below so we can determine what is the root cause of your problem.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. On edge

    On edge Corporal

    Here are the logs.
     

    Attached Files:

  4. On edge

    On edge Corporal

    I ran Malwarebytes' Anti-Malware and it found 0 infected files, and detected no malicious items, but I can't post the requested log file because this forum won't accept it. [See the print screen pic if you want.]
     

    Attached Files:

    • MAM.jpg
      MAM.jpg
      File size:
      80.9 KB
      Views:
      4
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs do not show any malware. Also the logs show that your settings are all configured properly to see hidden files and folders. Perhaps you should first check a more standard place with Windows Explorer. If you look at your C drive root folder. Do the below folders show as faded out?
    RECYCLER
    System Volume Information

    Do the below files show?
    hiberfil.sys
    pagefile.sys

    If you go to the C:\Windows\system32 folder, do files show?

    What is drive G? Is it an internal hard disk?

    What is the below service supposed to do?
    O23 - Service: Personal Secure Drive service (PersonalSecureDriveService) - Infineon Technologies AG - c:\WINDOWS\system32\IfxPsdSv.exe
     
  6. On edge

    On edge Corporal

    Yes.

    Yes.

    Yes. No hidden files there anymore as far as I can tell, but that's only after I used command prompt to unhide my drivers folder.

    G: is an external hard drive, but the problem has presented itself elsewhere. I just tried to find another example, (I checked 'Application Data' folders, for example, where it happened before), but couldn't find any, so maybe the problem went away.

    The only changes I'm aware of are that the scans you requested deleted some IAM-folder, disabled my fingerprint logon program, and subsequently I disabled my Windows logon password since it was a PITA to keep typing in my password manually instead of just wiping my finger over the fingerprint scanner as before...

    It's part of the HP's security system that came with the laptop. The fingerprint scanner may be part of it, or related at least. The programs you asked me to run may have disabled it. HP used to store all my passwords somewhere, and it would ask for a fingerprint, and input the passwords whenever I entered an email or message board website. For example, when I came to forums.majorgeeks.com, it would ask for my fingerprint, and then log me on, but that has stopped now. I assume I can restart the program manually, but I'll wait until my current problems have been sorted before I do anything about that.

    Does that help?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on all of your answers it therefore sounds like viewing of hidden files and folders is working just fine. Those items would not show if it was not working. I don't know what problem you are having with drive G but it is not related to these settings. It is however quite possible that there are other files on drive G. You have to understand that even when you have the settings configured to show everything, Microsoft Windows still does not show everything. It is just another bad design flaw put into Windows that malware takes advantage of everyday. One quick example is your C:\Windows\Downloaded Program Files folder. You can view it with Windows Explorer but you are not seeing the files in the folder You have to view it from the command prompt or using something other than Windows Explorer that properly shows all files.

    You can restore the
    C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
    that ComboFix mistakenly deleted from the C:Qoobox\Quarantine\C\Program Files folder. You will find it in here with a .vir extension added to it. Just remove the .vir and move or copy it back to the correct folder.

    Also in the C:Qoobox\Quarantine\C folder there should be a Registry_Backups folder. Tell me what files you see here. We need to restore the Legacy_ASBroker driver.
     
    Last edited: Jul 3, 2008
  8. On edge

    On edge Corporal

    There's no problem with drive G:. The 2 hidden folders were "RECYCLER" and "System Volume Information" (I assume); at least those 2 now appear when I look at G: and I don't get the error message anymore when I 'select all' in that drive or any other directory. Whatever those scans did, they fixed the problem - maybe it was something to do with HP's fingerprint/password authentication and protection.

    Thanks for the help so far. I'll get back to you on the other things later. I still have the wireless problems that also coincided with the Trojan attack, but I'll post more about that tomorrow (need to test it again and take some 'print
    screen' pics first.'
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that sounds better on the hidden files since it all looked fine to me.
     
  10. On edge

    On edge Corporal

    Wireless problem:

    I'm currently using a cable connection, but need my wireless back (currently same provider as the cable) for when I leave home.

    When I turn it on (at home), it links to some random networks if at all. I try to select my own secure Verizon network, but I cannot view the list of available networks (Windows cannot configure them), and I cannot start Zero Configuration utility either. The exact messages I get when I try are show in the attached pics. I've tried the usual things, but without success.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You would be better off working the problem in the Networking of Software Forum. I suggest that you first look at the Dependencies tab of the Wireless Zero Service and see what it is dependent on and make sure those services have not been stopped or disabled.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds