|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
#1 |
|
Member (7 bit)
Join Date: Feb 2005
Location: IL
Posts: 109
|
Window\System32 Folder hidden from view
Has anyone ever experience malware that hides the system32 from view? I have set the folder options to show hidden files and unchecked the option for hide protected operating system files. But the folder still is hidden.
I am asking because I am working on a computer running WinXP Home that was connected to the internet(via broadband cable) w/o any AV protection or anything but the Windows Firewall. Needless to say the system severely infected(Trojans and adware). Continous popups. Not able to control the computer with the mouse or keyboard. Only able to shut down using the power button So far I have been able to scan the computer thru the ethernet with McAfee A/V from my computer to remove some of the infections. Next I entered safe mode to do an online scan at ewido.net. ewido was not able to remove any of the infections. I then did a repair install of WinXP. This allowed me to regain control in normal mode. Installed Zone Alarm to control the IE from accessing the internet and displaying more popup ads. Installed Spybot Search and Destroy and AdAware SE. Both Spybot and AdAware found malware in the Windows\System32\surfkill folder but could not remove it. Both were ran twice, once in normal mode and again in safe mode. I tried to navigate to the folder using Windows explorer but the folder is missing from view. I have never seen anything like this before.I am not positive of the folder name 'surfkill' because I forgot to bring my notes I wrote down with me before I came to work. I am sure that 'surf' is part of the name. When I get home I will post more details of the malware name and location. Any feedback on how I should procede would be appreciated
__________________
It takes patience and more patience to fix this computer stuff.
|
|
|
|
|
|
#2 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 37,782
|
If I were working on that machine, at this point I'd be recommending a nuke and pave.
|
|
|
|
|
|
#3 | |
|
Member (7 bit)
Join Date: Feb 2005
Location: IL
Posts: 109
|
Quote:
Yeah, I agree. I have been working on this one for the pass two nights. I told the person I would try one more night to remove the malware before doing that. The problem is that this is a emachine computer and the person lost their recovery CD. That means they will have to buy a new copy of XPHome, which is more money that they don't want to spend. |
|
|
|
|
|
|
#4 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 37,782
|
By the time they buy a copy of XP and replacement software and pay your labor rates, they could buy a new PC.
|
|
|
|
|
|
#5 | |
|
Served with Pride
Staff
Premium Member
|
Quote:
|
|
|
|
|
|
|
#6 | ||
|
Member (7 bit)
Join Date: Feb 2005
Location: IL
Posts: 109
|
Quote:
Quote:
|
||
|
|
|
|
|
#7 |
|
Member (6 bit)
Join Date: Mar 2006
Posts: 55
|
Pre-installed environment.
You could pull out the folder in A43 file manager in a snap. Or you could use the CMD prompt to remove the hidden status and then run your AV/AS/AM scans in the bootable environment. Bart-PE would fix this one in under an hour. As it is, you might look into Panama Red's suggestion on a replacement recovery CD. Also, the machine might just have a recovery partition if it is newer. |
|
|
|
|
|
#8 | |
|
Member (7 bit)
Join Date: Feb 2005
Location: IL
Posts: 109
|
Quote:
Can you explain more about A43 file manager and Bart-PE. Or provide a link to were I can get more information. I am not familiar with either one. Thanks I did check with eMachines and you can get a replacement Restore/Recovery CD. I was not able to get a price because you have to give the serial number,store the computer was purchase from and the date. I will have to find out what store and date the computer was purchased from. Last edited by Cisridn; 04-28-2006 at 04:24 PM. |
|
|
|
|
|
|
#9 |
|
Member (7 bit)
Join Date: Feb 2005
Location: IL
Posts: 109
|
Never mind the request SWTF.
I was able to find information about A43 file manager and Bart-PE. |
|
|
|
|
|
#10 |
|
Member (6 bit)
Join Date: Mar 2006
Posts: 55
|
Sorry I wasn't able to check back sooner and explain... which I really should have done in the first place. Glad you managed to find some info though.
|
|
|
|
|
|
#11 |
|
Member (7 bit)
Join Date: Feb 2005
Location: IL
Posts: 109
|
No Problem. Any tips that you have would be helpful.
I believe I have got the situation under control. I am still having a problem removing on a folder: c:\Windows\Program Files\surfsidekick 3 When I try to delete it I get an message telling me the files cannot be accessed because it is in use by another program. I think if I can remove this folder and the files in it I will stop getting the popup ads. |
|
|
|
|
|
#12 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 37,782
|
|
|
|
|
|
|
#13 |
|
Member (7 bit)
Join Date: Feb 2005
Location: IL
Posts: 109
|
Thanks for the Link GLC.
To update the situation. After scanning the infected computer many times with A\V, spybot, Ad Aware SE. It appears that all malware infection have been removed or at least tamed. I slaved the hard drive in my system to remove the surfsidekick folder and scan again. Currently reinstalling SP2. Only thing left to do is remove rundll error message that pops up after windows finishes loading. BTW I did attrib -a -h -r -s for the system32 folder to get it to reappear. Thanks everyone for there suggestions and tips. |
|
|
|
|
|
#14 |
|
Member (6 bit)
Join Date: Mar 2006
Posts: 55
|
MoveOnBoot is another good solution.
The attrib -a-h-r-s is what I'd have done with CMD in Bart-PE if A43 couldn't rip it out. Good work handling that infection. You're a pro! |
|
|
|
|
|
#15 |
|
Member (7 bit)
Join Date: Feb 2005
Location: IL
Posts: 109
|
I believe I spoke to soon when I said it appears that the malware has been removed or at least tamed. SP2 install failed and now I can't get to the Windows Update website.
You will have to hold off on my Pro status for now SWTF. Other than that the system is running good. Does anyone have any ideas what is causing the Windows Update site not to load? I have tried a few steps that I found on microsoft support site but nothing has worked yet. |
|
|
|
|
|
#16 |
|
Member (7 bit)
Join Date: Feb 2005
Location: IL
Posts: 109
|
Great News
My client decided to find their restore CD for the infected computer.
After all the time and effort. This works out, because I was not able to get Windows Update to work anymore. I took that as a sign that the computer was still infected with some kind of malware. Since I have the restore/recovery CD I will do a low-level format of the hard drive and start out fresh.I guess that's how things goes sometimes. I am just thankful that I was reimbursed for my time and effort. Thanks again for everybody's input and suggestions. |
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|