This thread's last reply is from May 28, 2013, 9:33 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
ssmad
No luck I'm afraid it's still showing as a hidden folder nothing changed.
========== FILES ==========
< attrib -h -s day5 /c >
File not found - day5
C:\Users\SS\Desktop\cmd.bat deleted successfully.
C:\Users\SS\Desktop\cmd.txt deleted successfully.
< ren day5.lnk old-day5.lnk /c >
C:\Users\SS\Desktop\cmd.bat deleted successfully.
C:\Users\SS\Desktop\cmd.txt deleted successfully.
OTL by OldTimer - Version 3.2.69.0 log created on 05282013_004509
ssmad
still the same I'm afraid...
========== FILES ==========
< attrib -h -a H:\day5 /c >
Not resetting system file - H:\Day5
C:\Users\SS\Desktop\cmd.bat deleted successfully.
C:\Users\SS\Desktop\cmd.txt deleted successfully.
< ren H:\day5.lnk H:\old-day5.lnk /c >
C:\Users\SS\Desktop\cmd.bat deleted successfully.
C:\Users\SS\Desktop\cmd.txt deleted successfully.
OTL by OldTimer - Version 3.2.69.0 log created on 05282013_005213
deltalima
Try the last script again, I made a slight change after posting it.
ssmad
Success deltalima!
========== FILES ==========
< attrib -h -s H:\day5 /c >
C:\Users\SS\Desktop\cmd.bat deleted successfully.
C:\Users\SS\Desktop\cmd.txt deleted successfully.
< ren H:\day5.lnk H:\old-day5.lnk /c >
C:\Users\SS\Desktop\cmd.bat deleted successfully.
C:\Users\SS\Desktop\cmd.txt deleted successfully.
OTL by OldTimer - Version 3.2.69.0 log created on 05282013_005434
ssmad
Hey deltalima,
I'm not sure I follow you, the folder named Day5 is no longer being shown as a hidden folder after the last scan. The shortcut and all are still present but this particular folder is now working as normal.
So do i still run the fix and all the rest that you sent in your last post?
deltalima
Yes, run the script as above and let me know how it looks.
ssmad
Ok now all the shortcuts have been removed but the folders are still being shown as hidden folders.
As for Virustotal I'm afraid it's only giving me a place to upload files and trying to put the link there isn't working nor can i find the file so upload it.
========== FILES ==========
< attrib -h -s H:\*.* /c >
C:\Users\SS\Desktop\cmd.bat deleted successfully.
C:\Users\SS\Desktop\cmd.txt deleted successfully.
< del h:\*.lnk /c >
C:\Users\SS\Desktop\cmd.bat deleted successfully.
C:\Users\SS\Desktop\cmd.txt deleted successfully.
< attrib +h +s H:\$RECYCLE.BIN /c >
C:\Users\SS\Desktop\cmd.bat deleted successfully.
C:\Users\SS\Desktop\cmd.txt deleted successfully.
< attrib +h +s "H:\System Volume Information" /c >
Access denied - H:\System Volume Information
C:\Users\SS\Desktop\cmd.bat deleted successfully.
C:\Users\SS\Desktop\cmd.txt deleted successfully.
OTL by OldTimer - Version 3.2.69.0 log created on 05282013_010717
ssmad
Hey yes day5 is still being shown as unhidden.
I'm not sure if the last scan was supposed to make any changes or not, but if it was it didn't.
========== FILES ==========
< attrib H:\*.* /c >
File not found - H:\*.*
C:\Users\SS\Desktop\cmd.bat deleted successfully.
C:\Users\SS\Desktop\cmd.txt deleted successfully.
< dir H:\*.* /a /c >
Volume in drive H is My Passport
Volume Serial Number is 9666-B114
Directory of H:\
05/25/2013 01:44 PM <DIR> $RECYCLE.BIN
05/28/2013 12:45 AM <DIR> .Trashes
05/15/2013 02:21 PM <DIR> 100EOS5D
05/15/2013 05:18 PM <DIR> 101GOPRO
05/04/2013 06:24 PM <DIR> Day1 Nusai
05/05/2013 06:00 PM <DIR> Day2
05/07/2013 11:00 AM <DIR> Day3
05/08/2013 05:09 PM <DIR> Day4 Ishkashim
05/09/2013 08:23 PM <DIR> Day5
05/10/2013 08:23 PM <DIR> Day6
05/12/2013 11:14 AM <DIR> Day7
05/15/2013 03:49 PM <DIR> Day8
05/15/2013 02:39 PM <DIR> Day9
05/04/2013 02:05 PM <DIR> New Folder
05/15/2013 09:32 AM <DIR> PPH Vedio for Shabbir
05/25/2013 11:54 AM <DIR> System Volume Information
0 File(s) 0 bytes
16 Dir(s) 397,076,238,336 bytes free
C:\Users\SS\Desktop\cmd.bat deleted successfully.
C:\Users\SS\Desktop\cmd.txt deleted successfully.
< dir H:\.Trashes\*.* /a /c >
Volume in drive H is My Passport
Volume Serial Number is 9666-B114
Directory of H:\.Trashes
05/28/2013 12:45 AM <DIR> .
05/28/2013 12:45 AM <DIR> ..
05/11/2013 09:54 AM 63 Desktop.ini
1 File(s) 63 bytes
2 Dir(s) 397,076,238,336 bytes free
C:\Users\SS\Desktop\cmd.bat deleted successfully.
C:\Users\SS\Desktop\cmd.txt deleted successfully.
OTL by OldTimer - Version 3.2.69.0 log created on 05282013_013015
ssmad
hey deltalima,
All the folders that were created by me look fine now and seem to open and all just as they should.
I still have three hidden folders left though
.Trashes
$RECYCLE.BIN
System Volume Information
ssmad
hey deltalima,
It seems the scan didn't pick it up at all. After the scan finished I tried to just delete the folder .trashes and was able to. Everything seems find looks good in the drive as far as I can tell.
Shall we consider this problem resolved?
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=e57e078e27a2854bb4489cefe1cacb8d
# engine=13931
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2013-05-28 04:47:25
# local_time=2013-05-28 09:47:25 (+0500, Pakistan Standard Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=774 16777213 85 91 309004 146426317 0 0
# compatibility_mode=5893 16776573 100 94 58256 121346295 0 0
# scanned=252119
# found=5
# cleaned=0
# scan_time=27348
sh=CE0CFF1523E2DF7E436072554DEBBD86BCCDE1B8 ft=1 fh=64a8ad1547f2fc9f vn="a variant of Win32/Bundled.Toolbar.Ask application" ac=I fn="D:\Software\duplicate-file-finder-setup.exe"
sh=8F34BB9503DC54A9452821391D923FA19CE6E6FA ft=1 fh=ba0bf2bb89260abf vn="a variant of Win32/HackTool.Patcher.T application" ac=I fn="D:\Software\Adobe Acrobat XI Pro 11.0.1 Multilanguage [ChingLiu]\patch-MPT\adobe.acrobat.xi.pro.patch-MPT.exe"
sh=9B66BE44FCED8289978C552F513D94053E4D5D2A ft=1 fh=bd79624b2933f04f vn="Win32/PrcView application" ac=I fn="D:\Software\Drivers\Gigabyte\Other\Marvell\MSU\MSUSetup.exe"
sh=D2408C8A09A2BD9704AF39F818EC7AC9E9CCA46E ft=1 fh=08d2b982dc66508e vn="a variant of Win32/Bunndle application" ac=I fn="D:\Software\Windows Oct 5 2012\utorrent.exe"
sh=63E5A055D0F0D516D740E881AE9CE93440D148AA ft=1 fh=d03ef94bc0718461 vn="NSIS/TrojanDownloader.FakeAlert.DK.Gen trojan" ac=I fn="D:\Software\Windows Oct 5 2012\EASEUS.Partition.Master.v6.0.1.Professional.Edition.Retail-rG\EASEUS.Partition.Master.v6.0.1.Professional.Edition.Retail-rG\rgepm6pi\rg-setup\setup.exe"