My hard drive has been infected by Conduit

Page 8 of 9 FirstFirst ... 6789 LastLast

  1. Posts : 2,470
    Windows 7 Home Premium
       #71

    NeverFindExt or NeverShowExt???

    There are hidden files marked as Super Hidden Files that are not viewed by the normal routine.


    Please download SystemLook from one of the links below:
    Link 1
    Link 2
    (Only direct links available)

    Save the file to the Desktop
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following code box into the open textfield:
    Code:
    :regfind 
    NeverShowExt 
    NeverFindExt
    • Click the Look button to start the scan.
    • When finished, a Notepad window opens with the results of the scan.
    Please post the SystemLook.txt in your reply.


    Thanks!
      My Computer


  2. Posts : 25,847
    Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
       #72

    Thank you Cottonball. I learned something today and I like that.
    Super Hidden Files
    I didn't know I had any.
    Thanks again.
      My Computer


  3. Posts : 2,470
    Windows 7 Home Premium
       #73

    @Layback Bear:

    There is something to be learned every day you work here.
    Don't you ever have some "What the heck is the OP talking about?" moments?
    If you don't, you are lucky. I have those all the time. Some of them qualify under "Senior Moments"!

    The hide or show files game is not my thing, although malware can do strange things and hide something where you least expect it. Normally, from what I understand, it is best to leave SuperHidden files just as they are.

    Not sure if all files are displayed in Windows Explorer upon enabling 'Show hidden files' in Folder Options.
    If a User insists on seeing them, or, if there is a valid need, to display SuperHidden files, you can do the following:

    •Open the Registry editor(Start > Run > Regedit)
    •Go to: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
    •In the right pane, double-click on SuperHidden and set its value to: 1

    When done, close the Registry and restart the PC.
      My Computer


  4. Posts : 25,847
    Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
       #74

    You might of taken me wrong.
    I really didn't know what you just explained.
    The thank you was meant whole heartily.

    Don't you ever have some "What the heck is the OP talking about?" moments
    See them every day.

    I really don't want to see my Super Hidden files. They are super hidden for a reason and until now I didn't even know their was such a thing. I do find many things on my computer that I don't know what they are. Sometimes I will Google them. 99.999% of the time I just leave them alone.

    I will remember if I ever want to see them all I have to do is ask you how.
    Once again Thanks!
      My Computer


  5. Posts : 2,470
    Windows 7 Home Premium
       #75

    There are other ways of viewing those SuperHidden files, I'm sure.

    I really don't want to see my Super Hidden files. They are super hidden for a reason...
    Spot-on!!
      My Computer


  6. Posts : 114
    Windows 7 Home Premium
    Thread Starter
       #76

    For Cottonball

    There are five instances of HideFileExt on the given Registry key. I ran it twice and both times came up with 5.

    Checked Value is 0x00000001(1)

    NeverShowExt does not appear in the Registry

    Folder Options is 0.

    I set SuperHidden to 1 and rebooted


    GerryR
      My Computer


  7. Posts : 114
    Windows 7 Home Premium
    Thread Starter
       #77

    This is the result for Cottonball of using System_x64.exe


    SystemLook 30.07.11 by jpshortstuff
    Log created at 02:06 on 03/10/2013 by Gerald
    Administrator - Elevation successful

    ========== regfind ==========

    Searching for "NeverShowExt"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Access.Shortcut.DataAccessPage.1]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Access.Shortcut.Diagram.1]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Access.Shortcut.Form.1]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Access.ShortCut.Function.1]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Access.Shortcut.Macro.1]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Access.Shortcut.Module.1]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Access.Shortcut.Query.1]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Access.Shortcut.Report.1]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Access.Shortcut.StoredProcedure.1]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Access.Shortcut.Table.1]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Access.Shortcut.View.1]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Application.Reference]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ECF03A32-103D-11d2-854D-006008059367}]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fdse_file]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ffs0_file]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ffs1_file]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ffs2_file]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ffs3_file]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ffs4_file]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ffs5_file]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ffs6_file]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ffs7_file]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ffs8_file]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ffse_file]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fse_file]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IE.AssocFile.URL]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IE.AssocFile.WEBSITE]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\InternetShortcut]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\LibraryFolder]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.Website]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\piffile]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchConnectorFolder]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchFolder]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SHCmdFile]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ECF03A32-103D-11d2-854D-006008059367}]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\xnkfile]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}]
    "NeverShowExt"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{ECF03A32-103D-11d2-854D-006008059367}]
    "NeverShowExt"=""

    Searching for "NeverFindExt"
    No data found.

    -= EOF =-

    I then ran it twice more and both times got the following result.

    SystemLook 30.07.11 by jpshortstuff
    Log created at 02:32 on 03/10/2013 by Gerald
    Administrator - Elevation successful

    ========== regfind ==========

    Searching for "NeverShowExt "
    No data found.

    Searching for "NeverFindExt"
    No data found.

    -= EOF =-
    Last edited by GerryR; 03 Oct 2013 at 01:35.
      My Computer


  8. Posts : 114
    Windows 7 Home Premium
    Thread Starter
       #78

    To Cottonball re System_x64.exe


    1) Can you tell me what the significance of this is?

    2) Is there any point in keeping System_64.exe on my desktop any longer
      My Computer


  9. Posts : 2,470
    Windows 7 Home Premium
       #79

    1) Can you tell me what the significance of this is?
    It all deals with file extensions which have a NeverShowExt Registry value.

    If you take one of the entries, at random, like:
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}]
    "NeverShowExt"=""

    There's an entry in the Send To menu called "Compressed (zipped) Folder". It is obtained by right-clicking on a file,
    If you take a look at the folder specifying the entries for the Send To menu, %APPDATA%\Microsoft\Windows\SendTo, you'll find that this item is: ZFSendToTarget.

    The purpose of this shell extension is to allow for creating a compressed folder using Send To.

    Some other entries point to file extensions for Supper Hidden Files.


    2) Is there any point in keeping System_64.exe on my desktop any longer
    Have no clue what System_x64.exe is. However, if you mean SystemLook_x64.exe, you can remove it any time you wish.
      My Computer


  10. Posts : 114
    Windows 7 Home Premium
    Thread Starter
       #80

    SystemLook_x64


    We must be in radically different time zones. I don't receive Seven Forums notices from you until about 2:30 AM my time. I am not at my best then. Yes, I meant SystemLook_x64. Does this mean that my computer is now clean of conduit? Unfortunately I am dealing with some people who insist that all pdf files be opened by Adobe Reader. As I really have to deal with them, I'm stuck. I consider that to be a program of dubious security. I had been using Sumatra for PDF files but have temporarily uninstalled it. Somehow their PDF files won't allow Sumatra or Foxit to open them. I consider FlashPlayer to be another hacker target. I've uninstalled Java and so far no adverse effects have followed.

    Except for that, is my disaster officially over?

    In any case, many thanks,

    Gerry
      My Computer


 
Page 8 of 9 FirstFirst ... 6789 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 18:41.
Find Us