Hidden program files folder

mikaka next time can put code tags so the post does not run too long....
also (and if get dont get this correctly please correct me)
you ran Spybot S&D/Nod32 and it found something...
(do you know what you deleted [some sort of log would help from spybot and nod])
you deleted it
and then you went working into MSconfig tool looking for some more malware...

from the screen shot it (and following dinesh's advice)check these two
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
and these
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce

and from this info (and your msconfig screenshot)
it might seem you already deleted the file (although the only way you can be sure is if
boot a live cd (its more harder to infect a read only media to read/write media...) mount that disk and from there look if the file/s are there...

you can also use WinRE (pressing F8 and clicking on repair your computer) you can pick up a cmd prompt and you can check (throught the use of cd and dir commands) if the file is there and then delete it (using the del command)...
although do not try this is if you are not proficient with a DOS prompt style interface..
 

My Computer

Computer Manufacturer/Model Number
Tx2500z Tablet Pc/Homemade Server
OS
Windows 7 Ult x64(x2), HomePrem x32(x4), Server 08 (+VM), 08 R2 (VM) , SuSe 11.2 (VM), XP 32 (VM)
CPU
Turion X2 ultra (oh well came with laptop)/P4 @3.2 (yes P4)
Motherboard
IDK HP Motherboard / Intel DG965SS
Memory
OCZ Dual Channel 4GB kit/ 1gb Dual Channel
Graphics Card(s)
HD 3200 graphics /GMA x3100 (yay for intergrated!!)
Sound Card
Realtek HD Audio(mic working, well sort of)/Siig IC-70012
Monitor(s) Displays
built-in Hp 12" laptop screen/ Acer 19"
Screen Resolution
1280x800 /1440x900
Cooling
All Air Cooled
Mouse
Logi MX Rev. /MS Wheel Optical 1.1A /Logitech Optical Mouse
Internet Speed
College baby but its still routed through vpn to 1536k...
Other Info
love my wacom pen and pressure sensitivity...
wished it worked in 7, SUSE for that matter though
Would you please upload (individually) and scan each of these files to jotti
Jotti's malware scan
C:\Windows\System32\drivers\SRK.sys
C:\Windows\ôU
C:\Windows\”úo
C:\Windows\System32\%APPDATA%
C:\Windows\System32\APOMngr.DLL

Post the result logs {copy and paste} the link from the address bar ---> http://
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
I guess he will need to do a clean install. :(
 

My Computer

Computer Manufacturer/Model Number
Samsung NP530U4B-S02IN
OS
Windows® 8 Pro (64-bit)
CPU
Intel® Core™ i5 Processor 2467M (1.60GHz, 3MB L3 Cache)
Motherboard
Samsung Electronics
Memory
6GB DDR3 System Memory at 1,333MHz (on BD 4GB + 2GB x 1)
Graphics Card(s)
AMD Radeon™ HD7550M 1GB DDR3 (Ext. Graphic)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
35.56cm (14.0) SuperBright 300nit HD LED Display
Screen Resolution
1366x768
Hard Drives
1TB S-ATA II Hard Drive (5400RPM) with ExpressCache 16GB SSD
Internet Speed
sucks
Antivirus
Microsoft Security Essentials
Browser
Google Chrome (Sync enabled)
@darkassain

I think the log from Nod32 is gone, I cannot find it (unless there is a way to retrieve it, after Nod has been reinstalled).
But here is what Spybot found:
Imageshack - przechwytywanie

The registry entries look clean to me, both RunOnce's are empty.
Run in CURRENT_USER contains Google Update (I have Chrome browser), and Sidebar.
Run in LOCAL_MACHINE contains Ad Muncher (ad blocker, installed by me), Ad-watch (Ad Aware also installed by me), and Egui (GUI process for ESET Nod32).

I'm gonna boot with 7 DVD, and check if the two files of the _scott things are still there.

@Jacee
SRK.sys
ôU
”úo
index.dat (The only file inside %AppData%/Microsoft/Windows/IETldCache
APOMngr.DLL

@dinesh
I hope not :D
 

My Computer

OS
Windows 7 build 7600 64 bit
CPU
Intel Core2Quad Q8200 2.33 GHz @ 2.33 GHz
Motherboard
Gigabyte GA-P35-S3 rev. 1
Memory
GoodRAM DDR2 3 x 1 GB 800 MHz
Graphics Card(s)
HIS ATI Radeon HD 4850 512 MB VRAM
Sound Card
Creative X-FI Gamer
PSU
400 W
Did you try the Boot scan with avast?
 

My Computer

Computer Manufacturer/Model Number
Samsung NP530U4B-S02IN
OS
Windows® 8 Pro (64-bit)
CPU
Intel® Core™ i5 Processor 2467M (1.60GHz, 3MB L3 Cache)
Motherboard
Samsung Electronics
Memory
6GB DDR3 System Memory at 1,333MHz (on BD 4GB + 2GB x 1)
Graphics Card(s)
AMD Radeon™ HD7550M 1GB DDR3 (Ext. Graphic)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
35.56cm (14.0) SuperBright 300nit HD LED Display
Screen Resolution
1366x768
Hard Drives
1TB S-ATA II Hard Drive (5400RPM) with ExpressCache 16GB SSD
Internet Speed
sucks
Antivirus
Microsoft Security Essentials
Browser
Google Chrome (Sync enabled)
Did you try the Boot scan with avast?
Yes, it came clean.
So when it came clean, and then another scan with Nod32 also came clean, there's nothing strange in Run/Runonce, and I resolved the invisible Program Files, do you think I don't have to worry about this virus anymore??
I'll do a full scans in Spybot and AdAware just in case.
 

My Computer

OS
Windows 7 build 7600 64 bit
CPU
Intel Core2Quad Q8200 2.33 GHz @ 2.33 GHz
Motherboard
Gigabyte GA-P35-S3 rev. 1
Memory
GoodRAM DDR2 3 x 1 GB 800 MHz
Graphics Card(s)
HIS ATI Radeon HD 4850 512 MB VRAM
Sound Card
Creative X-FI Gamer
PSU
400 W
Last edited:

My Computer

Computer Manufacturer/Model Number
Tx2500z Tablet Pc/Homemade Server
OS
Windows 7 Ult x64(x2), HomePrem x32(x4), Server 08 (+VM), 08 R2 (VM) , SuSe 11.2 (VM), XP 32 (VM)
CPU
Turion X2 ultra (oh well came with laptop)/P4 @3.2 (yes P4)
Motherboard
IDK HP Motherboard / Intel DG965SS
Memory
OCZ Dual Channel 4GB kit/ 1gb Dual Channel
Graphics Card(s)
HD 3200 graphics /GMA x3100 (yay for intergrated!!)
Sound Card
Realtek HD Audio(mic working, well sort of)/Siig IC-70012
Monitor(s) Displays
built-in Hp 12" laptop screen/ Acer 19"
Screen Resolution
1280x800 /1440x900
Cooling
All Air Cooled
Mouse
Logi MX Rev. /MS Wheel Optical 1.1A /Logitech Optical Mouse
Internet Speed
College baby but its still routed through vpn to 1536k...
Other Info
love my wacom pen and pressure sensitivity...
wished it worked in 7, SUSE for that matter though
Yes, it came clean.
So when it came clean, and then another scan with Nod32 also came clean, there's nothing strange in Run/Runonce, and I resolved the invisible Program Files, do you think I don't have to worry about this virus anymore??
I'll do a full scans in Spybot and AdAware just in case.
How did you fix the program files issue?
Glad to hear that its fixed now. :)
 

My Computer

Computer Manufacturer/Model Number
Samsung NP530U4B-S02IN
OS
Windows® 8 Pro (64-bit)
CPU
Intel® Core™ i5 Processor 2467M (1.60GHz, 3MB L3 Cache)
Motherboard
Samsung Electronics
Memory
6GB DDR3 System Memory at 1,333MHz (on BD 4GB + 2GB x 1)
Graphics Card(s)
AMD Radeon™ HD7550M 1GB DDR3 (Ext. Graphic)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
35.56cm (14.0) SuperBright 300nit HD LED Display
Screen Resolution
1366x768
Hard Drives
1TB S-ATA II Hard Drive (5400RPM) with ExpressCache 16GB SSD
Internet Speed
sucks
Antivirus
Microsoft Security Essentials
Browser
Google Chrome (Sync enabled)
How did you fix the program files issue?
Glad to hear that its fixed now. :)

he ran in a elevated cmd prompt attrib -h -s Program Files
 

My Computer

Computer Manufacturer/Model Number
Tx2500z Tablet Pc/Homemade Server
OS
Windows 7 Ult x64(x2), HomePrem x32(x4), Server 08 (+VM), 08 R2 (VM) , SuSe 11.2 (VM), XP 32 (VM)
CPU
Turion X2 ultra (oh well came with laptop)/P4 @3.2 (yes P4)
Motherboard
IDK HP Motherboard / Intel DG965SS
Memory
OCZ Dual Channel 4GB kit/ 1gb Dual Channel
Graphics Card(s)
HD 3200 graphics /GMA x3100 (yay for intergrated!!)
Sound Card
Realtek HD Audio(mic working, well sort of)/Siig IC-70012
Monitor(s) Displays
built-in Hp 12" laptop screen/ Acer 19"
Screen Resolution
1280x800 /1440x900
Cooling
All Air Cooled
Mouse
Logi MX Rev. /MS Wheel Optical 1.1A /Logitech Optical Mouse
Internet Speed
College baby but its still routed through vpn to 1536k...
Other Info
love my wacom pen and pressure sensitivity...
wished it worked in 7, SUSE for that matter though
Have you visited 'GameSpot' forums and downloaded any games, cheats or etc?

Last time I downloaded Harry Potter 6 demo, and yes, I may have downloaded some cheat.

Looking at all the games you have, did you download Bypassing GameGuard?

This 'cheat' would be detected as Troj/RKProc-Fam
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
How did you fix the program files issue?
Glad to hear that its fixed now. :)
I didn't wanted to do triple post, so its posted on the end of the second log (the extras.txt).

looks like a rootkit...:(
run the disenfector
Sophos - Troj/RKProc-Fam and Troj/Stinx disinfection instructions
just in case run this to see if you have any traces of this trojan...;
Just finished, shows no objects detected.

Looking at all the games you have, did you download Bypassing GameGuard?

This 'cheat' would be detected as Troj/RKProc-Fam

I don't recall downloading that :/
 

My Computer

OS
Windows 7 build 7600 64 bit
CPU
Intel Core2Quad Q8200 2.33 GHz @ 2.33 GHz
Motherboard
Gigabyte GA-P35-S3 rev. 1
Memory
GoodRAM DDR2 3 x 1 GB 800 MHz
Graphics Card(s)
HIS ATI Radeon HD 4850 512 MB VRAM
Sound Card
Creative X-FI Gamer
PSU
400 W

My Computer

Computer Manufacturer/Model Number
Tx2500z Tablet Pc/Homemade Server
OS
Windows 7 Ult x64(x2), HomePrem x32(x4), Server 08 (+VM), 08 R2 (VM) , SuSe 11.2 (VM), XP 32 (VM)
CPU
Turion X2 ultra (oh well came with laptop)/P4 @3.2 (yes P4)
Motherboard
IDK HP Motherboard / Intel DG965SS
Memory
OCZ Dual Channel 4GB kit/ 1gb Dual Channel
Graphics Card(s)
HD 3200 graphics /GMA x3100 (yay for intergrated!!)
Sound Card
Realtek HD Audio(mic working, well sort of)/Siig IC-70012
Monitor(s) Displays
built-in Hp 12" laptop screen/ Acer 19"
Screen Resolution
1280x800 /1440x900
Cooling
All Air Cooled
Mouse
Logi MX Rev. /MS Wheel Optical 1.1A /Logitech Optical Mouse
Internet Speed
College baby but its still routed through vpn to 1536k...
Other Info
love my wacom pen and pressure sensitivity...
wished it worked in 7, SUSE for that matter though
Thanks for everyone, I reverted back to Vista as soon as I got my response from evenbalance that punkbuster will work with Windows 7 when it will be available in stores, and thats somewhere in October :(
Anyway thanks again for help.
 

My Computer

OS
Windows 7 build 7600 64 bit
CPU
Intel Core2Quad Q8200 2.33 GHz @ 2.33 GHz
Motherboard
Gigabyte GA-P35-S3 rev. 1
Memory
GoodRAM DDR2 3 x 1 GB 800 MHz
Graphics Card(s)
HIS ATI Radeon HD 4850 512 MB VRAM
Sound Card
Creative X-FI Gamer
PSU
400 W
HI

Hi,

I've had the same problem... But the elevated CMD prompt didn't work for me.
So I just open up Command Prompt as Administrator and type in:
attrib -h -s Program Files (x86) ?

I have a 64bit Vista Ultimate and the virus made my (x86) disappear.
I hope someone could help me out with this.
 

My Computer

OS
Vista
What was the error message?
 

My Computer

OS
Windows 7 build 7600 64 bit
CPU
Intel Core2Quad Q8200 2.33 GHz @ 2.33 GHz
Motherboard
Gigabyte GA-P35-S3 rev. 1
Memory
GoodRAM DDR2 3 x 1 GB 800 MHz
Graphics Card(s)
HIS ATI Radeon HD 4850 512 MB VRAM
Sound Card
Creative X-FI Gamer
PSU
400 W
Something like
"Parameter is not correct -" (I had to translate since I have a Dutch version).
 

My Computer

OS
Vista
Back
Top