|
07.04.2008., 22:52 | #1 |
Premium
Datum registracije: Dec 2005
Lokacija: Zagreb (centar)
Postovi: 190
|
ne zeli mi pokazati hidden files
mislim, kaj sam ja malo umoran pa ne vidim il koji je ovo vrag? problem je nastao maloprije kad sam kliknuo na start/my computer/local disc c i on mene pita s kojim programom ga zelim otvoriti??? ok, guglam ja i nadem da je vec netko imao slicnih problema i sad skuzim da nemam opciju "show hidden files and folders"!! kaj se desava? |
07.04.2008., 23:10 | #2 |
Moderator
Datum registracije: Jul 2004
Lokacija: Đakovo
Postovi: 1,816
|
Virus. Koji se najčešće prenosi USB Flash memorijama. Najvjerojatnije onaj (ne znam mu ime) što ti na svaku particiju naseli autorun.inf, mapu Recycled (ne Recycler, to treba biti) i još nešto, ne mogu se sjetiti - naravno, sve hidden. Inače, ovo s otvaranjem u exploreru se javlja nakon brisanja autorun.inf od strane AV programa. Evo, malo pročešljah na brzini, jedan virus se zove Brontok, a drugi New Folder.exe, možda ima i drugih sičnih... skini "New_Folder.exe_Removal_Tool.exe" i probaj s njim. Uglavnom, trebaš pobrisati navedenu gamad sa svih particija i USB stickova, te restartirati komp. Ako je sve očišćeno OK, to bi trebalo biti to. S gore navedenim alatom možeš vratiti older Options (opcija Restore Windows Default Settings).
__________________
|
|
|
Oglas
|
|
07.04.2008., 23:12 | #3 |
Od nonine sestre kunjado
Datum registracije: Dec 2006
Lokacija: (Vinjro)
Postovi: 1,130
|
Find this key in your registry: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden] Modify the string value "Type" and enter "group" as value data. After the edit is complete hit F5 to refresh, and go look in your Folder Options.
__________________
|
07.04.2008., 23:14 | #4 | |
Premium
Datum registracije: Dec 2005
Lokacija: Zagreb (centar)
Postovi: 190
|
da, prije toga sam ga skenirao s avgom, al se ne sjecam tocno kaj je nasao (a nasao je neka 3 virusa) Citiraj:
tak da to nije pomoglo probat cu ovo kaj je igorba rekao pa napisem kak je proslo a jebemu!!! |
|
08.04.2008., 00:56 | #5 |
Premium
Datum registracije: Dec 2005
Lokacija: Zagreb (centar)
Postovi: 190
|
ok, uspio sam natjerati windowse da mi otvaraju disc c i d, al jos uvijek nemam opciju "show hidden..." jebemu, kak da to rjesim - google mi bas i ne pomaze a jebemu, nedavno sam formatrirao komp!!!! joj kak sam sad ljut!!! |
08.04.2008., 01:39 | #6 |
N00B
Datum registracije: Oct 2006
Lokacija: Split
Postovi: 3,886
|
@ethan ajde nabaci logfile tu od hijack thisa.. PS.provaj ovo sve kopirati u text document i sjevati kao (bilosta.reg) mora biti ekstenzija .reg i importaj u registry dva puta klik na to pa >yes>zatim>ok Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Advanced\Folder\Hidden] "Text"="@shell32.dll,-30499" "Type"="group" "Bitmap"=hex(2):25,00,53,00,79,00,73,00,74,00,65,0 0,6d,00,52,00,6f,00,6f,00,74,\ 00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00 ,33,00,32,00,5c,00,53,00,\ 48,00,45,00,4c,00,4c,00,33,00,32,00,2e,00,64,00,6c ,00,6c,00,2c,00,34,00,00,\ 00 "HelpID"="shell.hlp#51131" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Advanced\Folder\Hidden\NOHIDDE N] "RegPath"="Software\\Microsoft\\Windows\\CurrentVe rsion\\Explorer\\Advanced" "Text"="@shell32.dll,-30501" "Type"="radio" "CheckedValue"=dword:00000002 "ValueName"="Hidden" "DefaultValue"=dword:00000002 "HKeyRoot"=dword:80000001 "HelpID"="shell.hlp#51104" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "RegPath"="Software\\Microsoft\\Windows\\CurrentVe rsion\\Explorer\\Advanced" "Text"="@shell32.dll,-30500" "Type"="radio" "CheckedValue"=dword:00000001 "ValueName"="Hidden" "DefaultValue"=dword:00000002 "HKeyRoot"=dword:80000001 "HelpID"="shell.hlp#51105" Zadnje izmijenjeno od: Joke. 08.04.2008. u 01:53. |
08.04.2008., 01:46 | #7 |
Premium
Datum registracije: Dec 2005
Lokacija: Zagreb (centar)
Postovi: 190
|
evo idem napravit hijack log EDIT1: evo log Logfile of HijackThis v1.99.1 EDIT2: al nisam te bas skuzio kaj trebam napravit s ovim tekstom copy/pastao sam u "new Text Document" i sejvao pao "proba.reg" i kaj sad s tim text dokumentom? (sorry ak pitam glupa pitanja, al vec sam izludio) EDIT3: ok, uspio sam napravit i ovo s reg fileom, al nema promjene a jebi ga, shit happens joj, kak mi se neda ponovno formatrirat komp zbog glupih hidden file-ova ok, ajde, sranje je tu i sad sam popusio formatriranje al ostaje pitanje - jel sam izgubio tu opciju zbog nekog virusa ili su jednostavno windowsi otisli kvragu? Zadnje izmijenjeno od: domy_os. 08.04.2008. u 16:09. |
08.04.2008., 09:33 | #8 |
Premium
Datum registracije: Apr 2007
Lokacija: Ivanić_Grad
Postovi: 1,943
|
makni - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.hr/ makni - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 makni - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 makni - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 makni- HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 makni - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll makni - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll makni - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll makni - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll makni - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll makni - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll makni - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll makni- Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe makni - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" makni - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" makni - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe makni - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP makni - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe makni - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" makni - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup makni - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start makni - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart makni - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe makni ovo bi moglo stvarati tvoj problem - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{A0343AF4-2540-438F-97B0-36E7D04340B2}: NameServer = 85.114.32.7 85.114.32.8 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\ O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe makni - Service: CSIScanner - Unknown owner - C:\Program Files\PrevxCSI\\PrevxCSI.exe" /service (file missing) O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: IPCLAMP by cebas Computer GmbH (IPClampService) - Unknown owner - C:\PROGRA~1\cebas\ip-clamp\ipclamp.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe makni - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe O23 - Service: WinFast(R) Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe našao sam ovdje samo jednu stavku koja bi mogla biti tvoje rješenje, ali sumnjam u to nekako neznam da je to baš to rješenje. Ovdje OBAVEZNO napravi backup prije micanja, jer sam ti pogasio dosta toga, ako će ti faliti nekaj kaj je prije bilo A DA TI TREBA reci da to vratimo OK ? |
08.04.2008., 14:56 | #9 |
Premium
Datum registracije: Dec 2005
Lokacija: Zagreb (centar)
Postovi: 190
|
a kak to micem? sta trebam napravit da to maknem? kliknem na fix u hijacku? EDIT: i kak napravim backup? sorry, nikad to nisam radio pa nemam pojma kaj tocno trebam napravit Zadnje izmijenjeno od: domy_os. 08.04.2008. u 16:10. |
08.04.2008., 16:11 | #10 |
EMP moderator
Datum registracije: Apr 2005
Lokacija: Osijek
Postovi: 18,394
|
U samom programu označiš to što ti je rekao night_whisper, a zatim klikneš na Fix. Backup se napravi automatski u onom folderu gdje je spremljen HijackThis. I nemoj slagati više postova za redom nego dodaj u prvi klikom na tipku EDIT.
__________________ "Kako su krojači novog svjetskog poretka uspjeli u tako kratko vrijeme slomiti intelektualne sposobnosti društva, uništiti kritičku svijest i ljudima nametnuti izvrnutu logiku?"
|
|
|
Oglas
|
|
08.04.2008., 16:45 | #11 |
Premium
Datum registracije: Dec 2005
Lokacija: Zagreb (centar)
Postovi: 190
|
evo, probao sam sve kaj ste mi napisali i sve kaj sam nasao preko interneta - i opcije "show hidden files" jos uvijek nema. najbolji uspjeh sam imao sa naredbom 155 sa ovog popisa - http://www.kellys-korner-xp.com/xp_tweaks.htm (mozda nekom drugom pomogne) znaci, privremeno sam uspio vidjeti svoje hidden files, ali te opcije u windowsima jos uvijek nema sad se prestajem baviti tim problemom - imam posla za fax, a za vikend vjerojatno formatriranje hvala svima koji su pokusali pomoci |
|
|
Oglas
|
|
|
|