Computers & Internet Logo
Anonymous Posted on Jul 20, 2013

Hidden Folder virus in PC not in USB

Now a day I am having a virus issue at user end that is about " Blank named Folder " it is a virus. People say it is a shortcut virus but in this case i found nothing in Pen drive but it shows... it is full. some how it fixed by this command " E:\attrib -a -s -r -h /s /d " but this is all about in pen drive. I want to ask the issue is.. however i remove the virus from pen drive by formatting or by using attribute command, but when i insert this in an infected PC it goes blank. now I want the solution to remove it from PC because in my organization a large number of PC's are infected by this virus. it always attack on USB. Mass Storage.

2 Answers

Eranda Gunathilaka

Level 1:

An expert who has achieved level 1.

MVP:

An expert that got 5 achievements.

Governor:

An expert whose answer got voted for 20 times.

Cheetah:

An expert who has answered 20 or more questions within one hour.

  • Contributor 36 Answers
  • Posted on Oct 19, 2014
Eranda Gunathilaka
Contributor
Level 1:

An expert who has achieved level 1.

MVP:

An expert that got 5 achievements.

Governor:

An expert whose answer got voted for 20 times.

Cheetah:

An expert who has answered 20 or more questions within one hour.

Joined: May 20, 2011
Answers
36
Questions
0
Helped
33766
Points
78

I have faced same problem. Shortcuts everywhere.

Not once, many times.

I tried many solutions.

Shortcut Virus Remover is the best solution I found.

A 100% free simple application.

You can download it from this link - Shortcut Virus Remover

Place it in your pen drive and double click to run.
Press Enter to confirm its process.
That is all.

Shortcuts will remove and your data will be back in a second.

Brian Sullivan

Level 3:

An expert who has achieved level 3 by getting 1000 points

Superstar:

An expert that got 20 achievements.

All-Star:

An expert that got 10 achievements.

MVP:

An expert that got 5 achievements.

  • Microsoft Master 27,725 Answers
  • Posted on Jul 22, 2013
Brian Sullivan
Microsoft Master
Level 3:

An expert who has achieved level 3 by getting 1000 points

Superstar:

An expert that got 20 achievements.

All-Star:

An expert that got 10 achievements.

MVP:

An expert that got 5 achievements.

Joined: Jul 19, 2010
Answers
27725
Questions
1
Helped
5665211
Points
79191

Windows PC Defender is designed to look like anti-virus or anti-spyware software from Microsoft, but it is actually a virus.
Windows PC Defender pretends to scan the computer for infections, displays a fake results log, then demands you to purchase the full program to fix the "detected" viruses.
Although the program claims to be an anti-virus program, it actually blocks real anti-virus programs from removing Windows PC Defender.
It also hijacks all program icons so that you can't launch your real anti-virus software or any other program.
If your PC is infected with the Windows PC Defender virus and you can't run your anti-virus or anti-malware software, you can remove the infection manually.

Turn on or restart the computer and press "F8" on the boot screen to open the Windows Advanced Boot Options menu.
Scroll to "Safe Mode" and press Enter.
Sign in to Windows. Hold down "Ctrl-Shift-Esc" to open Windows Task Manager.
Click the "Processes" tab.


Click "Image Name" to alphabetize the processes. Right-click "eb.exe."
Select "End Process" from the menu. Click "End Process" again.

Repeat the above step for fix.exe, ppal.exe and WP345d.exe.
Click "File." Click "New Task" to open the "Run" window.
Type "cmd" and press "Enter" to open a command-line window.

Type "cd c:\windows\system32" at the command-line prompt.
Press "Enter."
Type "regsvr32 -u mozcrt19.dll" and press "Enter" to unregister the Windows PC Defender dynamic linking library.

Repeat the process for sqlite3.dll, cid.dll and ddv.dll.
Type "cd %userprofile%\recent" at the command prompt and press Enter.
Unregister tempdoc.dll.
Close the command-prompt window.

Reopen the "Run" box. Type in "regedit" or "regedit.exe."
Press Enter to open Windows Registry Editor.

Navigate through the "HKEY_CLASSES_ROOT" and "CLSID" paths.
Right-click "{3F2BBC05-40DF-11D2-9455-00104BC936FF}." Click "Delete."
Click "Yes" to confirm.

Return to "HKEY_CLASSES_ROOT."
Right-click "WP345d.DocHostUIHandler" and click "Delete."
Click "Yes" to confirm the deletion.

Go through "HKEY_USERS ' .DEFAULT ' Software' Microsoft' Internet Explorer." Click "SearchScopes."
Right-click "URL," which has the value of "http://search-gala.com/?&uid=201&q={searchTerms," and click "Delete."
Click "Yes" to confirm the deletion.

Return to "Internet Explorer." Right-click "PRS," which has the value of "http://127.0.0.1:27777/?inj=%ORIGINAL%."

Click "Delete." Click "Yes."

Go to "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings." Find and delete "UID" with the "201" value.
Click "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform." Delete "89770891803."
Open "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run."
Delete "Windows PC Defender."

Click the Start button at the bottom left of your monitor screen.
Click "Computer."
Enter "8424.mof" into the search bar and wait for the computer to locate the file.
When the file appears in the results, right-click it, then click "Delete."
Click "Yes."

Repeat the process for the following files associated with Windows PC Defender: exec.tmp, mozcrt19.dll, CLSV.tmp, fix.exe, search.xml, ddv.dll, eb.exe, sqlite3.dll, tempdoc.dll, WP345d.exe, runddlkey.drv, WPCD.ico, ppal.exe, wpcd.cfg, energy.sys, vd952342.bd, cookies.sqlite, Windows PC Defender.lnk, PE.drv, cid.dll, eb.sys, FS.drv, Instructions.ini, kernel32.drv and PE.tmp.
Go to "C:\Documents and Settings\All Users\Application Data."
Delete the following folders: "3adffe," "WPCDSys" and "345d567."

Type "%userprofile%\application data" into the address bar and press Enter.
Right-click "Windows PC Defender" then click "Delete."
Click "Yes" to completely remove the Windows PC Defender virus from your computer.
Restart your computer.



http://www.2-spyware.com/remove-windows-pc-defender.html

Ad

2 Related Answers

Gav Shaw

  • 162 Answers
  • Posted on Dec 10, 2008

SOURCE: PC incompatable to antivirus and adobe reader

Download  a progran called Anti-Malware from www.Malwarebytes.org

Ad

Anonymous

  • 158 Answers
  • Posted on Mar 12, 2009

SOURCE: Regarding usb drivers

Install the chipset drivers from your motherboard cd or from net
i.e. http://h10025.www1.hp.com/ewfrf/wc/softwareCategory?lc=en&dlc=en&cc=us&lang=en&product=3814517&#

Add Your Answer

×

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

1helpful
1answer

Only EULA files will show

Your Drive is Infected with the Virus and your all files and folder are Hidden now by the Virus. So First thing I'll Suggest you to Scan your Drive with Good Antivirus which is Updated one. After Scan To view the Files and Folder you need to enable Show Hidden File and Folder and enable Hide Protected Files and Folder Option.from Folder OPtion
8_11_2012_11_10_50_am.jpg
tip

How to remove Autorun.inf Virus ?

Manual way:
1.) Open Notepad and do not write anything in it. Go to File > Save as autorun.inf
2.) Copy the blank autorun.inf file that you have created in the above step and paste it in your "Pen Drives"
3.) Remove your pendrive.
4.) Re-insert your PC. Now your pendrive is safe to use.
Automatic way:
1.) Download Panda USB Vaccine which allows users to vaccinate their PCs in order to disable autorun completely so that no program from any USB/CD/DVD drive can auto-execute.
2.) Download Flash_Disinfector.exe and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone.
  • Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Flash Disinfector will remove any autorun.inf files; create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection
on Oct 29, 2010 • Computers & Internet
0helpful
1answer

I have a problem with word normal.dot, I think normal.dot file is corrupted is this possible by a virus ?

1. Double click on My Computer.

2. Click on the Tools menu in the top menu bar.

3. Click on Folder Options...

4. Click on the View Tab

5. Click on the little button next to "Show hidden files and folders" (in the Advanced Settings box)

6. Click OK.

7. Double click on Local Disk (C:)

8. Double click on the Documents and Settings folder

9. Double click on the folder with your user name

10. Double click on Application Data. (That folder will be dimmed)

11. Double click on the Microsoft folder.

12. Double click on the Templates folder.

13. Right click on the Normal.dot file and delete it

14. Now you need to hide your hidden folders again

15. Click on the Tools menu in the top menu bar.

16. Click on Folder Options...

17. Click on the View tab.

18. Click on the little button next to "Do not show hidden files and folders" (in the Advanced Settings box)

19. Click on OK.

20. Close all the open windows and you are done!
Every time you open Microsoft Word, you go to a blank page. That blank page is called Normal.dot. If you ever open Microsoft Word, and you don't get a blank page, then your Normal.dot file has somehow been changed. If you have this problem, follow these steps


0helpful
1answer

Folder dissapear only some open file are ther and drive show 80 % full

Most probably your PC & external HDD is infected with dangerous objects/files eg. virus, malwares, etc... which resulted your folders & files atributes changed to "hidden".

Do a thorough Virus/Malware scan for the PC & External HDD, to removed the "dangerous object/files"

Refer to this thread how to recover your "hidden" folder/files @ Reset System and Hidden Attributes for Files or Folders Caused by Virus

Hope it helps
0helpful
1answer

My computer recognizes that I have 1.8 GB left on the disk but when I try to download songs it claims that the disk if full. What do I do?

Good day sir/maam, hi, your SD card may be infected by a virus that wont allow anymore software or files to be stored on the disk, run a virus scan on your PC, there is an easy way to check if your PC is infected, to check, on the my computer menu bar click tools, folder options, view, select show hidden files and folder, then apply, close the window, Now go back to the folder option, view and check the show hidden files, its changed. and goes back to not show hidden files. If this happens, download AVG anti virus and scan your computer.
1helpful
2answers

Hidden files are not showing

Hi there.
It sounds like you have a virus on your machine, apart from not being able to view hidden files and folders is there anything else thats going wrong with the PC at all?
for example on start-up do you get any strange error messages or has the recycle bin name been changed?
0helpful
2answers
0helpful
1answer

Hidden files and folder not show.

Most likely, you either have a virus or a domain policy restricting the viewing of hidden files.

Here's an easy fix:
1) Go to Start>Run
2) Type "regedit" and click "OK"
3) Expand to HK_CURRENT_USER>Software>Microsoft>Windows>CurrentVersion>Explorer>Advanced
4) Select the value on the right named "Hidden". Right-click and "Modify".
5) On most virus/policy restricted computers, it will have a value of 2, which it shouldn't because it should only be 0 or 1. Change the value to "1" and click "OK".
6) Refresh whatever window you were working in, and it should show you all the hidden files. It will show for all your windows after that until you go to options to change it.
0helpful
3answers

Show hidden folder problem radio button not selecting

Go to http://www.spybot.net "just copy paste link in your browser"
download it get the up dates and run it in safe mode F8 on start up .that will put ya in 16bit mode.after you run it it will show you thoes folders .DUMP NORTON>if you wish.i dont like it myself.this is a great program trusted by many.give it a run see what ya think. thanxs for useing FIXYA.COM
0helpful
3answers

Not displaying all files while connected as a USb

Your MP3 player is virused. clean virus then and in your pc done : tools-Folder option -view-(mark)show hidden files.. and (unmark) hide extension ... , hide protected... so change hidden folders in your MP3 player
Not finding what you are looking for?

169 views

Ask a Question

Usually answered in minutes!

Top Microsoft Computers & Internet Experts

Grand Canyon Tech
Grand Canyon Tech

Level 3 Expert

3867 Answers

k24674

Level 3 Expert

8093 Answers

Brad Brown

Level 3 Expert

19187 Answers

Are you a Microsoft Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...