Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hidden Files & Folders


  • Please log in to reply
1 reply to this topic

#1 LionsFanDET

LionsFanDET

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:04 PM

Posted 13 November 2011 - 02:21 PM

I am getting a reoccurring "virus" that occurs every few hours, usually while browsing in Firefox. Spybot detects a change called "upwJQGgCXjxrDJa.exe," but even when I deny the change the problem occurs. Files disappear from the desktop and the Start Menu > All Programs show up empty (Windows 7). A simple system restore and running unhide.exe solves the issue temporarily but it keeps popping up again later. The issue doesn't affect anything else and I can still access programs I have pinned to the taskbar, so I can still browse the internet, I just can't access any of my programs in my start menu. Even in My Documents and other folders, it says "This folder is empty" but like I said, I've been able to get back to them with system restore and unhide. If anyone knows how to stop the situation from happening again, though, let me know.

BC AdBot (Login to Remove)

 


#2 transceiver

transceiver

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Henderson, LA
  • Local time:05:04 PM

Posted 13 November 2011 - 05:21 PM

I ran across a laptop that was having intermittent boot failures. There was a suspicious popup that was supposedly scanning the machine and finding numerous hardware and software problems (that it would fix of course); and the actual antivirus software that was installed would not stay active.

In addition, like you reported, all of the data files were basically set with the "hidden" attribute. As well as the All Programs folders showing up "empty" in the Start Menu (the programs ARE however still in their original locations in c:\Program Files).

I was eventually able to boot into Safe Mode and run Autoruns. Under the logon tab, there was an entry under the key, HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run. The image path was c:\programdata\upwJQGgCXjxrDJa.exe

I deleted the entry and rebooted the machine and was immediately able to run the AV software without any problems. I did a full scan, which removed additional trojan horse viruses. So I'm not sure which behaviors were solely attributed to the "upwJQGgCXjxrDJa.exe" issue.

And at this point there is VERY little information about upwJQGgCXjxrDJa.exe out there.

So I would try running Autoruns and search for any instances of upwJQGgCXjxrDJa.exe and delete them. You can find detailed instructions on how to do this in this post: http://www.bleepingcomputer.com/tutorials/how-to-remove-a-trojan-virus-worm-or-malware/#remove

Hope this helps.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users