questions after an "about:blank" fix

redbeard1

Diamond Member
Dec 12, 2001
3,006
0
0
After pulling my hair out for most of the day, I found this link with instructions on how to find and remove the registry entry and the hidden file from the hard drive.

What threw me was that things could be hidden from view in the registry and on the hard drive. I found the registry entry value using the free registry editor, while regedit couldn't see it. Show all hidden files was turned on, yet I could not see the dll file while I was in windows. It was there at a recovery command prompt however.

I talked with a someone who said that the ability to hide certain things was a feature to protect system files. I was not able to talk with him long enough to see if he knew where I could edit whatever policy to change this "feature". I looked all around in the local and group policy and did not find a fix.

So my question is, what would need to be done to see ALL files, no matter what MS says. It is so irritating that the spyware is using windows security against itself. :|

SecuriTeam
 

redbeard1

Diamond Member
Dec 12, 2001
3,006
0
0
Further searching has turned up something called superhidden files in windows. In this key is an entry for ShowSuperHidden. Any idea what value would you change it to, to enable them to be seen? My non-infected system is set to: 0x000000001 (1)

HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Policies/Explorer/Advanced

Explains how to change
 

redbeard1

Diamond Member
Dec 12, 2001
3,006
0
0
I looked at the registry of the system, and superhidden was enabled. So that still gets back to the question of what can be changed to see even super secret triple probation files.
 

Jeff7

Lifer
Jan 4, 2001
41,596
20
81
Originally posted by: Schadenfroh
Originally posted by: Confusednewbie1552
what's wrong with about:blank?

an evil hijacker CWS variant

Ah, the horrid CoolWebSearch, may its creators burn in hell. I recently cured an infection of this on someone's system - it was an old variant though. CWSHredder found it and got rid of it easily.

Spyware Info Forum link. Those forums have info on how to get rid of CWS. I'll try to find the link that helped me. I needed to download a registry editor called Registrar Lite, so I could rename a hidden registry entry in order to delete it (it is regenerated if you just delete it), then a program called Killbox to forcibly delete the hidden file (which had a randomly generated name) in the Windows folder.
Relevant thread

Interesting link here - programs that bill themselves as spyware removers, when they are themselves spyware/malware. Quite a lengthy list too.