raksrules
Level N
I have a virus (or something) in one of my lappies. What it does is that whenever we attach any USB device to that laptop, it makes all the folders in that hidden and when i check the folder's properties and try to remove the hidden thing by unchecking it, it is greyed out so i cannot even Unhide it. Not even on a different machine. Additionally it makes duplicate folders (actually link files with folder icon) of the same name which were hidden but they can be seen normally and these folders are nothing but link to the "D:\windows\system32 file (yes file not folder or similar), so any unsuspecting user if would just plug this USB to his machine would see the folders fine but in reality the actual folders are hidden and what he sees are the links to the above mentioned location, so when you click that a command prompt windows opens for a second and disappears.
For now it has affected my ZTE blade's SD card few directories (the ones which were there when i used that laptop before, now i am using another laptop) and my PMP.
For now i can live with it as i am not using that laptop and the USB devices it has affected are not accessed by windows OS and that hidden thing does not matter to the android and my PMP's proprietary OS.
What can i do to remove the hidden property of these folders ?
Doing it through command prompt does not work (using attrib command). Dont remember what error it gave but it does give some error.
The AV check on host machine is futile as it does not detect anything wrong with the system or infected USB drives.
Also wanted to tell that it for some reason does not affect USB HDDs. So i feel that whatever gets detected as REMOVABLE STORAGE it attacks that, Since external HDD is detected as an additional drive, it gets saved probably.
For now it has affected my ZTE blade's SD card few directories (the ones which were there when i used that laptop before, now i am using another laptop) and my PMP.
For now i can live with it as i am not using that laptop and the USB devices it has affected are not accessed by windows OS and that hidden thing does not matter to the android and my PMP's proprietary OS.
What can i do to remove the hidden property of these folders ?
Doing it through command prompt does not work (using attrib command). Dont remember what error it gave but it does give some error.
The AV check on host machine is futile as it does not detect anything wrong with the system or infected USB drives.
Also wanted to tell that it for some reason does not affect USB HDDs. So i feel that whatever gets detected as REMOVABLE STORAGE it attacks that, Since external HDD is detected as an additional drive, it gets saved probably.