You may have caught a worm!
This thing is called the "Kido Worm" , "Downadup" and "Conficker." It began in Oct. 2008 but in December it evolved into a Superworm. Its ability to thwart any attempt to delete it and to spread via USB devices is confounding.
There is a lot of info out there if you Google these names. It is an interesting Worm as it seems to disable every defense before the victim can even launch a counter attack. It disables system restore, shuts off Microsoft updates, blocks Antivirus updates, hijacks the browser (Safari, Explorer, Chrome and Firefox) and finally it downloads more malicious software as it goes. It is impossible to give one set of instructions to remove the Virus as it is different on every machine.
The latest variant of the worm now lets it spread via thumb drives. It operates by copying itself in a random folder created inside the Recycler directory, which is used by the Recycle Bin to store deleted files, and creating an autorun.inf file in the root folder. The worm executes automatically if the Autorun feature is enabled.
Certain TCP functions are also patched to block access to security-related Web sites by filtering every address that contains certain strings. This makes it harder to remove because information about it is difficult to gather from an infected computer. Additionally, the sneaky little worm removes all access rights of the user, except execute and directory usage, to protect its file. Microsoft has created a removal tool for this worm, but if you are infected you must find an uninfected computer to download Microsoft's Malicious Software Removal Tool.
See the following link:
http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx
If you have the Kido/Conficker worm you will no be able to link to the above link.
Microsoft states,
"If your computer is infected with the Conficker worm, you might be unable to download certain security products, such as the Microsoft Malicious Software Removal Tool or to access certain Web sites, such as Microsoft Update. If you can't access those tools, try using the Windows Live OneCare Safety Scanner. If that doesn't work, read the following Microsoft Help and Support articles on an uninfected computer. "
My advise is to get the removal tool on a brand new/clean USB device from another computer and then load it onto your computer. The surprising thing is that this thing started in Oct. and already has infected 12.9 million computers. Microsoft has offered a 250K reward to help catch the culprits that created this worm.
Hope this helps,
Keifer
Cheers YD
Thanx for the help it worked and now i dont have to format my hard drive
i did all that what have u said but the problem remains same
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
The checked value was REG_DWORD 0X00000000 (0)
There is no Value which you have told to change.
now tell me what to do
I still face the same problem
Regards
Ganesh
I used the checkedvalue thing and modified the decimal to 1. from 0.
Thanks
The Reg-Edit DWOOD Value 1 Scenario
Worked 100% Fine For Me,
Don't Forget To Run A Full Virus Scan First And After On Both Your Computer AND Any Necessary USB Flash Sticks Especially If You Are Dealing With The Kido-Worm Virus As Described Above By Keifermail And I Would Suggest You Follow He's Suggested Hyperlink
Thanks MCG And Thanks Keifermail
it won't allow me to delete the "CheckedValue" string. i can creat another dword....but i can't name it accordingly because it won't delete the string.
what am i doing wrong? i even disabled the "prevent access to registry editing tools"......
I got conficker worm on my pc and all of my website file (the SQL database) were stored in a hidden folder, this worm also infected my cpanel so I need to re upload all backup files.
Thanks God everything is find so far, thank You, I really appreciate it :)
Now my site is works again.
This site : http://www.2coolhairstyles.com/
won't work and need to rebuild if I don't find the solution here.
Cheers,
Mary Winston
thanks, it solve the problem.
Have a good day and success in your career.
Best!
i tried all this and its still not working..
can u offer any more help?
thnx
You are a GENIUS dude.... Great help. Millions of thanks :)
Also, I had clicked pics from my camera onto a memory card. When I tried transferring them onto to the computer, the photos simply disappeared. This is extremely frustrating and it drives me mad. Is this because of the same kind of virus? Or what? How do I go about fixing this? I would greatly appreciate it if you could help me fix this. Like, you have no idea how relieved I would be to be able to fix it.
Any kind of help is highly appreciated. Thank you.
RestlessMonk, indeed.