why settings automatically change to "Hide protected operation system files"

2

I have BitDefender (With last update) on my Windows-7.

I want to see hidden files, so from Tools > Folder Options > View , I change the settings as below, and click on OK:

enter image description here

But I can't see hidden files. when I double check the Options, I see the settings changed automatically as below :

enter image description here

I know this is a virus-like application! checking by a virus total via ProcessExplorer didn't help :

enter image description here

How can I understand with process is related to this issue?

TheGoodUser

Posted 2014-08-20T09:53:39.610

Reputation: 1 045

1Verify this isn't a bit defender feature – Ramhound – 2014-08-20T10:06:40.287

1Note that when malware hides itself, it is unlikely to use the hidden file attribute, and instead use another more sophisticated form of cloaking. this is what rootkits excel at. – Frank Thomas – 2014-08-20T12:31:05.230

@FrankThomas How can I understand which process is the origin of this auto change setting? – TheGoodUser – 2014-08-20T12:55:23.500

can you change the hidden state using the reg hack here? http://techrena.net/show-hidden-files-and-folders-missing-windows-7/

– Frank Thomas – 2014-08-20T15:42:07.023

Answers

3

Use Process Monitor from Microsoft to see which process is setting the following registry value to 0. Simply run it before enabling the ability to see protect operating system files and then search the output for the below registry key to see which process reverts it back to 0.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden"

In my tests, this does not appear to be a "feature" of BitDefender.

Lawrence

Posted 2014-08-20T09:53:39.610

Reputation: 68

0

It is Bitdefender, more specifically BitDefender Active Virus Control Usermode Filtering Library. Module: avcuf64.dll. Once I've uninstalled BitDefender I was able to set the folder permissions again, so I am 100% sure it was the culprit.

MysterF

Posted 2014-08-20T09:53:39.610

Reputation: 1