To show hidden files, follow these steps:
Under normal circumstances, follow the steps below: Open the "Tools" menu of "My Computer"-"Folder Options", and in the "View" tab, select "show all files and folders" and find "Hide protected operating system files (recommended)" to remove the preceding check box. As shown in:
Solution:
If it is caused by viruses, there are many cases. Here we will talk about the two commonly used methods.
Method 1: Open the Registry Editor and enter the registry key: HKEY_LOCAL_MACHINE \ Software \ Microsoft \ windows \ CurrentVersion \ explorer \ Advanced \ Folder \ Hidden \ SHOWALL. Change the CheckedValue on the right to 1, then set the folder options in the general method.
If no CheckedValue is displayed, right-click the current window of the registry key and create a New DWORD Value named "CheckedValue" (no quotation marks ), double-click it to set its value to 1 (hexadecimal ). If it is not modified, download the registry editing file from here, decompress the file, and double-click it to import the information to the Registry.
Method 2: If none of the above methods works, the virus may have modified other key values of the file display attribute in the registry. Download this file, add the information to the Registry and restore it to the initial settings.
The following is a supplementary solution:
You can see that sys.exe is not infected. The following is a method. even if not, you can remove the hidden file.
Symptom: The system file is hidden and cannot be displayed. If you double-click the drive letter, the task manager finds that sxs.exe or svohost.exe is different from the system process svchost.exe. Anti-Virus Software is automatically disabled and cannot be opened in real time.
I found many methods on the Internet and could not delete them effectively, and there was no exclusive tool.
Manually delete the sxs.exe virus:
First, you need to display the hidden system files (this is why the hidden files are not displayed even, NND, and the registry is changed)
Run -- regedit
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ windows \ CurrentVersion \ explorer \ Advanced \ Folder \ Hidden \ SHOWALL, change the CheckedValue to 1
But it may not be used. The hidden file is not displayed because the virus deletes the valid DWORD Value CheckedValue after modifying the Registry to hide the file, an invalid string value CheckedValue is created, and the key value is changed to 0!
Method: Delete the CheckedValue, right-click New -- Dword Value -- name it CheckedValue, and modify its key value to 1, in this way, you can select "show all hidden files" and "Show System Files ".
Right-click the partition disk and choose "open" (you must right-click it to open it). You can delete the autorun. inf and sxs.exe files in each disk and directory. (You must delete each disk, or else you will be busy)
(It may be automatically generated after deletion. Therefore, you must first Delete the sxs.exe or svohost.exe process in the task manager)
Open the registry and run -- regedit
HKEY_LOCAL_MACHINE> SOFTWARE> Microsoft> Windows> CurrentVersion> Run
The SoundMam key value is found. There may be two. Delete the value C: \ WINDOWS \ system32 \ SVOHOST.exe, and finally to C: \ WINDOWS \ system32 \ directory to delete SVOHOST.exe (hidden)
After restarting the computer, we found that the anti-virus software can be opened, and the partition disk can be opened by double-clicking. Everything is normal!
Method 2
Copy the following content to notepad. Save the file and change it to REG. Double-click it.
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ Hidden \ SHOWALL]
"RegPath" = "Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced"
& Quot; Text & quot; = & quot; @ shell32.dll,-30500 & quot"
"Type" = "radio"
"CheckedValue" = dword: 00000001
The above two are the most common methods. If not, use method 2 to try the following:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ Hidden]
& Quot; Text & quot; = & quot; @ shell32.dll,-30499 & quot"
"Type" = "group"
"Bitmap" = hex (2): 25, 00, 53,00, 79,00, 00, 00, 6f, 00 ,\
, 25, 00, 5c, 79, 00, 00, 6d, 00, 00, 5c, 00 ,\
, 4c, 00, 4c, 00, 00, 2e, 00, 6c, 00, 00, 2c ,\
00
"HelpID" = "shell. hlp #51131"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ Hidden \ NOHIDDEN]
"RegPath" = "Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced"
& Quot; Text & quot; = & quot; @ shell32.dll,-30501 & quot"
"Type" = "radio"
"CheckedValue" = dword: 00000002
"ValueName" = "Hidden"
"DefaultValue" = dword: 00000002
"HKeyRoot" = dword: 80000001
"HelpID" = "shell. hlp #51104"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ Hidden \ SHOWALL] "RegPath" = "Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ \ Advanced"
& Quot; Text & quot; = & quot; @ shell32.dll,-30500 & quot"
"Type" = "radio"
"ValueName" = "Hidden"
"DefaultValue" = dword: 00000002
"HKeyRoot" = dword: 80000001
"HelpID" = "shell. hlp #51105"
"Checkedvalue" = dword: 00000001
Method 3
Copy HKEY_LOCAL_MACHINE \ Software \ Microsoft \ windows \ CurrentVersion \ explorer \ Advanced \ Folder \ Hidden to your computer and double-click it.
Method: Start-> Run-> regedit-> HKEY_LOCAL_MACHINE \ Software \ Microsoft \ windows \ CurrentVersion \ explorer \ Advanced \ Folder \ Hidden right-click Hidden-> export ,, copy the exported file to your computer and double-click
Hey, this method is the same as method 2. Why? Hey hey, write more, cheat the landlord's sympathy, give a flag, and then show it to the children who just bought a computer.
Why cannot I show hidden files in Win7?
Symptom Description: Open the folder and there is no way to display the hidden files. Click tool-Folder option-to view all the files with no effect. The hidden files are not displayed at all.
The original intention of this problem may be that the computer was infected with a virus and the Registry was modified.
Solution:
Create a new notepad file and copy the following content to it:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion
\ Explorer \ Advanced \ Folder \ Hidden \ SHOWALL]
CheckedValue = dword: 00000001
Name the file name to show the hidden file. REG.
The file name can be retrieved at will, but the suffix must be changed to. reg.
If you cannot display the file suffix, click the folder tool file option to hide the known file extension.
Solve the problem that hidden files cannot be displayed in all files and folders.
Which Trojan may be contained in the hacker. It is still possible that the Registry is changed to hide its identity.
Click the "run" command in the "Start" menu, type regedit in the pop-up dialog box to open the registry, and find HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \
CurrentVersion \ explorer \ Advanced \ Folder \ Hidden \ here there are two primary keys: NOHIDDEN and SHOWALL (windows2000 ). There is a binary key value CheckedValue under SHOWALL, and its key value is changed to "0". It turns out so! After I changed it to 1, I thought it was OK, and the result still exists.
Change the CheckedValue of NOHIDDEN to 1, and change the CheckedValue of SHOWALL to 0. If it is clicked, it will not be hidden ...... After you press OK, all the hidden folders are displayed, and then all the folders are displayed ...... After confirming, the folder is hidden, which is the opposite of the fact. Although it can be hidden by not displaying ...... Check hidden files, but it is always uncomfortable. There is no default option in the menu. I wonder if it is a windows BUG.
After comparison, I suddenly realized that the original Trojan changed the attribute of the CheckedValue of SHOWALL to REG_SZ instead of REG_DWORD! Therefore, no matter whether the CheckedValue of SHOWALL is = 1 or not, it does not work. After the change, the system returns to normal.
The llm.exe virus is also available on the computer. It was developed by a student from Harbin Institute of Technology. The Network Name of your computer is also changed. Clarity is complicated. The specific methods are as follows.
First, modify the registry:
"Start"-> "run"-> "regedit" to open the Registry Editor.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \
Explorer \ Advanced \ Folder \ Hidden \ SHOWALL]
Delete the "CheckedValue" key. Because the virus has changed its type to "SZ", changing the value to "1" in time cannot be viewed. After deletion, the new key of the "DWORD" type is created. The name is changed to "CheckedValue" and the key value is "1 ".
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ WindowsNT \ CurrentVersion \
Winlogon]
Change the internal userinit.exe key to internal userinit.exe, "(including commas). We can find that there is a" microsoft \ * (garbled cmd.exe "in the content of the key before modification. This file is actually one of the virus files.
Change the "Shell" key content to "EXPLORER. EXE ", then we can find that there is a" C: \ WINDOWS \ system32 \ dllcache \ dcache.exe "in the content of the key before modification. That's right, this file is the second of the virus file.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run]
Delete the "System" key. The key contains "C: \ WINDOWS \ system32 \ advanced.exe", which is the third virus file.
After the registry is modified, go to the System32 folder on drive C, and display the hidden file, system file, and extension. Find the hidden “ced.exe file (44.2kb, no icon). The file cannot be deleted at this time, but you can change the file name to any one, as long as you can find it next time and the file name is not the original one. After that, a new document is created (both new and new versions are available, and its name is changed to advanced.exe "(the extension must be displayed, otherwise it will become “ced.exe.txt), and the attribute will be changed to" read-only "(0 kb, program icon ).
Find the “dlcache.exe file, delete the hidden “dcache.exe file (44.2kb, no icon), return to the parent directory, find the "microsoft" folder, and delete the hidden "* (garbled cmd.exe" file (44.2kb, no icon ).
In this case, go back to the directories and delete the hidden llm.exe (44.2kb, no icon) and autorun. inf files. At this time, the generated llm.exeworkflow file is the same as the previous established advanced.exe (0kb, program icon), that is, there is no harm.
Deleted.
After some viruses are detected, hidden files and folders cannot be displayed!
In any folder, I click "tool" ==>> "folder option... "==>>" View "==>>" show all files and folders "and click" OK "or" Apply "and" OK, the computer still cannot display hidden files and folders. repeat the preceding steps to "tool" ==>> "Folder Options... "==>>" View "found that every time it is automatically changed back to" do not show hidden files and folders "option!
After finding a method on the internet, type "regedit" in "run" to open the Registry Editor, go to "HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ F older \ Hidden \ SHOWALL", change CheckedValue to 1, and restart the system.
I think it may be a virus. I got a Kaspersky Antivirus software and killed it once. It still didn't solve the problem!
I was so depressed that I found this file online to solve my troubles!
Restore to view hidden files. reg. If some netizens have encountered the same problem as me and the above methods have not solved the problem well, download the file I provided below and try again. Unzip it and double-click to import the registry, is the problem solved?
Restore to view hidden files option. reg
Copy codeThe Code is as follows: Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ Hidden]
& Quot; Text & quot; = & quot; @ shell32.dll,-30499 & quot"
"Type" = "group"
"Bitmap" = hex (2): 25, 00, 53,00, 79,00, 00, 00, 6f, 00 ,\
, 25, 00, 5c, 79, 00, 00, 6d, 00, 00, 5c, 00 ,\
, 4c, 00, 4c, 00, 00, 2e, 00, 6c, 00, 00, 2c ,\
00
"HelpID" = "shell. hlp #51131"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ Hidden \ NOHIDDEN]
"RegPath" = "Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced"
& Quot; Text & quot; = & quot; @ shell32.dll,-30501 & quot"
"Type" = "radio"
"CheckedValue" = dword: 00000002
"ValueName" = "Hidden"
"DefaultValue" = dword: 00000002
"HKeyRoot" = dword: 80000001
"HelpID" = "shell. hlp #51104"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ Hidden \ SHOWALL]
"RegPath" = "Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced"
& Quot; Text & quot; = & quot; @ shell32.dll,-30500 & quot"
"Type" = "radio"
"CheckedValue" = dword: 00000001
"ValueName" = "Hidden"
"DefaultValue" = dword: 00000002
"HKeyRoot" = dword: 80000001
"HelpID" = "shell. hlp #51105"
Failed to import *. reg: the specified file is not a registration script.
You can only import binary registration files in the Registry Editor.
This is because the file in the Registry format, Windows Registry Editor Version 5.00 must be in the first line, and there cannot be a blank line above. A blank line is required under Windows Registry Editor Version 5.00. .
As shown in: