| Windows 7: help showing all hidden files from CMD |
02 Apr 2012
|
| | windows 7 home premium 567 posts |
help showing all hidden files from CMD last night i got the S.M.A.R.T Virus. i got it removed ok i think, but now is the fun part, it hides ALL your files. the only reason im typing this now is because i showed hidden files.
is there a way from CMD to unhhide all files that arent meant to be hidden by windows? (meaning i still want things like desktop.ini to stay hidden)
i know there are programs that will do this for you, but i would rather just do it from cmd if possible | My System Specs |
| System Manufacturer/Model Number was an hp, now is modified to mostly an NZXT corsair OS windows 7 home premium CPU amd phenom 2 black ed. 3.4ghz quad core Motherboard AMD am3 24fsb Memory 10 gb DDR3 Graphics Card ATI Radeon 6970 Monitor(s) Displays 3 1920x1080p 23" monitors (eyefinity display) Screen Resolution 5770x1080 Keyboard logitech g15 Mouse cyborg rat7 Case NZXT Phantom Cooling fan Hard Drives 1 750 gb HP 7500 rpm Internet Speed 24434kbps download rate |
02 Apr 2012
|
| | Windows 7 Home Premium 64 Bit 11,308 posts Colorado |
To unhide a file: Start an Elevated Command Prompt and type the following command:
attrib -h "filename"
where filename is the file you want to unhide.
To unhide a directory and all its files within:
attrib /d /s -h "directoryname"
Also, many of these viruses cause the system switch to be applied so a simple -h does not do the trick. You may have to use -h -s instead of just -h | My System Specs | | System Manufacturer/Model Number HP Pavilion e9110t OS Windows 7 Home Premium 64 Bit CPU Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz Motherboard Pegatron IPIEL-LA3 Memory 6.00 GB Hundai HMT125U6BFR8C-H9 Graphics Card ATI Radeon HD 4850 Sound Card Realtek High Definition Audio/ATI High Definition Audio Monitor(s) Displays Acer AL2216W Screen Resolution 1680x1050 Keyboard HP Keyboard Mouse HP Mouse PSU Unknown/installed by HP Case HP generic case Cooling Intel Stock Cooling Hard Drives Hitachi HDP725050GLA360 ATA Device 500 GB Internet Speed Download: 19.15 Mbps Upload: 1.67 Mbps Other Info Network Adapter Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
Network Adapter 802.11n Wireless PCI Express Card LAN Adapter |
02 Apr 2012
|
| | Windows 7 Ultimate 32bit SP1 7,144 posts |
You can also use "Unhide" ( http://download.bleepingcomputer.com/grinler/unhide.exe) (by Grinler)
Once the program has been downloaded, double-click on the Unhide.exe icon on your desktop and allow the program to run. This program will remove the +H, or hidden, attribute from all the files on your hard drives. If there are any files that were purposely hidden by you, you will need to hide them again after this tool is run." | My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Antivirus Avira Internet Security Browser IE 9 Other Info ATI HDMI Audio |
02 Apr 2012
|
| | windows 7 home premium 567 posts |

Quote: Originally Posted by Jacee You can also use "Unhide" ( http://download.bleepingcomputer.com/grinler/unhide.exe) (by Grinler)
Once the program has been downloaded, double-click on the Unhide.exe icon on your desktop and allow the program to run. This program will remove the +H, or hidden, attribute from all the files on your hard drives. If there are any files that were purposely hidden by you, you will need to hide them again after this tool is run." used that a little while ago, still id like to know what scripts they used to acheive this, or of an ini i could make to do this | My System Specs | | System Manufacturer/Model Number was an hp, now is modified to mostly an NZXT corsair OS windows 7 home premium CPU amd phenom 2 black ed. 3.4ghz quad core Motherboard AMD am3 24fsb Memory 10 gb DDR3 Graphics Card ATI Radeon 6970 Monitor(s) Displays 3 1920x1080p 23" monitors (eyefinity display) Screen Resolution 5770x1080 Keyboard logitech g15 Mouse cyborg rat7 Case NZXT Phantom Cooling fan Hard Drives 1 750 gb HP 7500 rpm Internet Speed 24434kbps download rate |
02 Apr 2012
|
| | Windows 7 Ultimate 32bit SP1 7,144 posts |
Well that is the 'developer's' inside secret and we don't discuss scripts or anything else that has to do with detecting or possibly 'outwitting' malware. | My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Antivirus Avira Internet Security Browser IE 9 Other Info ATI HDMI Audio |
02 Apr 2012
|
| | windows 7 home premium 567 posts |

Quote: Originally Posted by Jacee Well that is the 'developer's' inside secret and we don't discuss scripts or anything else that has to do with detecting or possibly 'outwitting' malware.  im sorry? its not outwitting malware, i used to know it, its unhiding files, thats no different than what it has done but in reverse. forget developers inside secrets, thats not maleware, thats an ini, if this where maleware i would have to create a hidden executable or a trojan executable.
its not that hard, when i used to know how to do it, i remember it being a 1 liner, less than 200 characters
edit: nor is it detecting, it is somthing i can drop in cmd, they threw some fancy text in their program, that doesnt make it malware detection, that makes it text that does nothing while the real script is executed | My System Specs | | System Manufacturer/Model Number was an hp, now is modified to mostly an NZXT corsair OS windows 7 home premium CPU amd phenom 2 black ed. 3.4ghz quad core Motherboard AMD am3 24fsb Memory 10 gb DDR3 Graphics Card ATI Radeon 6970 Monitor(s) Displays 3 1920x1080p 23" monitors (eyefinity display) Screen Resolution 5770x1080 Keyboard logitech g15 Mouse cyborg rat7 Case NZXT Phantom Cooling fan Hard Drives 1 750 gb HP 7500 rpm Internet Speed 24434kbps download rate |
02 Apr 2012
|
| | windows 7 home premium 567 posts |

Quote: Originally Posted by writhziden To unhide a file: Start an Elevated Command Prompt and type the following command:
attrib -h "filename"
where filename is the file you want to unhide.
To unhide a directory and all its files within:
attrib /d /s -h "directoryname"
Also, many of these viruses cause the system switch to be applied so a simple -h does not do the trick. You may have to use -h -s instead of just -h thank you, did not see your post at first, ill write that down, that sounds like the command i used origonaly with a previous virus that infected thumb drives | My System Specs | | System Manufacturer/Model Number was an hp, now is modified to mostly an NZXT corsair OS windows 7 home premium CPU amd phenom 2 black ed. 3.4ghz quad core Motherboard AMD am3 24fsb Memory 10 gb DDR3 Graphics Card ATI Radeon 6970 Monitor(s) Displays 3 1920x1080p 23" monitors (eyefinity display) Screen Resolution 5770x1080 Keyboard logitech g15 Mouse cyborg rat7 Case NZXT Phantom Cooling fan Hard Drives 1 750 gb HP 7500 rpm Internet Speed 24434kbps download rate |
03 Apr 2012
|
| | Windows 7 Home Premium 64 Bit 11,308 posts Colorado |
No problem. Glad you remember using it now.  I've used this on a number of systems infected by these types of viruses. The OS Security 2012 virus is the most common of these types. It usually includes having to redo permissions for the users within the Windows files and the users' files, as well. | My System Specs | | System Manufacturer/Model Number HP Pavilion e9110t OS Windows 7 Home Premium 64 Bit CPU Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz Motherboard Pegatron IPIEL-LA3 Memory 6.00 GB Hundai HMT125U6BFR8C-H9 Graphics Card ATI Radeon HD 4850 Sound Card Realtek High Definition Audio/ATI High Definition Audio Monitor(s) Displays Acer AL2216W Screen Resolution 1680x1050 Keyboard HP Keyboard Mouse HP Mouse PSU Unknown/installed by HP Case HP generic case Cooling Intel Stock Cooling Hard Drives Hitachi HDP725050GLA360 ATA Device 500 GB Internet Speed Download: 19.15 Mbps Upload: 1.67 Mbps Other Info Network Adapter Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
Network Adapter 802.11n Wireless PCI Express Card LAN Adapter |
03 Apr 2012
|
| | windows 7 home premium 567 posts |

Quote: Originally Posted by writhziden No problem. Glad you remember using it now.  I've used this on a number of systems infected by these types of viruses. The OS Security 2012 virus is the most common of these types. It usually includes having to redo permissions for the users within the Windows files and the users' files, as well. good to know, thank you again, supprisingly, right as i was getting ridof the virrus, someone else on here got it, so imm gunna try and help them, and recomend this command, i trust knowing what im doing more than some random exe by someone with no name. | My System Specs | | System Manufacturer/Model Number was an hp, now is modified to mostly an NZXT corsair OS windows 7 home premium CPU amd phenom 2 black ed. 3.4ghz quad core Motherboard AMD am3 24fsb Memory 10 gb DDR3 Graphics Card ATI Radeon 6970 Monitor(s) Displays 3 1920x1080p 23" monitors (eyefinity display) Screen Resolution 5770x1080 Keyboard logitech g15 Mouse cyborg rat7 Case NZXT Phantom Cooling fan Hard Drives 1 750 gb HP 7500 rpm Internet Speed 24434kbps download rate |
03 Apr 2012
|
| | Windows 7 Home Premium 64 Bit 11,308 posts Colorado |
There is an unhide tool used by GFI, who owns the VIPRE Antivirus and Internet Security 2012 software. That's at least by a known company who produces security software. Fakerean removal tool | My System Specs | | System Manufacturer/Model Number HP Pavilion e9110t OS Windows 7 Home Premium 64 Bit CPU Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz Motherboard Pegatron IPIEL-LA3 Memory 6.00 GB Hundai HMT125U6BFR8C-H9 Graphics Card ATI Radeon HD 4850 Sound Card Realtek High Definition Audio/ATI High Definition Audio Monitor(s) Displays Acer AL2216W Screen Resolution 1680x1050 Keyboard HP Keyboard Mouse HP Mouse PSU Unknown/installed by HP Case HP generic case Cooling Intel Stock Cooling Hard Drives Hitachi HDP725050GLA360 ATA Device 500 GB Internet Speed Download: 19.15 Mbps Upload: 1.67 Mbps Other Info Network Adapter Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
Network Adapter 802.11n Wireless PCI Express Card LAN Adapter help showing all hidden files from CMD problems? All times are GMT -5. The time now is 07:06 AM. | |