help showing all hidden files from CMD

Thornton

New member
Power User
Local time
4:17 AM
Messages
597
Location
Orlando Florida
last night i got the S.M.A.R.T Virus. i got it removed ok i think, but now is the fun part, it hides ALL your files. the only reason im typing this now is because i showed hidden files.
is there a way from CMD to unhhide all files that arent meant to be hidden by windows? (meaning i still want things like desktop.ini to stay hidden)

i know there are programs that will do this for you, but i would rather just do it from cmd if possible
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
windows 7 Professional
CPU
Intel I7 4790k
Motherboard
ASUS Hero VII
Memory
16gb DDR3 1600mhz
Graphics Card(s)
Dual GTX 780 ASUS
Monitor(s) Displays
2x HP 2331
Screen Resolution
1080p
Hard Drives
750gb Hitachi 7200rpm
500gb Crucial SSD
PSU
Corsair 800g
Case
NZXT Phantom
Cooling
fan
Keyboard
Razer Deathstalker
Mouse
Razer Ouroboros
Internet Speed
70mbps
Antivirus
MSE + M-Bam
Browser
Chrome
To unhide a file: Start an http://www.sevenforums.com/tutorials/783-elevated-command-prompt.html and type the following command:

attrib -h "filename"​
where filename is the file you want to unhide.
To unhide a directory and all its files within:

attrib /d /s -h "directoryname"​


Also, many of these viruses cause the system switch to be applied so a simple -h does not do the trick. You may have to use -h -s instead of just -h
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion e9110t
OS
Windows 7 Home Premium 64 Bit
CPU
Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz
Motherboard
Pegatron IPIEL-LA3
Memory
6.00 GB Hundai HMT125U6BFR8C-H9
Graphics Card(s)
ATI Radeon HD 4850
Sound Card
Realtek High Definition Audio/ATI High Definition Audio
Monitor(s) Displays
Acer AL2216W
Screen Resolution
1680x1050
Hard Drives
Hitachi HDP725050GLA360 ATA Device 500 GB
PSU
Unknown/installed by HP
Case
HP generic case
Cooling
Intel Stock Cooling
Keyboard
HP Keyboard
Mouse
HP Mouse
Internet Speed
Download: 19.15 Mbps Upload: 1.67 Mbps
Other Info
Network Adapter Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
Network Adapter 802.11n Wireless PCI Express Card LAN Adapter
You can also use "Unhide" (http://download.bleepingcomputer.com/grinler/unhide.exe) (by Grinler)
Once the program has been downloaded, double-click on the Unhide.exe icon on your desktop and allow the program to run. This program will remove the +H, or hidden, attribute from all the files on your hard drives. If there are any files that were purposely hidden by you, you will need to hide them again after this tool is run."
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
You can also use "Unhide" (http://download.bleepingcomputer.com/grinler/unhide.exe) (by Grinler)
Once the program has been downloaded, double-click on the Unhide.exe icon on your desktop and allow the program to run. This program will remove the +H, or hidden, attribute from all the files on your hard drives. If there are any files that were purposely hidden by you, you will need to hide them again after this tool is run."
used that a little while ago, still id like to know what scripts they used to acheive this, or of an ini i could make to do this
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
windows 7 Professional
CPU
Intel I7 4790k
Motherboard
ASUS Hero VII
Memory
16gb DDR3 1600mhz
Graphics Card(s)
Dual GTX 780 ASUS
Monitor(s) Displays
2x HP 2331
Screen Resolution
1080p
Hard Drives
750gb Hitachi 7200rpm
500gb Crucial SSD
PSU
Corsair 800g
Case
NZXT Phantom
Cooling
fan
Keyboard
Razer Deathstalker
Mouse
Razer Ouroboros
Internet Speed
70mbps
Antivirus
MSE + M-Bam
Browser
Chrome
Well that is the 'developer's' inside secret and we don't discuss scripts or anything else that has to do with detecting or possibly 'outwitting' malware. :p
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Well that is the 'developer's' inside secret and we don't discuss scripts or anything else that has to do with detecting or possibly 'outwitting' malware. :p
im sorry? its not outwitting malware, i used to know it, its unhiding files, thats no different than what it has done but in reverse. forget developers inside secrets, thats not maleware, thats an ini, if this where maleware i would have to create a hidden executable or a trojan executable.

its not that hard, when i used to know how to do it, i remember it being a 1 liner, less than 200 characters

edit: nor is it detecting, it is somthing i can drop in cmd, they threw some fancy text in their program, that doesnt make it malware detection, that makes it text that does nothing while the real script is executed
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
windows 7 Professional
CPU
Intel I7 4790k
Motherboard
ASUS Hero VII
Memory
16gb DDR3 1600mhz
Graphics Card(s)
Dual GTX 780 ASUS
Monitor(s) Displays
2x HP 2331
Screen Resolution
1080p
Hard Drives
750gb Hitachi 7200rpm
500gb Crucial SSD
PSU
Corsair 800g
Case
NZXT Phantom
Cooling
fan
Keyboard
Razer Deathstalker
Mouse
Razer Ouroboros
Internet Speed
70mbps
Antivirus
MSE + M-Bam
Browser
Chrome
To unhide a file: Start an http://www.sevenforums.com/tutorials/783-elevated-command-prompt.html and type the following command:

attrib -h "filename"​
where filename is the file you want to unhide.
To unhide a directory and all its files within:

attrib /d /s -h "directoryname"​
Also, many of these viruses cause the system switch to be applied so a simple -h does not do the trick. You may have to use -h -s instead of just -h
thank you, did not see your post at first, ill write that down, that sounds like the command i used origonaly with a previous virus that infected thumb drives
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
windows 7 Professional
CPU
Intel I7 4790k
Motherboard
ASUS Hero VII
Memory
16gb DDR3 1600mhz
Graphics Card(s)
Dual GTX 780 ASUS
Monitor(s) Displays
2x HP 2331
Screen Resolution
1080p
Hard Drives
750gb Hitachi 7200rpm
500gb Crucial SSD
PSU
Corsair 800g
Case
NZXT Phantom
Cooling
fan
Keyboard
Razer Deathstalker
Mouse
Razer Ouroboros
Internet Speed
70mbps
Antivirus
MSE + M-Bam
Browser
Chrome
No problem. Glad you remember using it now. :) I've used this on a number of systems infected by these types of viruses. The OS Security 2012 virus is the most common of these types. It usually includes having to redo permissions for the users within the Windows files and the users' files, as well.
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion e9110t
OS
Windows 7 Home Premium 64 Bit
CPU
Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz
Motherboard
Pegatron IPIEL-LA3
Memory
6.00 GB Hundai HMT125U6BFR8C-H9
Graphics Card(s)
ATI Radeon HD 4850
Sound Card
Realtek High Definition Audio/ATI High Definition Audio
Monitor(s) Displays
Acer AL2216W
Screen Resolution
1680x1050
Hard Drives
Hitachi HDP725050GLA360 ATA Device 500 GB
PSU
Unknown/installed by HP
Case
HP generic case
Cooling
Intel Stock Cooling
Keyboard
HP Keyboard
Mouse
HP Mouse
Internet Speed
Download: 19.15 Mbps Upload: 1.67 Mbps
Other Info
Network Adapter Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
Network Adapter 802.11n Wireless PCI Express Card LAN Adapter
No problem. Glad you remember using it now. :) I've used this on a number of systems infected by these types of viruses. The OS Security 2012 virus is the most common of these types. It usually includes having to redo permissions for the users within the Windows files and the users' files, as well.
good to know, thank you again, supprisingly, right as i was getting ridof the virrus, someone else on here got it, so imm gunna try and help them, and recomend this command, i trust knowing what im doing more than some random exe by someone with no name.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
windows 7 Professional
CPU
Intel I7 4790k
Motherboard
ASUS Hero VII
Memory
16gb DDR3 1600mhz
Graphics Card(s)
Dual GTX 780 ASUS
Monitor(s) Displays
2x HP 2331
Screen Resolution
1080p
Hard Drives
750gb Hitachi 7200rpm
500gb Crucial SSD
PSU
Corsair 800g
Case
NZXT Phantom
Cooling
fan
Keyboard
Razer Deathstalker
Mouse
Razer Ouroboros
Internet Speed
70mbps
Antivirus
MSE + M-Bam
Browser
Chrome
There is an unhide tool used by GFI, who owns the VIPRE Antivirus and Internet Security 2012 software. That's at least by a known company who produces security software. Fakerean removal tool
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion e9110t
OS
Windows 7 Home Premium 64 Bit
CPU
Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz
Motherboard
Pegatron IPIEL-LA3
Memory
6.00 GB Hundai HMT125U6BFR8C-H9
Graphics Card(s)
ATI Radeon HD 4850
Sound Card
Realtek High Definition Audio/ATI High Definition Audio
Monitor(s) Displays
Acer AL2216W
Screen Resolution
1680x1050
Hard Drives
Hitachi HDP725050GLA360 ATA Device 500 GB
PSU
Unknown/installed by HP
Case
HP generic case
Cooling
Intel Stock Cooling
Keyboard
HP Keyboard
Mouse
HP Mouse
Internet Speed
Download: 19.15 Mbps Upload: 1.67 Mbps
Other Info
Network Adapter Realtek RTL8168D/8111D Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
Network Adapter 802.11n Wireless PCI Express Card LAN Adapter
There is an unhide tool used by GFI, who owns the VIPRE Antivirus and Internet Security 2012 software. That's at least by a known company who produces security software. Fakerean removal tool
thats good, ill remember that also if in future cases this does not work
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
windows 7 Professional
CPU
Intel I7 4790k
Motherboard
ASUS Hero VII
Memory
16gb DDR3 1600mhz
Graphics Card(s)
Dual GTX 780 ASUS
Monitor(s) Displays
2x HP 2331
Screen Resolution
1080p
Hard Drives
750gb Hitachi 7200rpm
500gb Crucial SSD
PSU
Corsair 800g
Case
NZXT Phantom
Cooling
fan
Keyboard
Razer Deathstalker
Mouse
Razer Ouroboros
Internet Speed
70mbps
Antivirus
MSE + M-Bam
Browser
Chrome

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Acer Aspire 5750G
OS
Windows 7 Home Premium x64, Windows 8 Pro
CPU
i5-2430M
Motherboard
Acer JE50_HR
Memory
8 Gb
Graphics Card(s)
nVidia GeForce 610M
Sound Card
Realtek High Definition Audio
Antivirus
Avast
Browser
Chrome

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
windows 7 Professional
CPU
Intel I7 4790k
Motherboard
ASUS Hero VII
Memory
16gb DDR3 1600mhz
Graphics Card(s)
Dual GTX 780 ASUS
Monitor(s) Displays
2x HP 2331
Screen Resolution
1080p
Hard Drives
750gb Hitachi 7200rpm
500gb Crucial SSD
PSU
Corsair 800g
Case
NZXT Phantom
Cooling
fan
Keyboard
Razer Deathstalker
Mouse
Razer Ouroboros
Internet Speed
70mbps
Antivirus
MSE + M-Bam
Browser
Chrome
Back
Top