Find Files (and Spyware) that are hidden even when Show Hidden Files is enabled

You can set windows to allow you to set, edit, view, and delete hidden files. However, even when you do this, the OS still hides some files from you. Some spyware is now using this technique as well.

You have your computer set to show all hidden files, so you would think that you should actually be able to see all hidden files, right? 

Not exactly. 

Microsoft realizes that there are some files (like files required for booting) that should really, really be hidden from the user. These files will not be displayed even if you have Windows set to show all hidden files. 

The problem with this is that some spyware programs are now using this property to hide their evil from the user. If you can't see it, it's hard to delete it. 

Disclaimer: You can really screw up your system by deleting the wrong files using this technique. Really, really, really. Backup your system before preceding. 

How to see them: 
  • Type this command from a command prompt... 

    attrib /s | findstr SHR
Here's my output: 
A SHR C:\WINDOWS\assembly\Desktop.ini 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\instance_ Personal_32_1033.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_1 .cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_1 0.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_1 1.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_1 2.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_1 3.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_1 4.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_1 5.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_1 6.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_1 7.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_1 8.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_1 9.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_2 .cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_2 0.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_2 1.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_2 2.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_2 3.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_2 4.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_2 5.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_2 6.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_2 7.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_2 8.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_2 9.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_3 .cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_3 0.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_3 1.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_3 2.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_3 3.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_3 4.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_3 5.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_3 6.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_3 7.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_3 8.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_3 9.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_4 .cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_4 0.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_4 1.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_4 2.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_4 3.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_4 4.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_4 5.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_4 6.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_4 7.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_4 8.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_4 9.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_5 .cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_5 0.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_5 1.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_5 2.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_5 3.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_5 4.cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_6 .cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_7 .cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_8 .cab 
SHR C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_9 .cab 
SHR C:\WINDOWS\system32\Restore\filelist.xml 
SHR C:\AVG6DB_F.DAT 
A SHR C:\boot.ini 
A SHR C:\IO.SYS 
A SHR C:\MSDOS.SYS 
A SHR C:\NTDETECT.COM 
A SHR C:\ntldr 



How to Delete Them: 
  • Remember... don't be an idiot. Do not remove one of these files unless you know that it is spyware or a trojan. 

    Here is the command: 
    attrib -r -s -h trojanfilename
    (where trojanfilename = the file you want to delete) 

    For example: 
    attrib -r -s -h c:\windows\system32\ispyonyou.exe 

    This command will not delete it. It will only unhide it so you can delete it through your regular methods.

ليست هناك تعليقات:

إرسال تعليق