Solved

*EMERGENCY* server hit with virus. Need to UNHIDE folders.

Posted on 2013-06-26
4
686 Views
Last Modified: 2013-11-22
freekin virus hit my server. I see a bunch of random files named .exe.  actual files and folders but with extension .exe.  looks like original files and folders are all there but "hidden"

how can I unhide these all at the same time?? still scanning server for viruses.
0
Comment
Question by:Anthony H.
  • 2
4 Comments
 
LVL 26

Accepted Solution

by:
MacroShadow earned 500 total points
Comment Utility
First of all you must remove the virus.

Once you remove the virus and remove the system restrictions imposed by it, follow these instructions to unhide the folders.
1. create a new text document
2. copy and paste the following code:
@ECHO OFF
ECHO Type the drive letter. ONLY the letter.
ECHO ALL FILES ARE GOING TO BE MODIFIED!!!
set /p letter=

ECHO %letter%: selected
taskkill /im explorer.exe /f
ECHO.
ECHO "Modifying files..."
ECHO.

attrib -s -h -a /s /d %letter%:\*.*

ECHO "Process completed."

start explorer %letter%:
taskkill /im cmd.exe /f

Open in new window

3. save the file as repair.bat
4. run and follow the prompts
0
 

Author Comment

by:Anthony H.
Comment Utility
what do you recommend to remove virus. I ran mcafee, super antispyware, and hitmanpro... not finding it. rebuilding itself.
0
 
LVL 26

Expert Comment

by:Thomas Zucker-Scharff
Comment Utility
try using chameleon by malwarebytes (run the svchost.exe file).  Check out the instructions here (even though they are for a different infection).
0
 
LVL 26

Expert Comment

by:MacroShadow
Comment Utility
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
OfficeMate Freezes on login or does not load after login credentials are input.
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now