isyan profile image

Using command prompt "attrib" to check for Viruses or Malware

Microsoft Command Prompt "attrib" is a very useful tool to check if your hard drives even your flashdisks have been infected by a virus.

You will know if a Malware is inside your hard drive just by looking at the attributes of each files and the file that has the attributes of +s +h +r

The function of attrib is to set and remove file attributes (read-only, archive, system and hidden).

Launch attrib

To start attrib

  1. Go to Start Menu > Run
  2. Type cmd (cmd stands for command prompt)
  3. Press Enter key

The Command Prompt will appear showing us where is our location in the directory.

command prompt showing the current location in the directory
See all 3 photos
command prompt showing the current location in the directory

Using attrib

To use attrib

  1. Go to the root directory first by typing cd\(because this is always the target of Malware / Virus)

2. Type attrib and press Enter key

after typing attrib, all the attributes of all the files (excluding folders) will be shown
See all 3 photos
after typing attrib, all the attributes of all the files (excluding folders) will be shown

In this example, I have two files that are considered as malware.

Note that there are two files which I outlined in red (SilentSoftech.exe and autorun.inf). Since you cannot see this file nor delete it (because the attributes that was set on these files are +s +h +r)

  1. +s - meaning it is a system file (which also means that you cannot delete it just by using the delete command)
  2. +h - means it is hidden (so you cannot delete it)


  3. +r - means it is a read only file ( which also means that you cannot delete it just by using the delete command)


Now we need to set the attributes of autorun.inf to -s -h -r (so that we can manually delete it)

  1. Type attrib -s -h -r autorun.inf ( be sure to include -s -h -r because you cannot change the attributes using only -s or -h or -r alone)
  2. Type attrib again to check if your changes have been commited
  3. If the autorun.inf file has no more attributes, you can now delete it by typing del autorun.inf
  4. Since SilentSoftech.exe is a malware you can remove its attributes by doing step 1 and step 3(just change the filename) ex. attrib -s -h -r silentsoftech.exe


a) I typed the attrib command with the -s -h -r setting b) the result after I pressed enter - autorun.inf has no attributes left
See all 3 photos
a) I typed the attrib command with the -s -h -r setting b) the result after I pressed enter - autorun.inf has no attributes left

There you have it!!!!

NOTE : when autorun.inf keeps coming back even if you already deleted it, be sure to check your Task Manager by pressing CTRL + ALT + DELETE ( a virus is still running as a process thats why you cannot delete it. KILL the process first by selecting it and clicking End Process.

NOTE: You can also apply the attrib -s -h -r command to all the partition of your computer, drive D: drive E: drive F: (all of your drives). For example. for drive D, just type "D:" (minus the double quote) then you can see that your current drive is D.. type there the command "attrib -s -h -r *.exe" for exe files and "attrib -s -h -r *.inf" and then delete the file by "del autorun.inf".

Hope this helps!!!!! :) Jah bles!

NOTE: If you want to have a more detailed information regarding How to delete a virus visit my other hub.. HOW TO DELETE A VIRUS IN YOUR USB/FLASHDISK

 Last updated on July 18, 2011

Useful {84}Funny {17}Awesome {28}Beautiful {13}Interesting {12}

Comments 193 comments

isyan profile image

isyan 5 years ago Hub Author

silentsoftech.exe is a virus.. I used it as an example... Attrib function will not delete a file, it will just set the attributes of a file... In this article I set the attributes of autorun.inf and silentsoftech.exe so that I can delete them using the del function..


alexis 5 years ago

thanks man.. this solved my problem.. :)


aldrn 5 years ago

this solves my problem but still there is one thing i don't get, how would i know if a attribute is a malware or trojans?


isyan profile image

isyan 5 years ago Hub Author

you can check if a file is an OS file or not but googling it... but usually virus has awkward names... :)


heyyo 5 years ago

how would you know if a file shown is infected?


Maple 5 years ago

Thanks so much! (:


pruthvi 5 years ago

thanks dude


Ghie 5 years ago

thanks:


Kirif 5 years ago

Thnks!


Gaz 5 years ago

Carried out all the steps as instructed but after the delete step the prompt page said autorun.inf file could not be found although it was still clearly there and once I typed in attrib the autorun file was back with the SHR attributes. This also happened with another virus/malware m1eqos3.exe which also didnt delete. Please help


isyan profile image

isyan 5 years ago Hub Author

@gaz: there is possible a running malware on your computer that is why when you change or delete the autorun, it will again be restored...

NOTE : when autorun.inf keeps coming back even if you already deleted it, be sure to check your Task Manager by pressing CTRL + ALT + DELETE ( a virus is still running as a process thats why you cannot delete it. KILL the process first by selecting it and clicking End Process.


robert 5 years ago

sir!! i still have my mp4 always formatiing by itself and i always lose my important pics. pls help me


hitesh 5 years ago

it does not remove any viruses

this is one of some silly methods.


pshh 5 years ago

how would i know what is the virus?


Silambu 5 years ago

Thanks!


sheryl 5 years ago

Thanks


isyan profile image

isyan 5 years ago Hub Author

@robert: try to scan your mp4 using kaspersky (update it first)

@hitesh: read the TITLE! it doesn't says remove virus --- we're just checking for it.. and maybe applying some first aid if we can..

@pshh: usually a virus has silly names.. but if you're unsure just google the filename...

@sheryl and silambu: np.. hoe it helps!


sathish 5 years ago

it 's ok ,


shikha 4 years ago

after typing del autorun.inf it is saying it is used by some other process,so can't be deleted


Tracy 4 years ago

Hi isyan,

I am having an issue with Explorer setting all of my folders to Read Only. I try to remove the check and Apply but it comes back.

Will the attrib cmd help?

Vista 64


junax 4 years ago

question:

Does this also make the folder options to come back to its original settings? which means when u have already deleted the virus, can you now access folder options?


Mokaya 4 years ago

Thanx, it works. Those complaining shuld follow tha process carefully.


vci 4 years ago

thank you so much i learned a lot from that.....


Beautypeacock 4 years ago

Yes This informaation is very useful to me.

And by this way we can create undetected virus.

If anybody want more information contact me at beautypeacock@gmail.com


S.P.Venkatesh Mani 4 years ago

this gives very usefull ideas thanks alot


allan 4 years ago

very good!

very helpful


tot 4 years ago

good simple to do


LyNn 4 years ago

i found 3 with SHR

bootmgr

io sys

ms dos

i see io sys and ms dos in yours too but you did not circle it in red, therefore i believe that this these two arent virus/malware/trojan

but what about bootmgr?


Harish Verma 4 years ago

It realy Work! It solved My problem.

Thanks!


maning 4 years ago

salamat sa information heehehe tanks karajaw gajud


arun pathania 4 years ago

this method..is very good....thanxxxxx


Jenilo 4 years ago

yAh dat was great i think i can now delete virus easily.. thanks for posting duds


softboy 4 years ago

perfect!

tyvm from PORTUGAL !

tiagosousa999@hotmail.com


Rgonz 4 years ago

Hey i am clean...No virus found..THANKS :D


donkz 4 years ago

hi.. i want to follow ur instructions but... wen i type the cmd and press the enter key... my computer shut downed...

is there any other way to removed the virus in comp? please help...


sahan!@# 4 years ago

how do u delete it

i need the steps!!


mayuri 4 years ago

thnks a lot.. i hope i dont see the viruses again..

u explained it v. well..


hammad ansaru 4 years ago

i have got two virus programms in my usb and i can see them using attrib. but i am unable to change their attribute and i get a message "Not resettig hidden file lemisha.exe"

and "Not resetting hidden file deutrovioce.exe"

any suggestions please?


isyan profile image

isyan 4 years ago Hub Author

@hammad ansaru: pls read the last part where you have to disable a malicious process running in your computer

@mayuri: thanks and i hope it helped you

@sahan:pls read and understand the instructions carefully because deleting it is included in my post.. :)


narico1025 4 years ago

thank you!!! it works...


Charaze 4 years ago

It worked! Now, my laptop is working just fine. I'll try to delete other viruses of my other accounts. Thanks for the info!


herwin 4 years ago

thank you so much!


much 4 years ago

sir how to delete an RVHOST.exe in command prompt?im recently using win7..the system doesn't start..so im using safe mode with command prompt trying to delete the virus..please help me thanks..


axel 4 years ago

this command "attrib" is very usseful and I tried it a few times but there's one thing that I'm not sure about. I restored one virus detected by AVG Int. Sec 9 and than command "attrib" couldn't find it on my system. Why and how to do that? Virus was smth. like Trojan horse Generic...thx


MM 4 years ago

i typed it in and it comes up with 'A SH'

O_O

what does that mean?

can anyone help me please D:


okello michael from uganda(arfrica) 4 years ago

Guess what i just love all the usefull help i get from here am In the MIS dept. but am always going to use this site.Thanx guy we learn alot


gulrpucle 4 years ago

hello dude,

in your example u stated that "Malware is inside your hard drive just by looking at the attributes of each files and the file that has the attributes of +s +h +r".

But at the end you find that only this two files infected although other file also show SHR (in the command prompt). SilentSoftech.exe and autorun.inf


Munavvar Able 4 years ago

example : del d:\ autorun.inf


JM 4 years ago

T.T my PC has just been attacked by a virus..

first it disabled me task manager then my anti-virus.. I've

already tried finding it by using command prompt but won't

work!...not it's starting to delete my files!..and infected

my 8 GB flash drive!..my gosh..really hate that virus! so

annoying! (cry mode!) gonna reformat my PC..bye bye files! >:/


jay01 4 years ago

bro can u help to how u can hide and show the files or maybe using a usb flash drive ,. because i have a usb flash drive but i cannot see my folder or files because they are hiding ,.please can u help me about that to recover again it., using you cmd ,command prompt . thanks!! God Bless you ................


John Robie Maniago 4 years ago

To remove the .exe file in the computer,

First remove first the autorun.inf and then delete the .exe file!

XD!


sumit 4 years ago

there is a very typical virusin my lappie which can never be deleted..it keeps on coming back even if it is deleted..and whenever i tried to open my command prompt, it dissapears this virus has affected my pendrive too....please help in this matter..


noIRAm... 4 years ago

Sir . . I had this virus that cannot be deleted due to it was been said that "Its been used by another program"? can u plss recommend me a good solution . . tnx more powers . .


..deomOlisher.. 4 years ago

..sir is it a sign f that there's a virus f may hard drive is loosing sO memory.? but.. i made to use some of u're steps but i didn;t see any infection/virus..


gayz 4 years ago

thanks man!!!


shiv 4 years ago

it really works


Bally Joesaccio 4 years ago

If you simply read and comprehend the instructions you will clearly see the value of this article. If you are a flippin bonehead and cannot understand the printed words you should prolly not be using computers.


nbbatt.com 4 years ago from bear, de, 19701

thanks guy, you solved my problem.


yidi 4 years ago

thanks man i try it and it works.cool.post more and i'll try it again.


ben 4 years ago

thanx man, you filipino are awesome. it makes my computer faster now.. cheers


neha 4 years ago

thanks


laxmi 4 years ago

are u sure it remove only the vires it is posible.......not the file of windows os....


isyan profile image

isyan 4 years ago Hub Author

@laxmi: it is possible that you can delete the os files.. my advice is you google first the suspected file then delete it if its a virus..


Praveen kumar 4 years ago

THIS IS VERY GOOD COMMAND THANKS!


lasith 4 years ago

WOW ITS GREAT

THANX DUDE


gudu 4 years ago

very good yar this works


jamal 4 years ago

not working,,, drive c has no virus,,, what should i do for the drive d? thers possible way to delet virus from drive d by using cmd?


pranav 4 years ago

this idea is working,i know about it before the thing i am searching for is ,how to totlly recover an deleated data piece using CMD codes


isyan profile image

isyan 4 years ago Hub Author

@jamal: you can apply the command on drive d...and yes.. its possible to delete a virus by using cmd...

@pranav: there is no cmd command that can recover a deleted data..none that I know of.. :) you must use 3rd party apps for that.. try googling for it.. :)


mark jordan dalayap 4 years ago

great!! i made it!!


isyan profile image

isyan 4 years ago Hub Author

@mark jordan dalayap: Congrats.. glad it helped alot of people.. :)


kishan kunwar 4 years ago

really bro this one article is knowledgeable..............

Thank you for putting such a nice article.


seon shrestha 4 years ago

hey this is great article . when is your next article coming?


melanie 4 years ago

thanks!!! it work it didnt work to others becos they r idot

1. first type attrib then enter

when u see .exe it means it is a malware or a virus for example the virus is axbcneag.exe

type del axbcneag.exe

then type again the attrib

then when u didnt see it, it is been remove


santosh 4 years ago

good


kamal 4 years ago

Hi Thanks.

Understood about the basics of attributes.


Bray 4 years ago

its says access denied when I typed attrib -s -h -r autorun.inf

when i typed del autorun.inf, it says could not find autorun.inf

How is that


deep 3 years ago

wooooooooooo its done


kumar abhishek 3 years ago

thanx mate..it did work :)


isyan profile image

isyan 3 years ago Hub Author

@muddassar: try to apply the steps in this post.. and then delete it.. if it's more complicated, Visit my other hub, it has more detailed info in deleting virus..

@Bray: check the process manager, maybe the autorun.inf process is still running.. kill the process then you can change the attribute, then delete it..


smitty232 3 years ago

i have found the yeawl.exe virus on my laptop, i have typed in attrib -s-h-r yeawl.exe then del yeawl.exe, but it says another process is using it, but i cannot find the process, is there a way to spot the difference to find the process


smitty232 3 years ago

ive removed the attributes and i cant even delete in safe mode, i have to kill this process but i cannot find it


MCA 3 years ago

@smitty232

you may try creating another admin account and delete the file located in your current account from that new account. You should apply the procedures written above.


prabhat 3 years ago

i am getting problem in removing the "recycler" which is located in c: drive...

i hv tried it removing it while it is located in any other drive it is getting removed but it is not working for removing in c: drive...pls suggest a solution for it


Digvijay 3 years ago

thanx man ur awesome..............


isyan profile image

isyan 3 years ago Hub Author

@prabhat: the recycler in drive c is not a virus..

@smitty232: try looking for autrun.inf process... it should be there somewhere... :)


Inaloz 3 years ago

It worked man. Thanx a lot :^,


aayush 3 years ago

hey isyan, i have a problem.i got a virus from my internet and due to it i can not open task manager and registry editor.What to do?Do you have any suggestions?


earl 3 years ago

@jufei

if you already had clear/clean ur USB for viruses, you can use attrib, type attrib -s -h -r *.* /s at the root directory of your USB, if you want to see those hidden folder, type DIR /AH, u can also use attrib on the folder that have been hidden by the virus

or

u can set ur windows explorer to view those hidden folders & files by doing this

1.open windows explorer

2.click tools, then folder options, then views, then tick "show hidden files and folders"


earl 3 years ago

@aayush

try gpedit.msc, type it on the run (press window & r on your keyboard)

for TASK MANAGER:

1.click Administrative Templates under the User Configuration

2.then click System,

3.then click Ctrl+Alt+Del Options,

4.then 2click Remove Task Manager, tick Enable, then apply

5.then tick Not Configured, then click Ok,

6.then close/exit the Group Policy

FOR REGEDIT

1.do 1 and 2 step(up)

2.then 2click Prevent access to Registry editing tools

3.do 4 to 6 step(up)

after that try to press CTRL+ALt+Del for you Task Manager

if this not come out you still have virus running on your system

hope that helps


Trisha 3 years ago

Thankz ppl,your atriclez has helpedz me alotz:) keepz up the good workz...really appreciatez itz:)


Richard 3 years ago

Thanks ISYAN it works.....GOD BLESS


Zenie 3 years ago

-- helo. im so much thank ful with u. i finally deleted the viruses in my pc.... thank u.


oxford 3 years ago

sir, i tried to delete autorun.inf but it will only display "Could Not Find autorun.inf"..


jayzon roxas 3 years ago

why does the autorun.inf in my USB flash drive keeps on coming back.....


chard 3 years ago

thanks it helps but one file with SHR cant delete, the "bootmgr", no file extension.when i try the attrib -s -h -r bootmgr it says "access denied"...wat happened,how to fix this?thanks much


james 3 years ago

@oxford, that means theres no virus in your system.


Omar 3 years ago

Very helpful, thank you.


sahar 3 years ago

i,have problem that copmuter is not showing all data of usb.the virus effect data is hidden it is not show.how to open this hidden virus effectd data from usb b/c it is important data.kindly guide me the dos command steps through we can recover my impt data. thanks


Azo 3 years ago

@sahar to view ur files do the follwing...

goto FOLDER AND SEARCH OPTIONS > VIEW >disable HIDE PROTECTED OPERATING SYSTEM option > apply changes....

ur files will be displayed in ur usb..


Te-friend-love-you-max 3 years ago

Wow, thanks msm, run correctly, you're 10


himan 3 years ago

hey ..thanks it really works


santoshxl 3 years ago

thanks


isyan profile image

isyan 3 years ago Hub Author

@walter: use google...

@santosh: dont type "cmd attrib".. pls follow step 1.. Launch attrib...


kaetlin 3 years ago

tnx for this:)


Lukas 3 years ago

Thanks man helpfully


uttam kumar 3 years ago

tanks


Nending 3 years ago

thanks for your knowledgeable n useful tips.....i like it v much!!!


sathish 3 years ago

thanks


rohit baldha 3 years ago

$recycle.bin is a virus.. I used it as an example... Attrib function will not delete a file, it will just set the attributes of a file... In this article I set the attributes of autorun.inf and silentsoftech.exe so that I can delete them using the del function..


Nikhildas 3 years ago

Thanks a lot..

nice article..


Matthew 2 years ago

this information is very helpful to me. thanks


gaby 2 years ago

thanks alot


ken 2 years ago

thanks po


joey jon pol 2 years ago

thanx man!Boinaparika.it means you guys are geniuses


Ranga 2 years ago

Thank you!


aboalse3ab 2 years ago

first must show all hidden files

and then follow

start cmd

select the letter of the drive (e.g: G:\)

G:\attrib -h -s -r /s *.* /d


asdf 2 years ago

thanks :)


sonam 2 years ago

hi its been very nic and effectively me to delete virus in my hard drive thankx a lot you are my god ......


chinu 2 years ago

thanx... its very nice n usefull....:)


ato 2 years ago

your are too much...............thanks alot


sujith 2 years ago

Thanks you for such wonderful information


tola 2 years ago

many thanks for kindness


Avinash Singh 2 years ago

thanks dude....


hey_jay19@yahoo.com 2 years ago

nice. very informative...


rayne 2 years ago

pinoy knaman cguro

mgtatagalog nlang ako pnu ba i delete ung my spacing na virus halimbawa new folder.exe kasi pgtype ko ng del new folder.exe sinasabi could n ot find d:\ new..pnu ba yon kapatid..salamat


isyan profile image

isyan 2 years ago Hub Author

just use TAB..

ex. type del new (then press TAB.. it will autocomplete the filename)..


isyan profile image

isyan 2 years ago Hub Author

haha.. your welcome.. Jesus is Lord


bile bbc 2 years ago

thnks really it is akind of helping before i don't know it but i make of it thnks alot


sim2king 23 months ago

it worked out just perfectly. Thanx hey


liesl5858 profile image

liesl5858 17 months ago from United Kingdom Level 2 Commenter

Thank you Isyan for this useful and interesting hub, I will it one day when my laptop get virus problems.


isyan profile image

isyan 4 months ago Hub Author

Hi,

hopefully you'll never have to experience virus problems.. by just being vigilant and cautious as to the things that you download through the internet.. :)

cheers


    Sign in or sign up and post using a HubPages account.

    8192 characters left.
    Post Comment

    No HTML is allowed in comments, but URLs will be hyperlinked. Comments are not for promoting your Hubs or other sites.


    Click to Rate This Article
    Please wait working