Script: Unhide Network Drive Folders

There is an infection going around that hides all folders on a network drive and sets them as system folders. Here is a script I wrote that will remove the hidden and system attributes all folders/files in a directory you specify.
It uses the “attrib -h -s” and is not recursive into subdirectories.

For complete removal of the infection, naturally scan all machines. Remove any rouge autorun.ini files and rouge .exe files on the network drive.

Download: UnhideNetworkDriveFolders.v1.zip

I haven’t tested on all system setups and naturally comes with no warranty.

Update 3/22/2013

This script can only be run against a folder ( C:/Production/Shared ) not against an actual mapped drive ( S:/ ) at this time.

Update 3/27/2013

Here is a quick list of things to check regarding cleaning up the infection/worm.

  • Scan all PCs with Malwarebytes
    • Cleanup the the startup items
    • Cleanup and rouge exe files located
      • C:\User\%Username%
      • C:\User\%Username%\AppData
      • C:\User\%Username%\AppData\Roaming
    • Find proccess the infection is running under. Example:  jjhhgg.exe
  • Network drives, Flashdrives, External Harddrives
    • Delete all *.exe that mimic a folder and have a folders name
    • Delete autorun.inf
    • Delete x.mpg
    • Deltee anything else odd, rouge .exe files, photos files with .exe extentions
    • CMD Prompt, browse to the folder and run
      • attrib -h -s
      • Note this only unhides files, not folders.
    • CMD Prompt, browse to the folder and run
      • FOR /F "tokens=*" %i IN ('DIR /A:D /b') do attrib -h -s "%i"
      • Note this only unhides folders, make sure to have the quotation marks


Utility: ISO Rip / Mount

I was searching around and found a set ISO utilities that are a great pair together. Both have no cost.

Portable Lightweight ISO Rip utility


LCISOCreator is great for creating .iso rips of a cd quickly.

ISOs rips are bootable for virtual machines. For physical machines I load the ISOs to a bootable USB disk. The interface can’t get much simpler. I can’t think of more to say.

LCISOCreator.exe (52KB)
Developers’s site seems to be no more.

Portable Lightweight ISO Mount utility


PortableWinCDEmu is great for mounting .iso files to a new virtual drive quickly.

The app does have to load a driver, naturally. The driver can be removed right from the app when you are finished. You can mount multiple images.

Supported image formats: iso, cue, img, nrg, mds, ccd, bin

PortableWinCDEmu-4.0.exe (229KB)
Developer’s Site