ArtsAutosBooksBusinessEducationEntertainmentFamilyFashionFoodGamesGenderHealthHolidaysHomeHubPagesPersonal FinancePetsPoliticsReligionSportsTechnologyTravel
  • »
  • Technology»
  • Computers & Software

Using command prompt "attrib" to check for Viruses or Malware

Updated on August 7, 2015

Microsoft Command Prompt "attrib" is a very useful tool to check if your hard drives even your flashdisks have been infected by a virus.

You will know if a Malware is inside your hard drive just by looking at the attributes of each files and the file that has the attributes of +s +h +r

The function of attrib is to set and remove file attributes (read-only, archive, system and hidden).

Launch attrib

To start attrib

  1. Go to Start Menu > Run
  2. Type cmd (cmd stands for command prompt)
  3. Press Enter key

The Command Prompt will appear showing us where is our location in the directory.

command prompt showing the current location in the directory
command prompt showing the current location in the directory

Using attrib

To use attrib

  1. Go to the root directory first by typing cd\(because this is always the target of Malware / Virus)

2. Type attrib and press Enter key

after typing attrib, all the attributes of all the files (excluding folders) will be shown
after typing attrib, all the attributes of all the files (excluding folders) will be shown

In this example, I have two files that are considered as malware.

Note that there are two files which I outlined in red (SilentSoftech.exe and autorun.inf). Since you cannot see this file nor delete it (because the attributes that was set on these files are +s +h +r)

  1. +s - meaning it is a system file (which also means that you cannot delete it just by using the delete command)
  2. +h - means it is hidden (so you cannot delete it)


  3. +r - means it is a read only file ( which also means that you cannot delete it just by using the delete command)


Now we need to set the attributes of autorun.inf to -s -h -r (so that we can manually delete it)

  1. Type attrib -s -h -r autorun.inf ( be sure to include -s -h -r because you cannot change the attributes using only -s or -h or -r alone)
  2. Type attrib again to check if your changes have been committed
  3. If the autorun.inf file has no more attributes, you can now delete it by typing del autorun.inf
  4. Since SilentSoftech.exe is a malware you can remove its attributes by doing step 1 and step 3(just change the filename) ex. attrib -s -h -r silentsoftech.exe


a) I typed the attrib command with the -s -h -r setting b) the result after I pressed enter - autorun.inf has no attributes left
a) I typed the attrib command with the -s -h -r setting b) the result after I pressed enter - autorun.inf has no attributes left

There you have it!!!!

NOTE : when autorun.inf keeps coming back even if you already deleted it, be sure to check your Task Manager by pressing CTRL + ALT + DELETE ( a virus is still running as a process that's why you cannot delete it. KILL the process first by selecting it and clicking End Process.

NOTE: You can also apply the attrib -s -h -r command to all the partition of your computer, drive D: drive E: drive F: (all of your drives). For example. for drive D, just type "D:" (minus the double quote) then you can see that your current drive is D.. type there the command "attrib -s -h -r *.exe" for exe files and "attrib -s -h -r *.inf" and then delete the file by "del autorun.inf".

Hope this helps!!!!! :) Jah bles!

NOTE: If you want to have a more detailed information regarding How to delete a virus visit my other hub.. HOW TO DELETE A VIRUS IN YOUR USB/FLASHDISK

Comments

Submit a Comment

  • isyan profile image
    Author

    isyan 3 years ago

    Hi,

    hopefully you'll never have to experience virus problems.. by just being vigilant and cautious as to the things that you download through the internet.. :)

    cheers

  • liesl5858 profile image

    Linda Bryen 4 years ago from United Kingdom

    Thank you Isyan for this useful and interesting hub, I will it one day when my laptop get virus problems.

  • profile image

    sim2king 4 years ago

    it worked out just perfectly. Thanx hey

  • profile image

    bile bbc 5 years ago

    thnks really it is akind of helping before i don't know it but i make of it thnks alot

  • isyan profile image
    Author

    isyan 5 years ago

    haha.. your welcome.. Jesus is Lord

  • isyan profile image
    Author

    isyan 5 years ago

    just use TAB..

    ex. type del new (then press TAB.. it will autocomplete the filename)..

  • profile image

    rayne 5 years ago

    pinoy knaman cguro

    mgtatagalog nlang ako pnu ba i delete ung my spacing na virus halimbawa new folder.exe kasi pgtype ko ng del new folder.exe sinasabi could n ot find d:\ new..pnu ba yon kapatid..salamat

  • profile image

    hey_jay19@yahoo.com 5 years ago

    nice. very informative...

  • profile image

    Avinash Singh 5 years ago

    thanks dude....

  • profile image

    tola 5 years ago

    many thanks for kindness

  • profile image

    sujith 5 years ago

    Thanks you for such wonderful information

  • profile image

    ato 5 years ago

    your are too much...............thanks alot

  • profile image

    chinu 5 years ago

    thanx... its very nice n usefull....:)

  • profile image

    sonam 5 years ago

    hi its been very nic and effectively me to delete virus in my hard drive thankx a lot you are my god ......

  • profile image

    asdf 5 years ago

    thanks :)

  • profile image

    aboalse3ab 5 years ago

    first must show all hidden files

    and then follow

    start cmd

    select the letter of the drive (e.g: G:\)

    G:\attrib -h -s -r /s *.* /d

  • profile image

    Ranga 5 years ago

    Thank you!

  • profile image

    joey jon pol 5 years ago

    thanx man!Boinaparika.it means you guys are geniuses

  • profile image

    ken 5 years ago

    thanks po

  • profile image

    gaby 5 years ago

    thanks alot

  • profile image

    Matthew 5 years ago

    this information is very helpful to me. thanks

  • profile image

    Nikhildas 6 years ago

    Thanks a lot..

    nice article..

  • profile image

    rohit baldha 6 years ago

    $recycle.bin is a virus.. I used it as an example... Attrib function will not delete a file, it will just set the attributes of a file... In this article I set the attributes of autorun.inf and silentsoftech.exe so that I can delete them using the del function..

  • profile image

    sathish 6 years ago

    thanks

  • profile image

    Nending 6 years ago

    thanks for your knowledgeable n useful tips.....i like it v much!!!

  • profile image

    uttam kumar 6 years ago

    tanks

  • profile image

    Lukas 6 years ago

    Thanks man helpfully

  • profile image

    kaetlin 6 years ago

    tnx for this:)

  • isyan profile image
    Author

    isyan 6 years ago

    @walter: use google...

    @santosh: dont type "cmd attrib".. pls follow step 1.. Launch attrib...

  • profile image

    santoshxl 6 years ago

    thanks

  • profile image

    himan 6 years ago

    hey ..thanks it really works

  • profile image

    Te-friend-love-you-max 6 years ago

    Wow, thanks msm, run correctly, you're 10

  • profile image

    Azo 6 years ago

    @sahar to view ur files do the follwing...

    goto FOLDER AND SEARCH OPTIONS > VIEW >disable HIDE PROTECTED OPERATING SYSTEM option > apply changes....

    ur files will be displayed in ur usb..

  • profile image

    sahar 6 years ago

    i,have problem that copmuter is not showing all data of usb.the virus effect data is hidden it is not show.how to open this hidden virus effectd data from usb b/c it is important data.kindly guide me the dos command steps through we can recover my impt data. thanks

  • profile image

    Omar 6 years ago

    Very helpful, thank you.

  • profile image

    james 6 years ago

    @oxford, that means theres no virus in your system.

  • profile image

    chard 6 years ago

    thanks it helps but one file with SHR cant delete, the "bootmgr", no file extension.when i try the attrib -s -h -r bootmgr it says "access denied"...wat happened,how to fix this?thanks much

  • profile image

    jayzon roxas 6 years ago

    why does the autorun.inf in my USB flash drive keeps on coming back.....

  • profile image

    oxford 6 years ago

    sir, i tried to delete autorun.inf but it will only display "Could Not Find autorun.inf"..

  • profile image

    Zenie 6 years ago

    -- helo. im so much thank ful with u. i finally deleted the viruses in my pc.... thank u.

  • profile image

    Richard 6 years ago

    Thanks ISYAN it works.....GOD BLESS

  • profile image

    Trisha 6 years ago

    Thankz ppl,your atriclez has helpedz me alotz:) keepz up the good workz...really appreciatez itz:)

  • profile image

    earl 6 years ago

    @aayush

    try gpedit.msc, type it on the run (press window & r on your keyboard)

    for TASK MANAGER:

    1.click Administrative Templates under the User Configuration

    2.then click System,

    3.then click Ctrl+Alt+Del Options,

    4.then 2click Remove Task Manager, tick Enable, then apply

    5.then tick Not Configured, then click Ok,

    6.then close/exit the Group Policy

    FOR REGEDIT

    1.do 1 and 2 step(up)

    2.then 2click Prevent access to Registry editing tools

    3.do 4 to 6 step(up)

    after that try to press CTRL+ALt+Del for you Task Manager

    if this not come out you still have virus running on your system

    hope that helps

  • profile image

    earl 6 years ago

    @jufei

    if you already had clear/clean ur USB for viruses, you can use attrib, type attrib -s -h -r *.* /s at the root directory of your USB, if you want to see those hidden folder, type DIR /AH, u can also use attrib on the folder that have been hidden by the virus

    or

    u can set ur windows explorer to view those hidden folders & files by doing this

    1.open windows explorer

    2.click tools, then folder options, then views, then tick "show hidden files and folders"

  • profile image

    aayush 6 years ago

    hey isyan, i have a problem.i got a virus from my internet and due to it i can not open task manager and registry editor.What to do?Do you have any suggestions?

  • profile image

    Inaloz 6 years ago

    It worked man. Thanx a lot :^,

  • isyan profile image
    Author

    isyan 6 years ago

    @prabhat: the recycler in drive c is not a virus..

    @smitty232: try looking for autrun.inf process... it should be there somewhere... :)

  • profile image

    Digvijay 6 years ago

    thanx man ur awesome..............

  • profile image

    prabhat 6 years ago

    i am getting problem in removing the "recycler" which is located in c: drive...

    i hv tried it removing it while it is located in any other drive it is getting removed but it is not working for removing in c: drive...pls suggest a solution for it

  • profile image

    MCA 6 years ago

    @smitty232

    you may try creating another admin account and delete the file located in your current account from that new account. You should apply the procedures written above.

  • profile image

    smitty232 6 years ago

    ive removed the attributes and i cant even delete in safe mode, i have to kill this process but i cannot find it

  • profile image

    smitty232 6 years ago

    i have found the yeawl.exe virus on my laptop, i have typed in attrib -s-h-r yeawl.exe then del yeawl.exe, but it says another process is using it, but i cannot find the process, is there a way to spot the difference to find the process

  • isyan profile image
    Author

    isyan 6 years ago

    @muddassar: try to apply the steps in this post.. and then delete it.. if it's more complicated, Visit my other hub, it has more detailed info in deleting virus..

    @Bray: check the process manager, maybe the autorun.inf process is still running.. kill the process then you can change the attribute, then delete it..

  • profile image

    kumar abhishek 6 years ago

    thanx mate..it did work :)

  • profile image

    deep 6 years ago

    wooooooooooo its done

  • profile image

    Bray 7 years ago

    its says access denied when I typed attrib -s -h -r autorun.inf

    when i typed del autorun.inf, it says could not find autorun.inf

    How is that

  • profile image

    kamal 7 years ago

    Hi Thanks.

    Understood about the basics of attributes.

  • profile image

    santosh 7 years ago

    good

  • profile image

    melanie 7 years ago

    thanks!!! it work it didnt work to others becos they r idot

    1. first type attrib then enter

    when u see .exe it means it is a malware or a virus for example the virus is axbcneag.exe

    type del axbcneag.exe

    then type again the attrib

    then when u didnt see it, it is been remove

  • profile image

    seon shrestha 7 years ago

    hey this is great article . when is your next article coming?

  • profile image

    kishan kunwar 7 years ago

    really bro this one article is knowledgeable..............

    Thank you for putting such a nice article.

  • isyan profile image
    Author

    isyan 7 years ago

    @mark jordan dalayap: Congrats.. glad it helped alot of people.. :)

  • profile image

    mark jordan dalayap 7 years ago

    great!! i made it!!

  • isyan profile image
    Author

    isyan 7 years ago

    @jamal: you can apply the command on drive d...and yes.. its possible to delete a virus by using cmd...

    @pranav: there is no cmd command that can recover a deleted data..none that I know of.. :) you must use 3rd party apps for that.. try googling for it.. :)

  • profile image

    pranav 7 years ago

    this idea is working,i know about it before the thing i am searching for is ,how to totlly recover an deleated data piece using CMD codes

  • profile image

    jamal 7 years ago

    not working,,, drive c has no virus,,, what should i do for the drive d? thers possible way to delet virus from drive d by using cmd?

  • profile image

    gudu 7 years ago

    very good yar this works

  • profile image

    lasith 7 years ago

    WOW ITS GREAT

    THANX DUDE

  • profile image

    Praveen kumar 7 years ago

    THIS IS VERY GOOD COMMAND THANKS!

  • isyan profile image
    Author

    isyan 7 years ago

    @laxmi: it is possible that you can delete the os files.. my advice is you google first the suspected file then delete it if its a virus..

  • profile image

    laxmi 7 years ago

    are u sure it remove only the vires it is posible.......not the file of windows os....

  • profile image

    neha 7 years ago

    thanks

  • profile image

    ben 7 years ago

    thanx man, you filipino are awesome. it makes my computer faster now.. cheers

  • profile image

    yidi 7 years ago

    thanks man i try it and it works.cool.post more and i'll try it again.

  • profile image

    nbbatt.com 7 years ago from bear, de, 19701

    thanks guy, you solved my problem.

  • profile image

    Bally Joesaccio 7 years ago

    If you simply read and comprehend the instructions you will clearly see the value of this article. If you are a flippin bonehead and cannot understand the printed words you should prolly not be using computers.

  • profile image

    shiv 7 years ago

    it really works

  • profile image

    gayz 7 years ago

    thanks man!!!

  • profile image

    ..deomOlisher.. 7 years ago

    ..sir is it a sign f that there's a virus f may hard drive is loosing sO memory.? but.. i made to use some of u're steps but i didn;t see any infection/virus..

  • profile image

    noIRAm... 7 years ago

    Sir . . I had this virus that cannot be deleted due to it was been said that "Its been used by another program"? can u plss recommend me a good solution . . tnx more powers . .

  • profile image

    sumit 7 years ago

    there is a very typical virusin my lappie which can never be deleted..it keeps on coming back even if it is deleted..and whenever i tried to open my command prompt, it dissapears this virus has affected my pendrive too....please help in this matter..

  • profile image

    John Robie Maniago 7 years ago

    To remove the .exe file in the computer,

    First remove first the autorun.inf and then delete the .exe file!

    XD!

  • profile image

    jay01 7 years ago

    bro can u help to how u can hide and show the files or maybe using a usb flash drive ,. because i have a usb flash drive but i cannot see my folder or files because they are hiding ,.please can u help me about that to recover again it., using you cmd ,command prompt . thanks!! God Bless you ................

  • profile image

    JM 7 years ago

    T.T my PC has just been attacked by a virus..

    first it disabled me task manager then my anti-virus.. I've

    already tried finding it by using command prompt but won't

    work!...not it's starting to delete my files!..and infected

    my 8 GB flash drive!..my gosh..really hate that virus! so

    annoying! (cry mode!) gonna reformat my PC..bye bye files! >:/

  • profile image

    Munavvar Able 7 years ago

    example : del d:\ autorun.inf

  • profile image

    gulrpucle 7 years ago

    hello dude,

    in your example u stated that "Malware is inside your hard drive just by looking at the attributes of each files and the file that has the attributes of +s +h +r".

    But at the end you find that only this two files infected although other file also show SHR (in the command prompt). SilentSoftech.exe and autorun.inf

  • profile image

    okello michael from uganda(arfrica) 7 years ago

    Guess what i just love all the usefull help i get from here am In the MIS dept. but am always going to use this site.Thanx guy we learn alot

  • profile image

    MM 7 years ago

    i typed it in and it comes up with 'A SH'

    O_O

    what does that mean?

    can anyone help me please D:

  • profile image

    axel 7 years ago

    this command "attrib" is very usseful and I tried it a few times but there's one thing that I'm not sure about. I restored one virus detected by AVG Int. Sec 9 and than command "attrib" couldn't find it on my system. Why and how to do that? Virus was smth. like Trojan horse Generic...thx

  • profile image

    much 7 years ago

    sir how to delete an RVHOST.exe in command prompt?im recently using win7..the system doesn't start..so im using safe mode with command prompt trying to delete the virus..please help me thanks..

  • profile image

    herwin 7 years ago

    thank you so much!

  • profile image

    Charaze 7 years ago

    It worked! Now, my laptop is working just fine. I'll try to delete other viruses of my other accounts. Thanks for the info!

  • profile image

    narico1025 7 years ago

    thank you!!! it works...

  • isyan profile image
    Author

    isyan 7 years ago

    @hammad ansaru: pls read the last part where you have to disable a malicious process running in your computer

    @mayuri: thanks and i hope it helped you

    @sahan:pls read and understand the instructions carefully because deleting it is included in my post.. :)

  • profile image

    hammad ansaru 7 years ago

    i have got two virus programms in my usb and i can see them using attrib. but i am unable to change their attribute and i get a message "Not resettig hidden file lemisha.exe"

    and "Not resetting hidden file deutrovioce.exe"

    any suggestions please?

  • profile image

    mayuri 7 years ago

    thnks a lot.. i hope i dont see the viruses again..

    u explained it v. well..

  • profile image

    sahan!@# 7 years ago

    how do u delete it

    i need the steps!!

  • profile image

    donkz 7 years ago

    hi.. i want to follow ur instructions but... wen i type the cmd and press the enter key... my computer shut downed...

    is there any other way to removed the virus in comp? please help...

  • profile image

    Rgonz 7 years ago

    Hey i am clean...No virus found..THANKS :D

  • profile image

    softboy 7 years ago

    perfect!

    tyvm from PORTUGAL !

    tiagosousa999@hotmail.com