How To Delete the Hidden Files of the Resik Worm?
This is actually part of my post on how to remove the Worm@W32.Resik worm from your PC or Flash Drive. Our visitor who send us an email yesterday, sent us again an email asking me the instructions on how to delete manually the hidden files of the Resik worm.
Yesterday, I posted the instruction on how to view the hidden files created by this worm because they couldn’t be viewed by simply changing the VIEW option of the Windows explorer.
So, since these files can only be viewed in DOS, we can also delete this files at DOS.
However, these files can’t be deleted by immediately deleting them using the DEL command because their attributes are set to hidden and read only. In other words, we should change their attribute first before we can delete them. And here’s how:
- Assuming that you already had opened the DOS interface (see our previous post how… step 1)
- Change the directory to the Windows system directory by typing at the DOS prompt, “cd c:\windows\system32\” without quote and press ENTER.
- Type “attrib inetsrv* -r -s -h” without quote and press ENTER. This DOS command changes the attribute of the files in which their filenames begin with “inetsrv” into minus readonly (-r), minus system (-s), and minus hidden (-h). In other words, these files will be made as not read-only, not system and not hidden files.
- To verify if their attributes have been changed already, type at the DOS prompt “attrib inetsrv*” without quote and press ENTER. The DOS will tell you the files’ corresponding attributes whether A for Archive, H for Hidden, R for Read-Only and S for System.
- Now, if these files are already with minus hidden attribute and minus read-only attribute, then you can now delete them by typing “del inetsrv*” without quote and press ENTER. If the DOS will ask you whether to delete them all just press Y to confirm the deletion command.
- The steps 3, 4 and 5 should be done also when deleting the autorun.inf at the root directory of your Flash Drive, and Voinfo* and Driveinfo* at the directory “Recycled” of your Flash drive. Just replace the INETSRV with VOINFO or DRIVEINFO.
If you still meet problems in deleting them, email me again or just drop your message at our comment section.
-
Sign up for PayPal and start accepting credit card payments instantly.
As the world's number one online payment service, PayPal is the fastest way to open your doors to over 150 million member accounts worldwide. -
Promote your product to high quality, targeted websites and blogs.
Find effective, influential blogs and highly targeted audiences to advertise.Choose to display your ad across entire blog networks to maximize your exposure to a wide audience.
Related Post
- How To Remove Worm@W32.Resik From Your PC and Flash Drive
- How to View the Hidden Files of Worm@W32.Resik Worm?
- Beware of Key Logger residing on your Flash Drive
- Worm Targets YM Users To Earn from Adsense
- Worm in MySpace Again via QuickTime Movie
- Hyborate At Work
- Are You an IM User? Beware of An Spyware Spying You!
- Sectoriate For Yahoo
- Virus.Win32.Gpcode
- Hello world!
- SezWho Security Issue, Fix
- Distrust for Firefox Private Browsing
- Exploiting The Exploitable
- Wordpress v2.1.1 Cracked, Upgrade To v2.1.2 Immediately
- MyBlogLog Banning Members
Recently Commented
- Wordpress, The Best Blogging Platform
- How to Choose the Right Domain for Your Blog?
- How to pick the right Webhost for your Blog?
- You Ask by Talking, Google Answers in Screen
- Porn Traffic Is Now Dying
- What Makes A Webhost Better than the Other?
- Counter Statistics
- How to Choose the Right Topic for Your Blog?
- Chat and Earn Dollar
- September 2008 LET - Licensure Examination for Teachers - Result
- Daisy - Korean Movie - English Sub
- Naruto Theme Songs Lyrics
- LET September 2008 Result, Released
- Beware of Key Logger residing on your Flash Drive
- Pinoy HangAroo





August 9th, 2007 at 6:23 pm
[...] How To Delete the Hidden Files of the Resik Worm? Save to del.icio.us • Stumble It! • Submit To Netscape • Digg This! Enter your email address to Subscribe: [...]
February 23rd, 2008 at 10:17 pm
NOTE: You have written the attrib comand name wrong in some lines of the how to del the Win32 worm tutorial. You wrote attribe.
February 24th, 2008 at 9:04 pm
hello. thank you so much for informing about my errors