How to Remove a Worm That Creates Hidden Shares on Your Network
A worm that creates hidden shares on your network can spread quietly between Windows computers, laptops, servers, and network-attached storage. It may use administrative shares such as C$, ADMIN$, or IPC$ to copy itself, launch commands, steal credentials, or return after an initial cleanup.
The first signs are often unusual: a new local account, repeated failed logins, unexplained traffic, disabled security software, or folders appearing on another device. A home office using an NBN modem and several connected devices can give a network worm plenty of paths to explore before anyone notices.
Treat the incident as a network-wide security problem rather than simply deleting one suspicious file. Disconnect affected systems carefully, preserve useful evidence, and check every computer that shares the same router, Wi-Fi, server, or NAS.
What Hidden Shares Can Reveal
Windows hides administrative shares from normal browsing, but they remain accessible to authorised accounts and some malware. In File Explorer, a path such as \\ComputerName\C$ may indicate a legitimate administrative connection, although an unexpected access attempt deserves investigation.
A worm may create a custom hidden share by adding a dollar sign to the share name, changing share permissions, or modifying registry settings so the share returns after reboot. Check whether the share points to a strange folder, a temporary directory, a user profile location, or an executable with a random name.
Do not assume every hidden share is malicious. Domain controllers, backup tools, remote-management software, and business applications can use them. The important clues are unusual creation times, unknown accounts, unexplained file transfers, and matching activity across several machines.
Isolate Devices Without Losing Evidence
Disconnect the suspected computer from Wi-Fi and Ethernet. If it is a business device, avoid repeatedly restarting it before recording what you can see. Photograph unusual alerts, note the computer name and time, and record which other systems were connected to the same network.
For a household in Brisbane, Perth, or regional New South Wales, this may mean unplugging a desktop from the router while leaving essential devices online. Avoid opening suspicious shares from another computer, because browsing them can trigger additional scripts or copy infected files.
Change the Wi-Fi password from a clean device if the worm may have stolen router credentials. Keep the modem or router powered on until you have recorded its settings, but review connected-device lists and remote administration options for anything unfamiliar.
Inspect Shares, Accounts, and Persistence
On Windows, open Computer Management and inspect Shared Folders, Shares, and Sessions. PowerShell can provide additional information with commands such as Get-SmbShare, Get-SmbSession, and Get-SmbOpenFile. Run these from an administrator account on a trusted machine where possible.
Review local users and groups, scheduled tasks, startup entries, services, firewall rules, and recent logons. A worm often creates persistence through a scheduled task or service rather than relying on the hidden share alone. Check for newly added administrators and accounts with vague names that resemble system processes.
Examine the share’s local folder and nearby files without executing anything. Record hashes or copy suspicious samples only if you have safe storage and appropriate security expertise. For a small Australian business, preserve logs before calling an IT provider, since those records may help distinguish a compromised workstation from a breached file server.
Choose the Right Cleanup Method
The safest approach depends on the number of affected devices, the worm’s persistence, and whether credentials were exposed. Use this comparison when deciding how to proceed:
| Situation |
Preferred action |
Important caution |
| One computer, no persistence found |
Run an updated offline or reputable antimalware scan |
Recheck shares after reboot |
| Several Windows devices show the same activity |
Isolate all suspected systems and investigate centrally |
Do not reconnect them casually |
| Administrator passwords may be stolen |
Reset credentials from a clean device |
Use unique passwords and MFA |
| Server or NAS is affected |
Stop access, preserve logs, and involve an administrator |
Avoid deleting shared data blindly |
| Malware returns after scans |
Back up essential documents and reinstall the system |
Treat the device as untrusted |
A normal antivirus scan can miss a worm hidden behind a scheduled task, service, or altered policy. Use Microsoft Defender Offline or a reputable second-opinion scanner, then inspect the system again after the scan and reboot.
For deeper guidance on a related Windows intrusion involving remote access, consult this RAT removal guide. The same principles—isolating the host, checking persistence, and changing credentials—often apply when a worm has used remote administration features.
Remove the Worm and Its Network Access
From a clean administrator account, disable suspicious shares and remove unauthorised share permissions. Delete the malicious folder only after recording its location and confirming that it is not required by legitimate software. Remove associated scheduled tasks, services, startup entries, and registry run keys.
Run a full scan with current definitions, followed by an offline scan if the threat returns. If Windows Security is disabled or the machine continues making suspicious connections, do not keep trusting the installation. Back up documents after scanning them and perform a clean Windows reset or reinstall.
Reset passwords for local accounts, Microsoft accounts, email, file storage, and network equipment. Begin with administrator credentials, then rotate passwords for any account that logged into the infected computer. Enable multifactor authentication wherever the service supports it.
Restore Files and Verify the Network
Before reconnecting a cleaned system, patch Windows, browsers, VPN software, router firmware, and NAS applications. Turn off SMBv1 if it is still enabled, restrict file sharing to private networks, and use strong passwords for every shared resource.
Check each device for the same indicators, including unknown accounts, altered firewall rules, new shares, and unexplained outbound connections. A worm can remain on an old laptop, printer server, or rarely used Windows PC and reinfect the main computer later.
Checks before reconnection
- Confirm the hidden share is gone or authorised
- Verify no unknown administrator accounts remain
- Review recent logons and scheduled tasks
- Scan removable drives before opening them
Reduce the Chance of Another Outbreak
Keep backups offline or protected from ordinary network credentials. Test restoring files periodically, because a backup connected permanently to the network may be encrypted or deleted by malware using stolen administrator access.
On a home network, separate smart-home devices and guest users from computers holding personal or business files. In Australia, many households combine an NBN gateway, mesh Wi-Fi, streaming boxes, work laptops, and a NAS; segmentation reduces the damage when one device is compromised.
Basic prevention guidance and security updates are available through Pc Malware Expert, while Australian users can also consult the Australian Cyber Security Centre for current threat advice. For business environments, document who can access shared folders and remove old accounts when staff or contractors leave.
Know When Professional Help Is Necessary
Escalate quickly if the worm reached a server, point-of-sale system, accounting computer, or shared customer records. A local IT security provider can collect logs, identify the first infected host, and check whether sensitive data was copied. Australian businesses may also need to consider privacy and breach-reporting obligations.
Seek specialist assistance when encryption, credential theft, repeated reinfection, or widespread lateral movement is involved. Preserve suspicious emails, filenames, timestamps, and firewall records instead of wiping every device immediately.
Warning signs that require escalation
- The worm returns after a clean reinstall
- Multiple sites or offices show matching activity
- Administrator, banking, or customer credentials may be exposed
- Shared files are renamed, encrypted, or deleted
A hidden share is a symptom of unauthorised access, not the whole infection. Removing the worm, securing credentials, checking every connected device, and hardening file-sharing settings together gives the network a much better chance of staying clean.