Solved USB Flash full of viruses! What do I do?

  • Thread starter Thread starter The Blessed One
  • Start date Start date
T

The Blessed One

Guest
Hello,

So my friends laptop is infested with viruses so I'm gonna do a clean Windows 7 install to freshen it up.

But he had some important stuff on it which he transferred to a USB flash drive. I know that USB is gonna be infested with viruses now. So how do I delete the viruses on the USB drive without them transferring to the clean Windows 7 copy?

Thanks. :)
 
Hello,

So my friends laptop is infested with viruses so I'm gonna do a clean Windows 7 install to freshen it up.

But he had some important stuff on it which he transferred to a USB flash drive. I know that USB is gonna be infested with viruses now. So how do I delete the viruses on the USB drive without them transferring to the clean Windows 7 copy?

Thanks. :)

Hi,

you have few possibilities:

1. Use virtual machine for that, ie. install free VirtualBox (Sun) VirtualBox
2. Use special Shadow mode (software like Returnil or Shadow Defender) - with restart all changes are gone.
3. Use DefenseWall with USB drive run as Untrusted box checked in Options of this program. It will isolate your USB drives from rest of your system.
4. Do image backup and move it on another partition/drive, then put in infected USB drive and clean it by AV/AS/AM etc... after that your OS will be probably infected so do restore from image backup which have you done earlier, before putting in infected USB drive.
5. Use software Panda USB Vaccine: Panda USB Vaccine - Free software downloads and software reviews - CNET Download.com
 

My Computer My Computer

At a glance

Windows 7 Home Premium x32 SP1x2 2.6 GHzA-Data 2GB DDR2-800ATI X1250
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Windows 7 Home Premium x32 SP1
CPU
x2 2.6 GHz
Motherboard
Asus
Memory
A-Data 2GB DDR2-800
Graphics Card(s)
ATI X1250
Sound Card
SB 5.1 Live!
Hard Drives
WD and Seagate FAP
PSU
Tagan TG-480-U01
Keyboard
BTC 6300
Mouse
Logitech VX Nano
Antivirus
None
  • Like
Reactions: JMH

Attachments

  • PandaUSBvaccine.jpg
    PandaUSBvaccine.jpg
    35.5 KB · Views: 13

My Computer My Computer

At a glance

Windows 7 x64Intel Core2 Extreme Q6850 3.00GHz8 GBRadeon R7 260X
Computer type
PC/Desktop
OS
Windows 7 x64
CPU
Intel Core2 Extreme Q6850 3.00GHz
Motherboard
EVGA 132-CK-NF79
Memory
8 GB
Graphics Card(s)
Radeon R7 260X
Sound Card
Xonar DS
Hard Drives
Hitachi Deskstar 1 tb
Hi, The Blessed One. You could have your friend use USBNoRisk. It was created and maintained by a well known member of the security community. The instructions follow:

-- Download USBNoRisk to your Desktop and run it by double-clicking the program's icon.
-- Wait a couple of seconds for initial scan to be done.
-- Connect all of the USB storage devices to the PC, one at a time, and keep each one connected at least for 10 seconds

Explanation: USB storage devices are all the USB devices that get their own partition letter at connecting to the PC, e.g. flash drives (thumb/pen drives, USB sticks), external HDDs, MP3/MP4 players, digital cameras, memory cards (SD cards, Sony Memory Stick, MultiMedia Cards etc.), some mobile phones, some GPS navigation devices etc.
 

My Computer My Computer

At a glance

Windows 7 & Windows Vista Ultimate
OS
Windows 7 & Windows Vista Ultimate
+1 On Panda UsbVaccine. ;) It's a good tool. :)
 

My Computer My Computer

At a glance

Win 7 Ultimate SP1 x64Intel Pentium Dual Core E5300 OC'd @ 3GHzKingston 2x2GB DDR2-800 Dual Channel SDRAMIntegrated Intel GMA X4500
Computer Manufacturer/Model Number
D3f's Customs
OS
Win 7 Ultimate SP1 x64
CPU
Intel Pentium Dual Core E5300 OC'd @ 3GHz
Motherboard
Asus P5G41-M LE
Memory
Kingston 2x2GB DDR2-800 Dual Channel SDRAM
Graphics Card(s)
Integrated Intel GMA X4500
Sound Card
Realtek 5.1 HD Audio (ALC887)
Monitor(s) Displays
LG Flatron W1943S @ 60Hz
Screen Resolution
1360 x 768
Hard Drives
Internal - WD Caviar Blue 500GB, External - WD My Passport Essential 500GB
PSU
Headway 450w PSU
Case
Pixxo Slim Black mATX Case
Cooling
Stock Cpu Fan, 1 x Top Case Fan
Keyboard
Logitech K120
Mouse
Logitech LS1 Laser Mouse
Internet Speed
17.66Mb/s Down, 0.82Mb/s Up
Other Info
Creative SBS A300 2.1 Speaker System, LG GH22NS50 22x Internal Super-Multi DVD-RW, 2Wire 5012NV Wireless Modem Router
and keep each one connected at least for 10 seconds

Corrine, What is it doing in these 10 seconds. It could not be a fulll scan - or?
 

My Computer My Computer

At a glance

Vista, Windows7, Mint Mate, Zorin, Windows 8from 1.6GHz Duo to i7
Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
It will scan for and block any autorun's.
 

My Computer My Computer

At a glance

Windows 7 & Windows Vista Ultimate
OS
Windows 7 & Windows Vista Ultimate
It will scan for and block any autorun's.

Thanks Corrine, that's good to know. I will suggest it to the equipment director in our computer club because we get most of the infections from people bringing in sticks or SD cards.
 

My Computer My Computer

At a glance

Vista, Windows7, Mint Mate, Zorin, Windows 8from 1.6GHz Duo to i7
Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
What about USB Disk Security? Is it any good?
 

My Computer My Computer

At a glance

Microsoft Windows 7 Ultimate 64-bit 7601 Mult...Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz8.00 GBNVIDIA GeForce GTX 660
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Microsoft Windows 7 Ultimate 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz
Motherboard
ASUSTeK COMPUTER INC. P8Z77-V
Memory
8.00 GB
Graphics Card(s)
NVIDIA GeForce GTX 660
Sound Card
(1) USB Audio Device (2) High Definition Audio Device (3
Screen Resolution
1360 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
(1) M4-CT128M4SSD2 ATA Device (2) WDC WD1002FAEX-00Z3A0 ATA Device (3) WDC WD10EZEX-22BN5A0 ATA Device
PSU
Corsair Enthusiast Series TX650M
Case
NZXT Phantom 410
Cooling
Cooler Master Hyper 212 EVO
Keyboard
Logitech HID-Compliant Keyboard
Mouse
Logitech HID-compliant MX320 Laser Mouse
What about USB Disk Security? Is it any good?

Now that's overpriced security software. Panda USB Vaccine is much better and its free...
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32-bit Version 6.1 (build ...Intel Pentium Dual CPU T2390 @ 1.86GHzSiS Mirage 3 Graphics SiS627 series
Computer Manufacturer/Model Number
Neo Vivid V2121
OS
Windows 7 Ultimate 32-bit Version 6.1 (build 7600.16385)
CPU
Intel Pentium Dual CPU T2390 @ 1.86GHz
Motherboard
SiS M720SR
Graphics Card(s)
SiS Mirage 3 Graphics SiS627 series
Sound Card
Built-in
Monitor(s) Displays
Generic PnP Monitor
Screen Resolution
1280x800
Hard Drives
Fujitsu MHZ2160BH G1 ATA Device 160GB
Keyboard
Standard PS/2 Keyboard
Mouse
Synaptics PS/2 Port Pointing Device
Isn't it possible to disable autorun, or did this disappear with Windows 7?

If it is still there, don't you just disable it, and scan with whatever scanner you have?

Surely there must be a setting somewhere to ensure that a USB can't be plugged in by a sociopath and automatically infect a library system.
 

My Computer My Computer

At a glance

Windows 7 Home Premium (64 bit)AMD Athlon 56 X2 5000+4.0 GBSapphire HD 4350 fanless w/512MB
Computer Manufacturer/Model Number
Gateway GM5472
OS
Windows 7 Home Premium (64 bit)
CPU
AMD Athlon 56 X2 5000+
Motherboard
ECS MCP61P-AM
Memory
4.0 GB
Graphics Card(s)
Sapphire HD 4350 fanless w/512MB
Monitor(s) Displays
VeiwSonic VX2035WM
Screen Resolution
1680x1050
Other Info
Stock system except for the addition of 2GB memory, a Swann PCDVR 4 Card and a Hauppage dual HD tuner and a Sapphire HD 4550 video card
I came across a tool "USB Vaccin" which not only stops the autorun and the spreading of the infection, but also prevents your thumb drive from getting some very common infections while using it at work or on a friend's computer: It creates a set of hidden, read-only folders with the following name scheme : malware_name.extension.
Among the created folders :
Autorun.exe
Adobe.exe
Adober.exe
svchost.exe ....

To distinguish these legitimate folders from actual malwares; hover the mouse and a the description popup will show you that they all contain the same text file (a description file).

Scanning a vaccin-ed drive will report as clean, the software itself (USB Vaccin) is being detected (falsely) as some sort of trojan dropper.

If the moderators agree, I'll post it here as a zip archive

Source : Infections par supports amovibles - Forums Zebulon.fr (French forum, use google translate)
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64Intel Core 2 Quad Q6600 @2.40 GHz8GB Transcend DDRII-800 @ 888MSI NVIDIA GeForce GT 240 / 1GB DDR3
Computer Manufacturer/Model Number
~DIY
OS
Windows 7 Ultimate x64
CPU
Intel Core 2 Quad Q6600 @2.40 GHz
Motherboard
Gygabyte P35-DS3L
Memory
8GB Transcend DDRII-800 @ 888
Graphics Card(s)
MSI NVIDIA GeForce GT 240 / 1GB DDR3
Sound Card
Integrated Realtek HD Audio ALC888
Monitor(s) Displays
Samsung SyncMaster 226BW 22"
Screen Resolution
1680*1050
Hard Drives
2 x WD Caviar Green 1TB (WDC WD10EADS)
PSU
Unnamed 550W
Case
Naked chassis
Cooling
Lots of fans
Keyboard
A4 Tech A-Shape PS/2 Keyboard
Mouse
eBox USB Mouse
Internet Speed
1 Mbps\512 Kbps (through a very very bad ISP)
Other Info
Currently undervolting the CPU to reduce the fan's noise
Just use Sandboxie to isolate it and keep it from spreading and +1 for Panda.
 

My Computer My Computer

At a glance

Windows 7 Enterprise 64-bitAMD Phenom II X4 3.0GHz8GB G-Skill Ripjaws DDR3 1333PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
OS
Windows 7 Enterprise 64-bit
CPU
AMD Phenom II X4 3.0GHz
Motherboard
ASUS M5A97
Memory
8GB G-Skill Ripjaws DDR3 1333
Graphics Card(s)
PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
Sound Card
VIA High Definition Audio
Monitor(s) Displays
Dell 19"
Screen Resolution
1280x1024
Hard Drives
1TB - Primary
160GB - Secondary
250GB - External backup for important files
PSU
OCZ Fata1ty 700W Modular PSU
Case
ASUS
Keyboard
Microsoft Wireless Keyboard 2000
Mouse
Microsoft Wireless Mouse 2000
Internet Speed
3 Mbps/768 kbps
Isn't it possible to disable autorun, or did this disappear with Windows 7?

If it is still there, don't you just disable it, and scan with whatever scanner you have?

Surely there must be a setting somewhere to ensure that a USB can't be plugged in by a sociopath and automatically infect a library system.
Sure, you can disable autoplay in Control Panel\Hardware and Sound\AutoPlay
 

My Computer My Computer

At a glance

Vista, Windows7, Mint Mate, Zorin, Windows 8from 1.6GHz Duo to i7
Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
Isn't it possible to disable autorun, or did this disappear with Windows 7?

If it is still there, don't you just disable it, and scan with whatever scanner you have?

Surely there must be a setting somewhere to ensure that a USB can't be plugged in by a sociopath and automatically infect a library system.
Sure, you can disable autoplay in Control Panel\Hardware and Sound\AutoPlay
.
I've read that Auto-Play and Auto-Run are not exactly the same thing. Are you sure that disabling Auto-Play in the Control Panel prevents the autorun.inf file on a USB drive from running?
 

My Computer My Computer

At a glance

Windows 7 x64Intel Core2 Extreme Q6850 3.00GHz8 GBRadeon R7 260X
Computer type
PC/Desktop
OS
Windows 7 x64
CPU
Intel Core2 Extreme Q6850 3.00GHz
Motherboard
EVGA 132-CK-NF79
Memory
8 GB
Graphics Card(s)
Radeon R7 260X
Sound Card
Xonar DS
Hard Drives
Hitachi Deskstar 1 tb
Until the introduction of Windows XP, the terms AutoRun and AutoPlay were used interchangeably, developers often using the former term and end users the latter. This tendency is reflected in Windows Policy settings named AutoPlay that change Windows Registry entries named AutoRun, and in the autorun.inf file which causes "AutoPlay" to be added to drives’ context menus. The terminology was of little importance until the arrival of Windows XP and its addition of a new feature to assist users in selecting appropriate actions when new media and devices were detected. This new feature was called AutoPlay and a differentiation between the two terms was created.[1]

AutoPlay is a feature introduced in Windows XP which examines removable media and devices and, based on content such as pictures, music or video files, launches an appropriate application to play or display the content.[1] If available, settings in an autorun.inf file can add to the options presented to the user.

Just use the Panda USB Anti-Virus tool and it'll do everything for you.
 

My Computer My Computer

At a glance

Windows 7 Enterprise 64-bitAMD Phenom II X4 3.0GHz8GB G-Skill Ripjaws DDR3 1333PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
OS
Windows 7 Enterprise 64-bit
CPU
AMD Phenom II X4 3.0GHz
Motherboard
ASUS M5A97
Memory
8GB G-Skill Ripjaws DDR3 1333
Graphics Card(s)
PNY GeForce 460 GTX 1GB OC - Enthusiast Edition
Sound Card
VIA High Definition Audio
Monitor(s) Displays
Dell 19"
Screen Resolution
1280x1024
Hard Drives
1TB - Primary
160GB - Secondary
250GB - External backup for important files
PSU
OCZ Fata1ty 700W Modular PSU
Case
ASUS
Keyboard
Microsoft Wireless Keyboard 2000
Mouse
Microsoft Wireless Mouse 2000
Internet Speed
3 Mbps/768 kbps
Thanks for the Panda USB Vaccine, it worked great. I had heard of this software but didn't realise it could be so useful!

I was a bit worried at first though as the vaccine disabled autorun, but when I connected the USB flash, the 'AutoPlay' pop-up appeared asking me what to do. This must be different to the 'AutoRun'? Anyway I used Avast 5 free to scan the flash and indeed there two worms in there! The threat level was classed as 'High'. Avast just wiped them out with ease as usual. This new version 5 is a great antivirus! :D
 
Thanks for the Panda USB Vaccine, it worked great. I had heard of this software but didn't realise it could be so useful!

I was a bit worried at first though as the vaccine disabled autorun, but when I connected the USB flash, the 'AutoPlay' pop-up appeared asking me what to do. This must be different to the 'AutoRun'? Anyway I used Avast 5 free to scan the flash and indeed there two worms in there! The threat level was classed as 'High'. Avast just wiped them out with ease as usual. This new version 5 is a great antivirus! :D
May I suggest that you scan this stick with some more scanners. As good as Avast may be, it could have missed some. Superantispyware and Malwarebytes come to mind. And if you want to be really thorough, send the files here: VirusTotal - Free Online Virus and Malware Scan
 

My Computer My Computer

At a glance

Vista, Windows7, Mint Mate, Zorin, Windows 8from 1.6GHz Duo to i7
Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
Back
Top