Need to clean an external hard drive that's badly infected.

Page 1 of 2 12 LastLast

  1. Posts : 637
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
       #1

    Need to clean an external hard drive that's badly infected.


    My parents had a desktop that was terribly infected and they copied all their important info to an external hardrive without cleaning or should i say before cleaning the computer . They then scrapped the old computer .

    Yeah i know , but anyway , how would i go about cleaning the stuff thats on this external hard drive so they can get their important info back clean?

    I have a clean computer to plug it into via USB but i'm nervous as hell.

    Thank you
      My Computer


  2. Posts : 369
    Windows 7 Pro 32bit
       #2

    If you are certain that your computer is clean, you can plug that external HD on it. But, before you do that , make sure that your AV and anti-malware software are up-to-date. To be sure on doing that, you can run your scan from Safe Mode.
      My Computer


  3. Posts : 7,781
    Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
       #3

    Also, make sure to verify that your AV settings are indeed set to scan external drives. If it is set up like this, your AV should scan the drive immediately when you plug it in & start trying to disinfect any infections.
      My Computer


  4. Posts : 637
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #4

    Thanks guys , yeah i can scan it with Kaspersky and other on demand scanners but what i'm concerned with is many anti malware solutions that i tried to clean their machine with was ineffective .

    They had the Alereon rootkit , numerous Trojans , you name it , don't have much confidence in just scanning with a certain AV and expect to have everything wiped out.
      My Computer


  5. Posts : 2,470
    Windows 7 Home Premium
       #5

    jonnyhillow,

    Consider using the tool UsbFix:

    It can detect and remove infections found on removable devices such as an external hard drive.
    Download UsbFix

    Press: Download UsbFix Windows Installer- 3.73 MB | version: 7.812

    Next, please, temporarily disable your antivirus software so it does not interfere with the running of USBFix.

    Next, right-click the downloaded USBFix file and select: Run as Administrator

    Connect the external hard drive to your PC, turn it on (if powered), but, do not open it.
    At the main console of USBFix, press: Listing

    Once a scan is completed, a report is generated. It is normally found at C:\USBFix\Log
    Please post the Listing report in your reply.

    Once again, run USBFix as Administrator, but, this time, press: Research
    Also post the Research report in your reply.
      My Computer


  6. Posts : 7,781
    Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
       #6

    Once you get the files transferred you want to save, wiping the drive is probably the best option. Here is a list of drive erasers:

    Five hard disk cleaning and erasing tools - TechRepublic

    Also, TDSSKiller is a good rootkit cleaner, but there are others you can try:

    Five free portable rootkit removers - TechRepublic
      My Computer


  7. Posts : 637
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #7

    Been away for awhile, sorry guys . Finally got around to doing a few things as requested.



    Rapport


    ############################## | UsbFix V 7.901 | [Research]

    User: charles (Administrator) # CHARLES-PC
    Updated 25/02/2015 by El Desaparecido - SosVirus
    Started at 15:39:59 | 25/02/2015

    Website : UsbFix - Official Website
    Changelog : Changelog Archives
    Support : SosVirus
    Live detection : How To Remove ?
    Contact : Contact El Desaparecido, UsbFix author

    ################## | System information |

    MB: ASUSTeK Computer Inc. (U56E)
    CPU: Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz
    GC: Intel(R) HD Graphics 3000
    RAM -> [Total : 6049 Mo | Free : 4658 Mo]
    Bios: American Megatrends Inc.
    Boot: Normal boot

    OS: Microsoft™ Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1
    WB: Internet Explorer : 11.00.9600.16428
    WB: Opera : 27.0.1689.76

    ################## | Security Information |

    AV: Kaspersky Anti-Virus [(!) Disabled |Updated]
    AS: Kaspersky Anti-Virus [(!) Disabled |Updated]
    AS: Windows Defender [(!) Disabled |Updated]
    AS: Malwarebytes Anti-Malware : 2.0.4.1028
    FW: Windows Firewall [Enabled]
    SC: Security Center [Enabled]
    WU: Windows Update [Enabled]

    ################## | Disk Information |

    C:\ (%SystemDrive%) -> Fixed disk # 224 Gb (192 Gb free - 86%) [] # NTFS
    E:\ -> Fixed disk # 298 Gb (257 Gb free - 86%) [FreeAgent Drive] # NTFS

    ################## | Regedit Run |

    F2 - HKLM\..\Winlogon : [Shell] explorer.exe
    F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
    F2 - HKLM\..\Winlogon : [Userinit] userinit.exe
    F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
    04 - HKCU\..\Run : [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
    04 - HKLM\..\Run : [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
    04 - [x64] HKLM\..\Run : [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
    04 - [x64] HKLM\..\Run : [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
    04 - [x64] HKLM\..\Run : [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
    04 - [x64] HKLM\..\Run : [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3
    04 - [x64] HKLM\..\Run : [IntelWirelessWiMAX] "C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe" /tasktray /nosplash
    04 - [x64] HKLM\..\Run : [IgfxTray] "C:\Windows\system32\igfxtray.exe"
    04 - [x64] HKLM\..\Run : [HotKeysCmds] "C:\Windows\system32\hkcmd.exe"
    04 - [x64] HKLM\..\Run : [Persistence] "C:\Windows\system32\igfxpers.exe"
    04 - [x64] HKLM\..\Run : [Everything] "C:\Program Files\Everything\Everything.exe" -startup
    04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
    04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
    04 - HKU\S-1-5-21-2936650077-4203905920-2493637114-1000\..\Run : [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
    04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
    04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
    04GS - Secunia PSI Tray.lnk : C:\Program Files (x86)\Secunia\PSI\psi_tray.exe

    ################## | Generic Research |


    ################## | Registry |


    ################## | UsbFix - Information |

    Info : How to remove shortcut virus on flash disk (Video)
    Info : Shortcut virus on flash disk, What is it ?
    Live detection : How To Remove ?

    ################## | Hijack |


    ################## | E.O.F | SosVirus | UsbFix - Official Website |



    I don't know if any malware is present by the results , hoping someone can let me know.
    Need to clean an external hard drive that's badly infected. Attached Files
    Last edited by jonnyhillow; 25 Feb 2015 at 18:10.
      My Computer


  8. Posts : 2,470
    Windows 7 Home Premium
       #8

    jonnyhillow,

    Also need the Listing report.

    Thanks!
      My Computer


  9. Posts : 2,470
    Windows 7 Home Premium
       #9

    Duplicate - please disregard.
      My Computer


  10. Posts : 637
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #10

    cottonball said:
    jonnyhillow,

    Also need the Listing report.

    Thanks!






    UsbFix Report 428cad4671940b931f146f914481709db3340e2b.txt
    Need to clean an external hard drive that's badly infected. Attached Files
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 19:40.
Find Us