Storage Trojan Virus in my Friends USB How Can he delete it without Formating

Discussion in 'Tech Support' started by Dark_Master_Dragon, 3 Feb 2009.

  1. Dark_Master_Dragon

    Dark_Master_Dragon Beware of my lair!!!

    Joined:
    22 Jan 2009
    Posts:
    82
    Likes Received:
    0
    My friend Cody has a Trojan Virus he doesnt want to format it and lose his stuff is there anyway to clean out the Virus? The only thing i know was that the Virus came from C.S portable 1.6 meaning that the game had the virus and eventually it got into codys flashdrive.

    Ideas please?:wallbash::wallbash::wallbash:.

    C.S portable 1.6
    Meaning Counter Strike 1.6
     
    Last edited: 3 Feb 2009
  2. Nexxo

    Nexxo * Prefab Sprout – The King of Rock 'n' Roll

    Joined:
    23 Oct 2001
    Posts:
    34,540
    Likes Received:
    1,932
    How does he know that he has one?
     
  3. Dark_Master_Dragon

    Dark_Master_Dragon Beware of my lair!!!

    Joined:
    22 Jan 2009
    Posts:
    82
    Likes Received:
    0
    :(

    i watched him loading C.S and when it finished extracting it shows this box saying Trojan Virus
    after that i told him to restart his computer and found out that nothing wrong except when he plug his USB it wont open :wallbash::wallbash:.
     
  4. C-Sniper

    C-Sniper Stop Trolling this space Ądmins!

    Joined:
    17 Jun 2007
    Posts:
    3,028
    Likes Received:
    126
    If you can Isolate the file that is infected then you should be able to clean it before you extract it.
     
  5. Dark_Master_Dragon

    Dark_Master_Dragon Beware of my lair!!!

    Joined:
    22 Jan 2009
    Posts:
    82
    Likes Received:
    0
    Ok

    give me a sec he right beside me.:D
     
  6. Dark_Master_Dragon

    Dark_Master_Dragon Beware of my lair!!!

    Joined:
    22 Jan 2009
    Posts:
    82
    Likes Received:
    0
    Back

    It Seems like that he cant open C.S anymore and he cant get into his Flash Drive my advice for him is to get a new one what you think?
    :eyebrow:
     
  7. C-Sniper

    C-Sniper Stop Trolling this space Ądmins!

    Joined:
    17 Jun 2007
    Posts:
    3,028
    Likes Received:
    126
    Have you tried getting the flash drive on another PC? I think that your AV has it locked down on the current PC.
     
  8. Ransoman

    Ransoman What's a Dremel?

    Joined:
    18 Jul 2008
    Posts:
    105
    Likes Received:
    0
    Open the USB drive on a "disposable" pc (with full up-to date anti-virus).
    Ensure "hidden files" "hide system files" and "do not show file extentions" are unchecked.
    "explore" (not open) the contents of the drive and delete every file with the following extention on the Root of the drive:

    .bat
    .exe
    and finally, Autorun.inf

    Virus scan the whole drive and pc when you are done.

    I do this every day so i have the technique down to an art.
     
  9. Kúsař

    Kúsař regular bit-tech reader

    Joined:
    23 Apr 2008
    Posts:
    317
    Likes Received:
    4
    I don't think it's good idea to plug infected drive to your PC - if there's autorun.inf on flashdrive it might infect registry in your PC as well because WinXP will autoexecute it and make changes to registry even though you keep 'shift' pressed(but at least it won't run virus).

    Plug flashdrive into your friend's PC. If there are no sensitive data - format it. He can't open flashdrive because virus has probably made changes to registry. But it can be fixed quite easily.
    1) open regedit and navigate to:
    HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ MountPoints2
    Inside MountPoints2 is list of all drives and actions associated with them - they are represented by 32 digit string - {###.....}.

    2) Now you need to find which one is flashdrive. But it would be good idea to check all of them.
    When you expand {###} there should be only one of these keys:
    shell - make sure default value is 'none'.
    or
    _autorun - default value: none
    Delete every value that refers to suspicious .exe file.
    If there is mess you can delete these sub-keys and keep only 32 digit string key, Windows will create new sub-keys as necessary.

    When virus change one of these keys you usually run virus when you try to access flashdrive or even HDD because it executes different command(something like this: "rundll32 virus.exe, ###"). After virus is executed it opens up explorer so that everything looks OK. So if you delete virus - windows keeps trying to execute this command but nothing happens, because virus executable is gone. In some cases windows display "missing file" warning message when you doubleclick drive(depends on what command it execute).
     
    Last edited: 4 Feb 2009
  10. mm vr

    mm vr The cheesecake is a lie

    Joined:
    18 Nov 2007
    Posts:
    2,968
    Likes Received:
    84
    You mention it's a portable. Portables are usually made with Thinstall/ThinApp. Some stupid virus scanners flag these portables as viruses. They are false positives, though.

    What AV are you / he running?
     
  11. Dark_Master_Dragon

    Dark_Master_Dragon Beware of my lair!!!

    Joined:
    22 Jan 2009
    Posts:
    82
    Likes Received:
    0
    Re:What AV are you/He running

    Just so you know its cody that has the virus hes my best friend thats why im helping him and its Window XP and the flashdrive is 1gig Lexar
     
  12. Cupboard

    Cupboard I'm not a modder.

    Joined:
    30 Jan 2007
    Posts:
    2,148
    Likes Received:
    30
    And the antivirus is...?
    If you have access to a Linux machine that would be immune from the virus so you could scan it / save data from it without risks, otherwise ^what they said
     
  13. tranc3

    tranc3 ADHD Modder

    Joined:
    16 Jul 2007
    Posts:
    1,622
    Likes Received:
    13
    Use a live CD of what ever Linux distro your happy with, and delete the files that you believe are dangerous. That way you don't have to worry about it sneaking in on your other drive.
     
  14. Dark_Master_Dragon

    Dark_Master_Dragon Beware of my lair!!!

    Joined:
    22 Jan 2009
    Posts:
    82
    Likes Received:
    0
    Problem Solved

    Silly really what happen was that he copy and pasted every program and folders that were important and reformat his USB it.

    The USB is able to open now thank you all for the Handy advices :thumb:.

    And repasted it back to his USB
     
  15. Akava

    Akava Lurking...

    Joined:
    28 Jul 2007
    Posts:
    1,213
    Likes Received:
    26
    Exactly what I was gonna say, I had to use my linux box to clear a virus from my USB that i picked up from college of all places, worked nicely though.
     
  16. davidfield375

    davidfield375 Hardware Mods

    Joined:
    3 Feb 2009
    Posts:
    95
    Likes Received:
    1
    Why not format everything then run an un-format tool and only select the files you need. Not 100% sure that the Trojan could infect your PC from the un-format program, but I would safely say that it wouldn't.
     
  17. Dark_Master_Dragon

    Dark_Master_Dragon Beware of my lair!!!

    Joined:
    22 Jan 2009
    Posts:
    82
    Likes Received:
    0
    Re:David

    Thanks for the advice for my friend aready finished formating and its been a couple of days and everything is going well for there is no need more more adivces but i thank you for the idea.
     
  18. nitrous9200

    nitrous9200 What's a Dremel?

    Joined:
    4 Oct 2007
    Posts:
    131
    Likes Received:
    3

Share This Page