Page 1 of 2 12 LastLast
Results 1 to 15 of 16

Thread: virus/trojan/worm on an external drive

  1. #1
    Potato's Avatar

    poe-tay-toe

    Join Date
    Feb 2003
    Location
    MN
    Posts
    7,143

    virus/trojan/worm on an external drive

    How would you guys get rid of a virus/trojan/worm on an external drive?
    Now stop being so freaking nice, and buy a stun gun. - Krell

  2. #2
    thelastfreeman's Avatar

    Amateur Proctologist

    Join Date
    Jun 2007
    Posts
    1,026
    Scan the drive, isolate non system files like docs, vids, etc and trash the rest. But if you already know where it is, it wouldn't be hard to remove the virii. Could you give me more details
    Too lazy to Google? No problem.
    Let me google that for you!

    Read this before begging for invites
    Private Tracker-How To Guide

  3. #3
    mountain_rage's Avatar

    Zeropaids nipple

    Join Date
    Mar 2004
    Location
    purgatory
    Posts
    7,069
    Boot into safe mode and run various virus scanners.
    Anyone upset or offended by my post please follow the link and let your opinions be known.
    http://www.zeropaid.com/bbs/showthread.php?t=55492

  4. #4
    wapazoid's Avatar

    Registered User

    Join Date
    Jun 2003
    Location
    Under your BED
    Posts
    1,389
    Quote Originally Posted by Potato View Post
    How would you guys get rid of a virus/trojan/worm on an external drive?
    What reported the virus? Is it not capable of taking care of the problem?

  5. #5
    Drew Wilson's Avatar

    AKA IceCube

    Join Date
    Dec 2007
    Location
    Igloo Country?
    Posts
    9,660
    Most anti-virus programs at least tell you where the problem is. In Norton Antivirus, where it says it detected a virus, there's a way to export the log. Just export it to somewhere on your computer where you know you'll find it, then open it up (it's a text file) and scroll down to the virus on the external. It should have a file path that tells you where it's at (along with some other technical info along with it)

    I don't know what anti-virus software you are using, but if it's Norton, that should help. :)

  6. #6
    carpefile's Avatar

    Chronic

    Join Date
    Aug 2003
    Location
    Omnipresent
    Posts
    1,414
    The virus will only do its thing on your OS drive. If your external is just archives, and you haven't activated the virus yet, just delete it.

    If it has already delivered its payload, you can still just delete it from your external, but you're also gonna have to disinfect your OS.
    Nobody can start over and make a new beginning, but anyone can start today and make a new ending.

  7. #7
    Potato's Avatar

    poe-tay-toe

    Join Date
    Feb 2003
    Location
    MN
    Posts
    7,143
    Kaspersky's the antivirus.

    XP Pro's the OS.


    http://www.precisesecurity.com/blogs...sycledbootcom/ <-- This helped (comments 24 and 25) some, I think, but I'm sick of testing and being fucked again.

    I can't open either the C: or the external when it's connected, at least, not via My Computer. I can explore just fine.

    I'm still getting a "Windows cannot find 'resycled\boot.com' message when accessing either.



    P.S. You guys are quick. Thanks for the replies :)
    Now stop being so freaking nice, and buy a stun gun. - Krell

  8. #8
    Dark Messenger's Avatar

    Pervy sage

    Join Date
    Apr 2002
    Location
    Alone, in the dark...usually
    Posts
    997

    my 2 cents

    Quote Originally Posted by Potato View Post

    I can't open either the C: or the external when it's connected, at least, not via My Computer. I can explore just fine.

    I'm still getting a "Windows cannot find 'resycled\boot.com' message when accessing either.
    Usually that is a problem with it being called from in the path.

    I liked this suggestion pretty good from the link you provided:

    I got rid of the problem by simply removing s file called autorun.inf from the root directory of my hard drive and it also worked for my USB memory stick when I removed the same file from the root of that drive.
    Being able to follow those very difficult and tedious instructions in steps 24 and 25 shows you have the capacity for getting this fixed.

    You've narrowed down some of the problem and found out you can still access both drives with the explorer view...

    From here I'd make sure that under folder options you can see all hidden file types even system files and that show all file extensions is selected even for known file types.

    Look for that 'autorun.inf' file they are talking about..don't delete it...just make a new folder for it on your c:\ drive and move the autorun.inf into it..if you have it and can see it on your c:\ drive.

    Then do the same thing with your external drive...what drive letter does your computer assign to your external drive?
    Anyway do the same with your external drive for now I'm using 'X' to represent the drive letter for your external drive as I don't know that info yet..but look for that same file on it and create a new folder for it on the external and move it into it if it can be found.

    If the file moves in both places with no errors..reboot and see what you get.

    Also make sure you have the lastest version of hijack this in the zip archive format and extract its contents to its own folder. rename the hijack this folder 'happy' (all lowercase no quotes) then rename the main executable of hijackthis.exe (or whatever its called to 'addon.exe' again alll lower case and without quotes)

    2) now double-click on the the renamed hijackthis.exe program now called 'addon.exe' and run a scan...post us a log of the scan you did with hijack this here so we can help you figure out what's calling up the path for 'boot.com'

    the reason for the renaming is because some viruses and malware look for the hjthis.exe (or whatever the original name for its called) and deliberately hide from it..renaming it as suggested will give you a better chance of getting more accurate results.

    Neway good luck with this.

    -DM

  9. #9
    RACKnRAIL's Avatar

    今は知っているでしょ

    Join Date
    Apr 2003
    Location
    an island in the pacific
    Posts
    6,540
    Have you fixed your stick?

    This tool looks like it may be of use. I have not tried it, but it may be worth a try. Good for future use too.
    -----------®N®----------


    あなたをファック

  10. #10
    shawners's Avatar

    Hurt no more my son.

    Join Date
    Dec 2002
    Location
    An angel in Heaven and on Earth
    Posts
    7,899
    With gasoline and a match. Format =)

  11. #11
    w31n3r's Avatar

    Stop 0x0000007B

    Join Date
    Sep 2007
    Location
    Huh?
    Posts
    1,345
    had a similiar problem once, licked it with a little (more than a little actually) help from the master himself. might want to check it out.
    http://www.zeropaid.com/bbs/showthre...ndows+explorer

  12. #12
    Potato's Avatar

    poe-tay-toe

    Join Date
    Feb 2003
    Location
    MN
    Posts
    7,143
    Okay... I moved the autorun.inf file on the C: and the E: into different folders on each.

    Opening either drive from My Computer still gave the same message.

    I found some registry cleaner and ran that. It wanted me to pay, and I didn't, so it only "fixed" 15. I rebooted, then opening any drive brought up a search window. Found a fix for that, and now everything works beautifully.

    What should I do with those autorun.inf files?
    Now stop being so freaking nice, and buy a stun gun. - Krell

  13. #13
    Dark Messenger's Avatar

    Pervy sage

    Join Date
    Apr 2002
    Location
    Alone, in the dark...usually
    Posts
    997
    Quote Originally Posted by Potato View Post
    Okay... I moved the autorun.inf file on the C: and the E: into different folders on each.

    Opening either drive from My Computer still gave the same message.

    I found some registry cleaner and ran that. It wanted me to pay, and I didn't, so it only "fixed" 15. I rebooted, then opening any drive brought up a search window. Found a fix for that, and now everything works beautifully.

    What should I do with those autorun.inf files?
    you can safely delete them...or if you don't mind could you put them together in a zip file and upload them here as an attachment for me to look at?

    It's optional of course.

    Glad you got things sorted.

    oh and btw what was the fix with the search window deal....and for the sake of completeness which registry cleaner did you use?

  14. #14
    carpefile's Avatar

    Chronic

    Join Date
    Aug 2003
    Location
    Omnipresent
    Posts
    1,414
    Here's an excellent freeware reg cleaner. It won't stop at 15 ;)
    http://www.freewarefiles.com/RegScru...ram_40487.html
    Nobody can start over and make a new beginning, but anyone can start today and make a new ending.

  15. #15
    Potato's Avatar

    poe-tay-toe

    Join Date
    Feb 2003
    Location
    MN
    Posts
    7,143
    hey random mod, thanks for editing the title (but not really)


    Fix for the issue of it opening a search window all the time: http://windowsxp.mvps.org/searchwindow.htm

    Modified value at HKEY_CLASSES_ROOT \ Drive \ shell to say "none"
    Now stop being so freaking nice, and buy a stun gun. - Krell

Page 1 of 2 12 LastLast

Similar Threads

  1. Convert your External Drive to NTFS w/out reformating
    By Mels_Smileys45 in forum Windows
    Replies: 24
    Last Post: February 1st, 2010, 09:23 AM
  2. Expanding Your PS3's Storage Capacity Guide!
    By itani in forum Sony Playstation
    Replies: 5
    Last Post: August 30th, 2008, 08:17 PM
  3. hard drive problem
    By cLuELeSS in forum General Computing
    Replies: 23
    Last Post: May 12th, 2008, 12:32 AM
  4. FarStone Virtual Hard Drive 2 Pro
    By mohamedrias in forum The Lounge
    Replies: 1
    Last Post: October 27th, 2007, 12:30 PM
  5. Replies: 0
    Last Post: March 12th, 2006, 04:42 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •