removal of Autorun.inf/svchost.exe virus on flashdrive

Discussion in 'Computer Gaming Forum' started by 3do, Apr 22, 2010.

  1. 3do

    3do Segata Sanshiro!

    Joined:
    Sep 25, 2006
    Messages:
    1,901
    Likes Received:
    12
    So i've got a 4GB USB flash drive which has Autorun.inf/svchost.exe files on which are being detected as viruses but i cannot get rid of them and need advice.

    I tried a quick format and then a normal format in windows but no luck there as they just keep coming back. I then tried a few method i read online which used the windows command prompt but that didn't work either as the files came back.

    How do i get rid of these files from my flash drive so that that they don't come back because i've tried several methods and none work.

    Cheers
     
  2. Twimfy

    Twimfy Site Supporter 2015

    Joined:
    Apr 10, 2006
    Messages:
    3,570
    Likes Received:
    32
    Erm surely if you format the drive then they should be gone. Seems to me like the infected files are on your PC and are just duplicating to the flash drive each time you format it.

    Thoroughly disinfect your PC first. Then format the drive.
     
  3. Johnny

    Johnny Gran Turismo Freak and Site Supporter 2013,2015

    Joined:
    Mar 14, 2004
    Messages:
    6,230
    Likes Received:
    397
    My best suggestion would be to google the Virus name and check how to get rid of it.

    I had 2 USB pendrives with virus in the last 6 months, and each one had a different virus that need a different way of getting the drive cleaned. One of those even used two command line programs to getting rid of it.

    Anyway, after cleaning it, make sure you lock the autorun.inf on the drive (so it won't get infected - and even if it does, it won't run - easier to delete) and disable autorun in XP/Vista/7.
     
    Last edited: Apr 22, 2010
  4. mairsil

    mairsil Officer at Arms

    Joined:
    Apr 20, 2005
    Messages:
    3,425
    Likes Received:
    153
    Is it one of those flash drives that has its own built in software (e.g. Sandisk Cruzer)? If it is, it could be the "special" partition which is infected or it is continually reinstalling the files, which just happen to be picked up as viruses for some reason. You might need to get special removal software from the drive's manufacturer to get rid of any hidden software, as Windows generally either doesn't see the software/partition or it is locked out.
     
  5. phate

    phate Enthusiastic Member

    Joined:
    Feb 23, 2008
    Messages:
    540
    Likes Received:
    3
    I'd boot into another OS and nuke partitions on the sucker. I'd also run an Antivirus on my whole machine because it would seem that its not the flash drive that still has the infection.

    Actually that is a lie, if it where me I'd stop trusting my current install, backup my documents and blast the OS. But thats just me.
     
  6. cOcO!

    cOcO! Rising Member

    Joined:
    Mar 29, 2010
    Messages:
    68
    Likes Received:
    0
    The best way to PREVENT viruses in pendrives is to create a folder in the root of the drive called AUTORUN.INF. That way the autorun file will drop in there and will not be able to execute.
     
  7. madhatter256

    madhatter256 Illustrious Member

    Joined:
    Mar 13, 2004
    Messages:
    6,578
    Likes Received:
    4
    Download and install Avira. Removed this when I had my thumb drive infected.

    It will comeback even after a format as it copies itself on to the PC and writes itself to any thumbdrive you connect it to. This is how it spreads.
     
  8. 3do

    3do Segata Sanshiro!

    Joined:
    Sep 25, 2006
    Messages:
    1,901
    Likes Received:
    12
    It's not got a hidden partiton on it as I always get rid of those straight after I get drives with them on it.

    Did a scan of the C: drive with Avast which is the main AV program used, also scanned with malwarebytes
    and it seems clean so I think the virus may be on one of the external drives which I'll scan next.
     
  9. Yorkshire Remixer

    Yorkshire Remixer Newly Registered

    Joined:
    Jun 6, 2009
    Messages:
    4
    Likes Received:
    0
    yeh had the same problem at work; all machines seemed to have the same and also when you attempted to open c: it tries to open as a file??
    formatted usb stick; fine
    formatted pc; fine
    plugged in an external hdd and then all 3 got it again; if you have this virus it looks like you need to format every machine you have and virus check the files you want to keep.
     
  10. z_killemall

    z_killemall Familiar Face

    Joined:
    Dec 4, 2006
    Messages:
    1,116
    Likes Received:
    6
    Maybe you're connecting the flash drive to other computers with that virus on it, long ago when I used to go often to internet cafes I found that adding two dummy files named autorun.inf and svchost.exe (both empty) and flagging them as hidden and system files they couldn't be replaced. But as I said, that was many years ago, I don't know if these viruses are able to overwrite those files now.
     
  11. 3do

    3do Segata Sanshiro!

    Joined:
    Sep 25, 2006
    Messages:
    1,901
    Likes Received:
    12
    I think the problem has gone now??

    The USB drives have been formatted several times by now and when put in the original offending computer i no longer get any virus warning coming up plus i've re-instyalled windows 7 on my machine so if it was that then its gone.
     
  12. KIWIDOGGIE

    KIWIDOGGIE Peppy Member

    Joined:
    Jul 9, 2008
    Messages:
    357
    Likes Received:
    15
    DBAN = Best. Google it, its free, and it does a GREAT job of formatting HDD's.
     
sonicdude10
Draft saved Draft deleted
Insert every image as a...
  1.  0%

Share This Page