Results 1 to 12 of 12

Thread: removal of Autorun.inf/svchost.exe virus on flashdrive

  1. #1
    Wiiiiiiiiiiiiiiiiiiiiiiii iiiiiiiiiiiiiii Member Elite
    3do's Avatar

    Join Date
    Sep 2006
    Location
    Scotland
    Posts
    1,897

    removal of Autorun.inf/svchost.exe virus on flashdrive

    So i've got a 4GB USB flash drive which has Autorun.inf/svchost.exe files on which are being detected as viruses but i cannot get rid of them and need advice.

    I tried a quick format and then a normal format in windows but no luck there as they just keep coming back. I then tried a few method i read online which used the windows command prompt but that didn't work either as the files came back.

    How do i get rid of these files from my flash drive so that that they don't come back because i've tried several methods and none work.

    Cheers

  2. #2
    I don't like the "3000" Image below. ASSEMbler Soldier
    Twimfy's Avatar

    Join Date
    Apr 2006
    Location
    UK
    Posts
    3,111
    Erm surely if you format the drive then they should be gone. Seems to me like the infected files are on your PC and are just duplicating to the flash drive each time you format it.

    Thoroughly disinfect your PC first. Then format the drive.

  3. #3
    Gran Turismo Freak Staff


    Tribuni Angusticlavii
    Johnny's Avatar

    Join Date
    Mar 2004
    Location
    Rio de Janeiro, Brazil
    Posts
    4,845
    My best suggestion would be to google the Virus name and check how to get rid of it.

    I had 2 USB pendrives with virus in the last 6 months, and each one had a different virus that need a different way of getting the drive cleaned. One of those even used two command line programs to getting rid of it.

    Anyway, after cleaning it, make sure you lock the autorun.inf on the drive (so it won't get infected - and even if it does, it won't run - easier to delete) and disable autorun in XP/Vista/7.
    Last edited by Johnny; 04-22-2010 at 10:39 AM.

    A-Spec level: 28 / B-Spec level: 13
    Current car: Chevrolet Corvette Stingray Final Prototype 2014
    Number of cars on garage: 94 ( Check my Garage HERE )
    B-Spec driver shared: N.Schumacher - Class 13
    ## Cars available for trade : 2x Toyota CELICA XX 2800GT '81 ) ##


  4. #4
    ASSEMbler Soldier
    mairsil's Avatar

    Join Date
    Apr 2005
    Location
    Rockville, MD
    Posts
    3,033
    Is it one of those flash drives that has its own built in software (e.g. Sandisk Cruzer)? If it is, it could be the "special" partition which is infected or it is continually reinstalling the files, which just happen to be picked up as viruses for some reason. You might need to get special removal software from the drive's manufacturer to get rid of any hidden software, as Windows generally either doesn't see the software/partition or it is locked out.
    PouncingKitten Games
    Xbox 360 - Glide, Bingo Party, Poker Night, O.C.D.
    Flash - BunnyRun, Tic-Tac-Poker

  5. #5
    Combat Soldier
    phate's Avatar

    Join Date
    Feb 2008
    Location
    West Jordan, Utah
    Posts
    540
    Quote Originally Posted by 3do View Post
    So i've got a 4GB USB flash drive which has Autorun.inf/svchost.exe files on which are being detected as viruses but i cannot get rid of them and need advice.

    I tried a quick format and then a normal format in windows but no luck there as they just keep coming back. I then tried a few method i read online which used the windows command prompt but that didn't work either as the files came back.

    How do i get rid of these files from my flash drive so that that they don't come back because i've tried several methods and none work.

    Cheers
    I'd boot into another OS and nuke partitions on the sucker. I'd also run an Antivirus on my whole machine because it would seem that its not the flash drive that still has the infection.

    Actually that is a lie, if it where me I'd stop trusting my current install, backup my documents and blast the OS. But thats just me.
    Only you can prevent asshatery.

  6. #6
    Conscript
    cOcO!'s Avatar

    Join Date
    Mar 2010
    Location
    Buenos Aires, Argentina
    Posts
    63
    The best way to PREVENT viruses in pendrives is to create a folder in the root of the drive called AUTORUN.INF. That way the autorun file will drop in there and will not be able to execute.
    LIFE IS A SEXUALLY TRANSMITTED DISEASE

  7. #7
    ASSEMbler Extreme
    Lives in the server
    madhatter256's Avatar

    Join Date
    Mar 2004
    Location
    USA
    Posts
    6,586
    Download and install Avira. Removed this when I had my thumb drive infected.

    It will comeback even after a format as it copies itself on to the PC and writes itself to any thumbdrive you connect it to. This is how it spreads.

  8. #8
    Wiiiiiiiiiiiiiiiiiiiiiiii iiiiiiiiiiiiiii Member Elite
    3do's Avatar

    Join Date
    Sep 2006
    Location
    Scotland
    Posts
    1,897
    It's not got a hidden partiton on it as I always get rid of those straight after I get drives with them on it.

    Did a scan of the C: drive with Avast which is the main AV program used, also scanned with malwarebytes
    and it seems clean so I think the virus may be on one of the external drives which I'll scan next.

  9. #9
    New member Yorkshire Remixer's Avatar

    Join Date
    Jun 2009
    Location
    Cleckheaton, Bradford, West Yorkshire, UK
    Posts
    4
    yeh had the same problem at work; all machines seemed to have the same and also when you attempted to open c: it tries to open as a file??
    formatted usb stick; fine
    formatted pc; fine
    plugged in an external hdd and then all 3 got it again; if you have this virus it looks like you need to format every machine you have and virus check the files you want to keep.

  10. #10
    Member Hardcore
    z_killemall's Avatar

    Join Date
    Dec 2006
    Location
    Montevideo, Uruguay
    Posts
    1,108
    Maybe you're connecting the flash drive to other computers with that virus on it, long ago when I used to go often to internet cafes I found that adding two dummy files named autorun.inf and svchost.exe (both empty) and flagging them as hidden and system files they couldn't be replaced. But as I said, that was many years ago, I don't know if these viruses are able to overwrite those files now.

    "We have nothing to fear, but fear itself ... and the chupacabra! Madre de dios he'll kill us all!" -Max

  11. #11
    Wiiiiiiiiiiiiiiiiiiiiiiii iiiiiiiiiiiiiii Member Elite
    3do's Avatar

    Join Date
    Sep 2006
    Location
    Scotland
    Posts
    1,897
    I think the problem has gone now??

    The USB drives have been formatted several times by now and when put in the original offending computer i no longer get any virus warning coming up plus i've re-instyalled windows 7 on my machine so if it was that then its gone.

  12. #12
    DBAN = Best. Google it, its free, and it does a GREAT job of formatting HDD's.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •