BleepingComputer.com: Uh Oh, possible infected a flash drive with a rootkit? How do I check?

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Uh Oh, possible infected a flash drive with a rootkit? How do I check? Using a flash drive to run DDS & GMER on infected Laptop

#1 User is offline   dathorpes 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 26
  • Joined: 01-October 09
  • Gender:Female
  • Location:Arizona: but it's a dry heat

  Posted 28 May 2011 - 01:07 PM

Hi everyone,

My problems have just multiplied - I have a laptop with major problems - posted all about it in the "..Malware Removal Logs". So I was using a little flash drive to transfer programs (DDS & GMER) and their log files between it and my main computer so I can post them.
Now DDS randomly starts when it is in the infected laptop! :dance: How do I make sure I have not transfered the problem to my main machine via the flash drive?
I think one of the viruses on the laptop is MS Recovery.

I ran a virus scan using MS Security essentials against the flash drive, nothing.
Any other scan suggesstions? I hate to trash a flash drive, but I hate to trash my main computer even more! :woot:


And my problems continue to grow......:lmao:
Any suggestions?
Gratefully,

Anne

#2 User is offline   Blade 

  • Strong in the Bleepforce
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Site Admin
  • Posts: 10,238
  • Joined: 20-January 09
  • Gender:Male
  • Location:US

Posted 30 May 2011 - 09:53 AM

Hi Anne.

Which OS is this?

~Blade
Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
Circle us on Google+

#3 User is offline   dathorpes 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 26
  • Joined: 01-October 09
  • Gender:Female
  • Location:Arizona: but it's a dry heat

Posted 30 May 2011 - 02:47 PM

The laptop is XP, the main computer is Windows 7 (MS Security Essentials & Malwarebytes).

The reason I am concerned, is sometimes when the flash drive is in the laptop, the program DDR will suddenly start running.

#4 User is offline   Blade 

  • Strong in the Bleepforce
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Site Admin
  • Posts: 10,238
  • Joined: 20-January 09
  • Gender:Male
  • Location:US

Posted 30 May 2011 - 03:05 PM

Hello Anne,

Please download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives. Please do so and allow the utility to clean up those drives as well.
  • Hold down the Shift key when inserting the drive until Windows detects it to keep autorun.inf from executing if it is present.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: As part of its routine, Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that was plugged in when you ran it. Do not delete this folder...it will help protect your drives from future infection by keeping the autorun file from being installed on the root drive and running other malicious files.

~Blade

In your next reply, please include the following:
How's the computer running now?

Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
Circle us on Google+

#5 User is offline   dathorpes 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 26
  • Joined: 01-October 09
  • Gender:Female
  • Location:Arizona: but it's a dry heat

Posted 04 June 2011 - 12:20 PM

I ran the fix - had to wait until my xp computer was up and running (still has virus problems) I will let you know if there is any problems or virus/malware on it after this.


Thanks for the help

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users