Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Thumbdrive infected? now on laptop

  • Please log in to reply
1 reply to this topic

#1 sh4rkbyt31


  • Members
  • 13 posts
  • Local time:05:22 AM

Posted 01 June 2017 - 03:32 PM

A while ago I had worked on a computer that appeared to have several infections. Something seemed to get onto one of my thumb drives and was transmitting itself from thumbdrive to computer despite scanning it and reformatting it several times. Even after getting help through BC the original computer remained infected. 

I accidentally seem to have used that same thumb drive from a while back on a laptop that tries to start up (Windows 10) shows log in screen but after I put in the password I get a black screen with white cursor and an occasional blue start up circle that seems to be rotating intermittently. It will not allow the laptop OS to start but I am able to access the Lock screen, Change user, etc by using alt+ctrl+del. That's as far as it will go. If whatever it is, is so easy to transmit should I use a sandbox environment to get the dds.log/txt or is there a chance another thumbdrive will infect my clean desktop I'll be using to transfer the dds image/file
The only message I was able to see very quickly was a dwm.exe error with a zero code address but couldn't save it.

Sorry if this is posted in the correct area.

Edited by hamluis, 01 June 2017 - 04:16 PM.
Moved from Gen Sec to Am I Infected - Hamluis.

BC AdBot (Login to Remove)


#2 boopme


    To Insanity and Beyond

  • Global Moderator
  • 72,725 posts
  • Gender:Male
  • Location:NJ USA
  • Local time:06:22 AM

Posted 02 June 2017 - 09:45 AM

Hello and welcome.

Can you boot to Safe Mode With Networking ?

If so Run this ESET scan with the drive connected and scan all drives.
  • It is recommended to turn off your antivirus program. Click on the E5rfZI9.png button to see which antivirus is currently enabled:
  • Turn off your antivirus program. See here how to do this.
  • Check the option beside: Enable detection of potentially unwanted applications.
  • Now click on Advanced Settings and make sure that the option Clean threats automatically is NOT checked, and select the following:
Enable detection of potentially unsafe applications
Enable detection of suspicious applications
Scan archives
Enable Anti-Stealth Technology
  • Click on the Change button and select only Operating memory, Autostart locations and drive C:\ to be scanned.
  • Push the dtoGjAL.png button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes a list of found threats will open automatically (if any malicious files are found).
  • Push thecRhRYZ8.png button and save the file to your desktop using a unique name, such as ESETScan.txt. Include the contents of this report in your next reply.
  • Push the 9IjfdXq.png button.
  • Check the box beside RHzfZB1.png to uninstall the application when closed.
  • Push Vc3btaC.png and the close the application clicking the X in upper right corner.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users