HEEELP!! Remove Viruses from external USB hard disk drive ....

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Maggie_61, Apr 6, 2006.

  1. Maggie_61

    Maggie_61 Private First Class

    Windows Defender and www.bitdefender.com detected two viruses as you can see in my attachment:

    KAZAA & ALTNET.

    These two programs say that the viruses are found in my external USB hard disk drive in F:\System Volume Information\_restore …….. [ numbers … ]

    But I CANNOT DELETE THEM WITH NONE OF THESE PROGRAMS !!!!

    HOW CAN I DELETE THEM FOR EVER? IS MY DISK REALLY AFFECTED ??

    Why a virus entered an external USB hard disk drive? I knew this could not be done !

    I use the disk to copy all my files and transfer them in my Laptop !

    IS IT POSSIBLE THAT THESE VIRUSES WILL AFFECT MY LAPTOP, IF I COPY MY FILES THROUGH IT ?

    I WANT TO REMOVE THEM AS SOON AS POSSIBLE, BECAUSE I AM AFRAID ….

    I must save my USB hard disk from the viruses without Format, because I have there all my IBM’s desktop entire big backups….

    HEEEELP !!!
     
    Last edited: Aug 21, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You just need to disable System Restore on the external hard drive. See the READ & RUN ME for info on disabling/enabling System Restore. But make sure you select the proper drive.
     
  3. Maggie_61

    Maggie_61 Private First Class

    Windows Defender still finds KAZAA & ALTNETafter I disable System Restore.

    Does my disk have a virus and will I copy it to my Laptop when transfering my files ? :rolleyes:
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must make sure you disable System Restore for the external drive or for all drives.

    Then locate the files in the logs you posted and manually delete them while System Restore is disabled. You should be able to just delete the following restore point folders: RP132, RP136, RP137, and RP138
     
  5. Maggie_61

    Maggie_61 Private First Class

    First question: I disabled System Restore only for the external disk drive.

    But when I try to open the folder SYSTEM VOLUME INFORMATION it says
    "access is denied in System Volume Information"

    So, I cannot delete these two files KAZAA + ALTNET.

    What do I do?

    Thanks,
    Maggie
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Disable System Restore on all hard disks. Then install the below application and try using it to delete the files. It is better out finding files and deleting them then Windows Explorer.

    ExplorerXP

    But I have a question too! Do you have any of the crap from Kazaa (including Kazaa) installed?
     
  7. Maggie_61

    Maggie_61 Private First Class

    Of course my friend, I dont have any KAZAA program installed !

    I will download ExplorerXP. Then I will have to delete it ? :rolleyes:

    Does it delete Windows Explorer? Will I have a problem with this program ?


    Thanks !
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should keep ExplorerXP. It does not interfere with Windows Explorer and it only runs when you run it. It is much better than Windows Explorer at finding and deleting files. Windows Explorer does not show ALL files even when you tell it to show hidden and system files. And since malware knows this, they take advantage of tricks to hide from you.

    This is a utiltity that everyone should have and use especially in the war on malware.
     
  9. Maggie_61

    Maggie_61 Private First Class

    After I did everything you exactly said, I had problems working with Windows Explorer !

    I had to remove ExplorerXP to work again...

    I have Win XP, SP2.

    But many thanks cause I removed the viruses successfully,

    and now I will run again Bitdefender.

    I´ll let you know !

    You are the greatest !!!!!!!!!!! :D
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have personally installed ExplorerXP on more than a 20 PCs and have no problems with Windows Explorer. Out of curiosity, I will make sure there has been no change in the version number being used and check it on a WinXP SP2 system again! But it has not been a problem thus far and we also have many people install and use it in this forum to fix malware. No one has ever said they had a problem with Windows Explorer after installing ExplorerXP.

    Exactly what was your problem? If it impacted Windows Explorer, I would expect that you would have problems booting up to your Desktop since Windows Explorer is your shell and without it, there is no Desktop, Start button, etc.
     
  11. Maggie_61

    Maggie_61 Private First Class

    The only problem I had was that I opened Windows Explorer and it when I tried to open, let's say Control Panel it stucked, you understand ? It could not be opened, it was frozen, how to say ...

    I removed ExplorerXP and WIN Explorer is OK now.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still don't see any problem right now. But currently I'm not on a WinXP SP2 system.
     
  13. Maggie_61

    Maggie_61 Private First Class

    Hijack This, logs, and Removing Viruses success !!!! :)

    I did EXACTLY what you say as a reply in my two messages.

    I have to say one problem only:
    I scanned with www.bitdefender.com my entire computer and my external USB hard disk drive more than once.

    Each time, when the scan ends will all the files, I get the message:

    “IE needs to close.
    The following add-on was running when this problem occurred: File: oscan8.ocx”

    THEN, I MUST CLOSE IE AND I CANNOT SAVE THE SCAN REPORT !

    I cannot manage the add-on or update it. IE says the update failed.

    How can I fix this problem for good ?

    SO HERE I CANNOT ATTACH THE LOG (WHICH IS CLEAR, WITH NO VIRUS) FROM BITDEFENDER AS IE CLOSED AND I COULD NOT SAVED IT.

    I attach the log from PANDA ACTIVE SCAN and HIJACK THIS.

    I think everything is OK now !
    Please read the logs and tell me what you say...

    I have manually removed the viruses as shown in PANDA ACTIVE SCAN, and scanned again with success !

    EVERYTHING IS COMPLETELY OK NOW ... :D

    Thanks !!!!

    You are all great here !!!!!!!!!!!!


    Maggie from Athens, Greece
     
    Last edited: Aug 21, 2006
  14. Maggie_61

    Maggie_61 Private First Class

    Hijack threats again .... !!!!!!

    I really dont believe it !

    After my reply I just sent you with all my scans results here below, I just opened WINDOWS DEFENDER and I get this message again:

    THIS HOSTS FILES IS THE ONE I CREATED YESTERDAY WITH HOSTER !
    WHAT DO I DO? I JUST DID ALL YOUR REQUESTED SCANS AND EVERYTHING WAS OKAY... I AM GOING CRAZY ....

    DOES IT MEAN I HAVE A VIRUS OR IT SEES THE NEW HOSTS FILE AS A THREAT:

    "POSSIBLE HOSTS FILE HIJACK, ALERT LEVEL MEDIUM, WINDOWS DEFENDER"

    DO I CHOOSE TO IGNORE THIS ??

    *****************************************

    Category:
    Configuration Change

    Description:
    This program has potentially unwanted behavior.

    Advice:
    Allow this configuration change only if you trust its origin. It is recommended that you run a quick scan if you choose to block this change.

    Resources:
    file:
    C:\WINDOWS\system32\drivers\etc\HOSTS

    Summary:
    System Configuration change occurred.

    This agent monitors security related configuration changes made to Windows.

    Checkpoint:
    Hosts File

    View more information about this item online.
     
  15. Maggie_61

    Maggie_61 Private First Class

    HOSTS file a Spyware ?

    [ PLEASE READ MY TWO OTHER NEW MESSAGES FOUND HERE BELOW. THANKS. ]

    *******************************

    Is it possible that the HOSTS file from HOSTER could be SPYWARE ?

    This is the new report from a quick scan from WINDOWS DEFENDER I just did...

    *******************************

    Category:
    Spyware

    Description:
    This program has potentially unwanted behavior.

    Advice:
    Review the alert details to see why the software was detected. If you do not like how the software operates or if you do not recognize and trust the publisher, consider blocking or removing the software.

    Resources:
    file:
    C:\WINDOWS\system32\drivers\etc\hosts

    View more information about this item online.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: HOSTS file a Spyware ?

    No Hoster did not install any spyware. Windows Defender is simply telling you that the file was changed since its last checkpoint. When you ran Hoster this is what changed the file which is what we wanted to do. You just need to allow/approve the change and create a new check point.

    You also have too many conflicting spyware blocking programs running that could result in driving you crazy. I would not have Spyware Doctor, Spy Sweeper, and Windows Defender installed at the same time (just keep one). If Spyware Doctor and Spy Sweeper are trials, uninstall them. And I would even go as far as saying remove SpywareGuard too.
     
  17. Maggie_61

    Maggie_61 Private First Class

    What do you mean:

    "You just need to allow/approve the change and create a new check point." ??

    I click IGNORE in Windows Defender annoucement of HOSTS Hijack?

    and what do you mean "create new checkpoint"? What is this? What exactly do I have to do?

    Regarding your help on the spyware programs, I will IMMEDIATELY remove exactly what you say !! :) Thanks !

    Thanks a million !!! You are great !
    You made me a computer expert .... !!!!! :D
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need to know if you purchased any of the programs! Or are they all free trials.

    But right now start with uninstalling Windows Defender. Then reboot and run Hoster to fix your hosts file.
     
  19. Maggie_61

    Maggie_61 Private First Class

    The programs are all free trials.

    I will uninstal WIN DEFENDER.
    I will reboot and run Hoster to fix hosts file again.

    and then I WILL REINSTALL WIN DEFENDER again ? :rolleyes:
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First uninstall Spyware Doctor, Spy Sweeper, and Spyware Guard. The first two are only trials which expire and are of no use to you. Spyware Guard just is not necessary if you have Windows Defender. In addition they are using loads of system resources and can conflict with each other.
     
  21. Maggie_61

    Maggie_61 Private First Class

    I unistalled everything as you say.

    I deleted WINDOWS DEFENDER.

    I opened HOSTER and clicked on RESTORE MICROSOFT'S ORIGINAL HOSTS FILE. Is this correct?

    Is it good to CREATE A BACKUP HOSTS FILE with HOSTER ??

    Do I have to make HOSTS READ ONLY ?? !!!! :rolleyes:

    I am expecting your answer if everything is OK, so I will then install WIN DEFENDER !

    Thanks, super job !! :)
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean you uninstalled Windows Defender.....right? Delete and Uninstall are two different things.

    Yes!

    You don't need it. You are putting your Hosts file back to system default and you don't need a backup of the default since Hoster can always just give you the default.

    No! It does not truly provide any real protection doing that since most malware is smart enough to remove the read only setting, and could just confuse you if you ever tried to edit the hosts file.
     
  23. Maggie_61

    Maggie_61 Private First Class

    You are great ! :)

    Many thanks !!!

    My only question left is if I need WINDOWS DEFENDER, cause I installed it again, I did a full scan and found nothing.

    I also have:
    * Ad aware SE Personal (free)
    * Spybot (free)
    * Symantec Antivirus Full Version Corporate for client
    * Spyware Blaster (free)
    * CCleaner (as you guys told me ! )
    * Microsoft Malicious Software Removal Tool

    I have WIN XP, SP2, Office 2003.

    I will keep WINDOWS DEFENDER ? Because everything is OK now, THANKS TO YOU !!!!

    BIG BIG THANKS !!!! :)
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Unless you are going to buy a program like Spy Sweeper, Ewido, or similar then you still need a program like Windows Defender to provide similar protection to what they would provide. If you were to buy Spy Sweeper then I would use it and uninstall Windows Defender.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds