Malware on Portable Hard Drive?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MalawiBrian, May 23, 2011.

  1. MalawiBrian

    MalawiBrian Private E-2

    I have a friend's portable drive seem to have been given a malware virus that has the following:

    * Folders on the drive appear hidden, not solid and completely visible, on XP and Win Vista. On Win 7 they appear solid for some reason.
    * Attached to Win 7 I can see folders. Attached to Win Vista I see only a couple of files, no folders.
    * I can't delete several of the folders, which contain wing-ding type objects, which may basically the former readable contents of the folder
    * Until I deleted them, the drive had an "exe" file corresponding to each of the main folders in the drive: "videos.exe", "music.exe", etc.
    * I have scanned with Malware Bytes and Avira Premium and found nothing.

    Any suggestions?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you tried to format it?

    For the external Hard Drive and a USB stick.

    Insert your flash drive before you begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

    Please have all your removable storage devices ready for disinfection.

    Download Flash Disinfector by sUBs and save it to your desktop.

    * Double-click Flash_Disinfector.exe to run it.
    * Your desktop and icons may disappear. This is normal.
    * It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    * Follow any prompts that may appear.
    * The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    * Wait until it has finished scanning and then exit the program.
    * There will be no GUI interface or log file produced.
    * Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.

    You can also try doing this:
    http://www.pandasecurity.com/homeusers/downloads/usbvaccine/

     
  3. MalawiBrian

    MalawiBrian Private E-2

    I haven't tried to reformat them. Will this suggestion do that? I'd need to check with my friend before I do that.

    Otherwise, I'll try this if it won't reformat. I've gotta wait til morning before I can get to it so I have time...Thanks - Brian
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't think either tool will remove the malware, so it would be best to try to format the stick. Make sure you only plug it into a well updated and protected computer.
     
  5. MalawiBrian

    MalawiBrian Private E-2

    Holding down the shift key doesn't turn autorun off...and when i double click it asks me if I want to run, when I click yes it just goes away...nothing seems to be happening?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can use this to stop the autorun features:
    AutoEater.
     
  7. MalawiBrian

    MalawiBrian Private E-2

    The USBs seem to trigger AutoPlay anyway, and the panda download comes up empty. Bummer!
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  9. MalawiBrian

    MalawiBrian Private E-2

    Panda loads, stops the run, but when I double click flash disinfector nothing happens. huh?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hummm......have you decided to try reformating the drive? Have you run both SAS and MBAM with the drive plugged in?
     
  11. MalawiBrian

    MalawiBrian Private E-2

    I ran SAS and MBAM after updating. They didn't find anything! I reformatted the flash drive that was infected because the data on it was not significant. But the portable drive has materials not backed up anywhere else. What would happen if I removed the contents of the folders to another drive and them reformat the drive? I could then put the contents back on the drive...but the essential question is, what if I take the virus...and how would I know?

    What the heck is this thing??
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would suggest that you transfer any files you need to save to a CD. Reformat the drive and then scan the CD before you put it back on the drive.
     
  13. MalawiBrian

    MalawiBrian Private E-2

    It is a portable drive with about 200g of data...I'll see what I can do over the next few days!
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please also download MBRCheck to your desktop and have the external drive plugged in.

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  15. MalawiBrian

    MalawiBrian Private E-2

    That was cool - it did detect issues both on my hard drive and portable...the log is attached.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.
    Enter your choice:

    * Please push the 'Y' key and then press Enter
    * When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    * Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
    o Enter 1 and press the Enter key.
    * The program will show Available MBR codes as below

    * You need to select your version of Windows from the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    * The program will prompt for confirmation. Type 'YES' and hit Enter.
    * Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    * You will see all the text in the window get highlighted.
    * Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    * Paste that text into Notepad, save it to your desktop as MBRfix.txt
    * Restart your PC.
    * Attach the MBRfix.txt file to your next message..

    Now please re-run MBRCheck.exe and attach that log also.
     
  17. MalawiBrian

    MalawiBrian Private E-2

    I did what you asked but was not prompted to enter my OS nor to confirm that choice. After the line "Enter the physical disk number to fix (0-99, -1 to cancel:" there was nothing.

    I entered codes for both the hard drive and the portable but they were not saved in a valid file extension so I can't attach them. I saved the step by step results to a log file attached, and I attached the text file so you can see how it went. Thanks!
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's possible that MBRCheck is just not recognizing the MBR on your external drive. What malware issues are you having?
     
  19. MalawiBrian

    MalawiBrian Private E-2

    Could be...the issues I am having depend in a way what computer I connect it to. On my Win 7 laptop, where I ran this MBRCheck, the folders appear shaded, not solid, If you understand what I mean? I hook it up to my Win Vista desktop and in fact the folders are completely hidden - in the details view the drive is said to have 223g of data. But there are only 4 objects visible, and none of them are of any substance! Very off. My folder view option is set to view even hidden items.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your OS disc for either of those machines? If you do:

    For vista:
    boot to the cd, choose Command prompt and type these followed by the enter key:
    bootrec.exe /fixmbr \device\harddisk1
     
  21. MalawiBrian

    MalawiBrian Private E-2

    Dang...I'll have to look. We've moved a bit since I got these...
     
  22. MalawiBrian

    MalawiBrian Private E-2

    I do this with the drive plugged in?
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you have to do it with the drive plugged in. When in the recovery console, check that the external drive is recognized. Select it and type this:
    bootrec.exe /fixmbr
     
  24. MalawiBrian

    MalawiBrian Private E-2

    I'm afraid I've looked where I can tonight and can't find the OS disks. Ill check in the store room tomorrow unless there's any other way. Thanks!
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Instructions were not being followed properly. The wrong option was being chosen. Your instructions did not ask for the MBR to be dumped to a file. They asked for option 2 to be run to - Restore the MBR of a physical disk with a standard boot code


    However MBRcheck may not fix it anyway when the correct option is used, since it seems to fail quite frequently now.
     
  26. MalawiBrian

    MalawiBrian Private E-2

    Apologies for that! When it opens in a window the last option was below the visible screen and I didn't think to scroll down.

    I re-ran it and I selected the option to replace it. I attached the .txt file, and then ran it again, and so you have before and after results, which don't look different. Thanks!

    FYI there is a folder in the drive that is called System Volume Information that shows it was modified on May 23, the day these problems started. It is illustrated with a lock, and I can't open it...not that I think I want to at this point!
     

    Attached Files:

    Last edited: May 28, 2011
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    With the external drive plugged in, toggle system restore. See if that doesn't clear that file. Did you boot into the Recovery Environment? Did it show both drives?
     
  28. MalawiBrian

    MalawiBrian Private E-2

    Hi I toggled system restore, booted in the recovery environment, and the folders on the portable look normal in that environment only.

    I ran all the malware checks again and the logs are attached - Brian
     

    Attached Files:

  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You included the external drive when you ran both MBAM and SAS?

    When you booted to the recovery console, did you choose the external disc and try running fixmbr?
     
  30. MalawiBrian

    MalawiBrian Private E-2

    Yes, I had the portable hooked up for both MBAM and SAS.

    "When you booted to the recovery console, did you choose the external disc and try running fixmbr?"

    I did not...I will give it a shot.
     
  31. MalawiBrian

    MalawiBrian Private E-2

    I booted again and ran MBRCheck. I selected the portable drive and followed all the prompts successfully. Everything now appears normal!? The folders in the drive seem fine. Log is attached. Your thoughts?
     

    Attached Files:

  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have not a clue, as the MBRCheck is still not recognizing the MBR on that drive. But you are saying that everything is appearing to be there and normal?
     
  33. MalawiBrian

    MalawiBrian Private E-2

    Yes, everything appears normal on the drive now. I ran MBRCheck and it said it rewrote the code for it, so should I assume that fixed it? All the folders appear and when I hook it up to my desktop everything on the drive is visible, whereas it wasn't before.
     
    Last edited: May 31, 2011
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  35. MalawiBrian

    MalawiBrian Private E-2

    I've been traveling and haven't had much time but I realized I left this hanging. I'll close it out by saying thanks - everything seems to be running fine and there have been no problems since you helped me out. Nice work!
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds