Missing USB drive files caused by malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by gman863, Mar 1, 2014.

  1. gman863

    gman863 MajorGeek

    I'm running into an issue attempting to recover files off a USB drive that seems to be infected with malware.

    When I transferred the files to a USB drive prior to doing a system restore on the PC, they showed up in "My Documents" and appeared to transfer to the USB drive normally.

    When I attached the drive to a working, clean PC and scanned it with both AVG and Malware Bytes before attempting to open the folders, each found and removed a few issues. I rescanned the "clean" PC afterwards using both AVG and Malware Bytes and found no issues on it.

    Now the folder on the USB drive ("Old Files") exists, but none of the files in it are visible. If I right click on "Old Files," however and choose "properties" it appears the data is on the drive based on the number of GB marked used.

    It appears the files are still on the drive but are being hidden. As noted above, neither AVG nor Malware Bytes solves the problem. I've also tried Hitman Pro and TDDS Killer, but these do not give me the option to scan only the USB drive.

    Can you recommend a freeware or shareware program that is effective in fixing this type of issue? Thanks in advance.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can try disinfecting the drive:

    Insert your flash drive before you begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

    Please have all your removable storage devices ready for disinfection.

    Download Flash Disinfector by sUBs and save it to your desktop.

    * Double-click Flash_Disinfector.exe to run it.
    * Your desktop and icons may disappear. This is normal.
    * It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    * Follow any prompts that may appear.
    * The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    * Wait until it has finished scanning and then exit the program.
    * There will be no GUI interface or log file produced.
    * Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.
     
  3. gman863

    gman863 MajorGeek

    Tim,

    When I try to run the Flash Disenfector file, AVG is flagging it with a high-risk Trojan Horse warning. Should I ignore the message and install it or try a different download?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Disable AVG and then run it.​
     
  5. gman863

    gman863 MajorGeek

    With AVG disabled, the program installs (desktop icon) and Windows asks permission to run it. When I click allow, the screen flashes for a second but nothing happens. Looking at the USB drive, I do not see an "autorun.inf" file added. I am running Win 7 Ultimate x64 on the PC. I tried running it in compatibility mode (XP SP2) but got the same results.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only other course of action I can offer, before sending you to the software forum is to try this:
    USB Vaccine
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds