Removing Malware from External Hard Drives

Discussion in 'Malware Help (A Specialist Will Reply)' started by mcbreeza, Oct 16, 2008.

  1. mcbreeza

    mcbreeza Private E-2

    Dear All!

    I have been through all the steps of the Windows XP cleaning but keep coming up with Trojans in Zone Alarm on a daily basis. Think something has crept in real deep this time. Im happy to do a complete re-format once again to swipe anything BUT I have alot of files on an external hard drive I want to gain access to and load back onto here at a later date. Question is... how do I do a real deep check on the external hard drive as I have a feeling that is the carrier that infected this in the first place???

    And how can I protect my pc from getting anything naughty from the external hard drive while I connect it?

    Thanks all.

    Breeza ;)
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The first thing you need to do is to attach the logs from the Read and Run First.....

    When you ran those scans, did you have the external drive attached and did you include that drive in the SAS and MWB's scanning?
     
  3. mcbreeza

    mcbreeza Private E-2

    Just did the computer by itself as was more interested in cleaning that up at the time and didn't want the chance of it getting reinfected. What im gonna do is do a full clean up and scan with the external hard drive attached then place the logs up.

    Thanks for your help Tim,

    (any advice for when I do attach the external HD back on and run the scans)

    Thanks again

    Simon (Breeza)
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    As I mentioned, run the scans and include the external drive.

    I will look at the logs when you are ready. :)
     
  5. mcbreeza

    mcbreeza Private E-2

    Thank you :)
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem...I will be here. :)
     
  7. mcbreeza

    mcbreeza Private E-2

    Hi Tim, :)

    Been a bit busy at work so haven't been able to complete all the steps yet fully but have the logs so far.. will do the rest as soon as possible when I get time away from work (running the bloody london underground) lol

    Things to note...

    - Windows running in normal mode as advised
    - Zone Alarm Security Suite fully turned off so all scans can do everything without that getting in the way
    - External hard drive plugged in permanently and included in scans where possible
    - System Restore has been Disabled from the external hard drive

    (Peculiarities currently happening in windows)

    - Auto run doesn't ever autorun now
    - 'Open with' option disappeared
    - Every so often the ram will start doing something and sounding very busy but no applications selected to start and can't find any processes on task manager running up the cpu?? (this one has me very worried as have a feeling something naughty is kicking in in the background)

    Drive References:

    C: Hard Drive
    D: Swap Drive Files (Separate partition I made on drive when installing windows for virtual memory)
    F: External Hard Drive

    Logs so far attached..

    Thank you Tim, your a life saver :)

    Simon
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem.....but so far no malware has been found. So please attach the ComboFix log and the MGLogs.zip with the next reply. :)
     
  9. mcbreeza

    mcbreeza Private E-2

    Have also attached print screens of the Zone Alarm logs so you know what I originally found.. Hope this is of help

    Simon :)
     

    Attached Files:

  10. mcbreeza

    mcbreeza Private E-2

    Am on the combofix and Mg case once I finish writing this so will be back on asap. :)
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The first screen shot lists items in your system restore files which can only be removed by toggling system restore.....I can not see where the items that it found in the second screen shot are located....the rest were removed.
     
  12. mcbreeza

    mcbreeza Private E-2

    Toggled System Restore off on all drives once found that (a couple of days ago) then only turned it back on on the C drive. But seems like it has turned itself back on again on the F Drive (external hard drive) ???? Could this be caused if you unplug it? Does appear the F drive virus is gone though as all subsequent ZA scans didn't find it.

    Have attached the final Combo and MG Logs...

    Thank you,

    Simon :)
     

    Attached Files:

  13. mcbreeza

    mcbreeza Private E-2

    (Zone alarm being a bit rubbish at times doesn't give the option to show where spyware was found in logs) :confused
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean...however I do not see any active AV on your C drive where it should be....also you have no Java installed.

    You can download it here:
    Java Runtime 6

    Are you having any issues?

    If not we can start the final clean up:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you get a success message, then:
     
  15. mcbreeza

    mcbreeza Private E-2

    Sorry what is active AV Tim? :eek:

    And does this mean you think the F Drive (external hard drive) is clean now? .. also did you see in one of the logs it deleted autorun.inf from the external hard drive... does this mean something?

    Simon :)
     
  16. mcbreeza

    mcbreeza Private E-2

    Oh yeah Tim forgot to mention I was ideally looking at doing a fresh install of windows on this machine.. any steps I should take straight away after doing it? E.G Removing/ Adding of certain software or redoing the tests.. as want everything fresh and new and as tidy as can be.

    You have been really helpfull so far and if there's anything I can do to help in return I'd be more than happy to.

    Thanks mate, owe you one!

    Simon :p
     
  17. mcbreeza

    mcbreeza Private E-2

    Just did another full system scan on ZA and found...

    Win32.Trojan.KillAV.ko
    Win32.HLLW.spreader.17

    looking at the logs these keep re-appearing

    Was found in C: System Restore Volume Information
    this time..

    Very interesting..
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Active AV means an anti-virus program that is scanning your system all the time. There are numerous freeware programs Top Freeware Picks.

    Why re-install Windows when your system is clean now?

    The items that Zonealarm is reporting, if in your system restore files, means you need to turn off system restore, reboot and then turn it back on.

    If you would like to, you can go to Bitscan : agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
  19. mcbreeza

    mcbreeza Private E-2

    Just wanted a clean install as really want it as streamlined as possible as gonna use it for DJ'in. :)

    Does ZA not activelly scan your pc when you have it on?? I can see that it might not as it only does a scan when timed to or you manually push it to but it does scan files as and when their opened etc..

    What freeware one would you recommend if I did put one on.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I believe the version of ZoneAlarm that you have does have an active scanner.....:)

    If the Bitscan shows you are clean ( with the external also being scanned), then there is no reason not to do a clean install if you so wish.
     
  21. mcbreeza

    mcbreeza Private E-2

    Just got in from a lazy days work and a quick visit to the pub so gonna give Bitscan a quick run through now :)

    (should I turn off system restore for my scan so I can let it have a look and play in there?)

    :tas:tas:tas:tas Tazz all the way!!
     
  22. mcbreeza

    mcbreeza Private E-2

    Bit scan ran... nothing found :-D
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet....then you can rock and roll.....:)
     
  24. mcbreeza

    mcbreeza Private E-2

    Thanks Tim, your help was really good and am very thankful!

    :):):):):):):):):):):):):p
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....safe surfing. :)
     
  26. mcbreeza

    mcbreeza Private E-2

  27. mcbreeza

    mcbreeza Private E-2

    Hey Tim, know your a busy man and that but keep finding Win32.dropper.vb.rw in system restore.. only zone alarm finds this though?? SAS, MB, spybot, sophos root kit and Avivra never spot it. Is it a false positive? Had a little googling and can't really find much info on it.....
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi McBreeza

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds