Viruses can easily spread through USB or Pen Drives. Most viruses like ’Ravmon’ , ‘New Folder.exe’, etc are spreading through these Flash Drives. These Viruses are hard to delete even for the Best anti virus applications. So only option is to remove Virus from USB drives Manually , Here is the procedure you have to follow..
-
Never Open the USB drive directly through the Auto Play Feature. Scan the USB drive for viruses by using your anti virus application. If you find any viruses in that scan, Eliminate them.
-
After that, Open the Command Prompt by typing ‘cmd‘ in the run box. In the command prompt type the drive letter: and press enter . Now type dir /w/a and press enter.
Check whether the list displayed contains the below given files.
-
Autorun.inf, Ravmon.exe, New Folder.exe, svchost.exe, Heap41a or any other exe file which may be suspicious.
If you encounter any of the above files, then probably the USB drive is infected. Now to delete the virus files manually..
-
Go to command prompt type attrib -r -a -s -h *.* and press enter. This will remove the Read Only, Archive, System and hidden file attribute from all the files.
-
Now just delete the files using the command del filename. example del Ravmon.exe.
-
Delete all the files that are suspicious.
-
To be on a safer side, just scan the USB drive with an anti virus program to check whether it is free of virus or not.
-
Now remove the drive and plug it again. In most of the cases, the real culprit turns out to be the “Autorun.inf” file which mostly gets executed when someone clicks Ok in the dialog window which appears in Auto Play.
Note : To protect yourself from Virus, Disable the Autoplay feature of USB drives. If you disable the Autoplay feature of USB drives, then there are lesser chances of the virus spreading in your computer. A tool which can perform such a function is Tweak UI. Download it here
[via WhoisMadhur]
thanks for your tips.but it’s not working for me.when i give “delultimate” it says ‘you cannot remove the file as it is being used by some other program.Pls help me 🙁
I consider Autorun Virus Remover one of the best security solution for USB devices. I use it to clean my USB disks from infections and to repair the corrupted system settings.
http://bstdownload.com/reviews/autorun-virus-remover-3/
i tried it bt it didnt work…. every time i removed it ,it get replaced… i didnt understand.. plzz help…
How about a comdom for USB drives…
http://www.skipser.toolsbysk.com/p/96/p/general/usb-condoms-to-protect-pcs-from-virus-infections.html
I just wanted to thank you for this. My USB stick had school projects on it, and it WOULD NOT WORK! And now it does! Thank you so much!
Thank you for the above instructions. But this has not helped me. I had folders in my USB containing pictures, word files, some music etc. When i click on any one folder, there are so many folders inside that and when i click any one from that , there are still more folders in that with the same names as in the previous folders. like this there are 100 s of foldrs in each folder. and i cannot find my files. from various recovery softwares available on the net, i could recover only 5 music files and 4 jpegs. all the rest has just vanished. I NEED HELP. Please advice. THe normal scan says : NOTHING FOUND:
Remove autorun.inf virus manually.
1). Go to any folder.In that on the top menu go to Tools–> Folder Options, which will be beside File, Edit, View, Favourites.
2). A window pops up after you click on folder options.In that window go to View tab and select the option Show hidden files and folders.Now uncheck the option Hide protected Operating system files.Click Ok
3). Now Open your drives (By right click and select Explore. Don’t double click!) Delete autorun.inf and MS32DLL.dll.vbs or MS32DLL.dll (use Shift+Delete as it deletes files forever.) in all drives include Handy Drive and Floppy disk.
4). Open folder C:\WINDOWS to delete MS32DLL.dll.vbs or MS32DLL.dll (Use Shift+Delete ) 5). Go to start –> Run –> Regedit and the Registry editor will open
6). Now navigate in the left pane as follows: HKEY_LOCAL_MACHINE –> Software –> Microsoft –> Windows –> Current Version –> Run .Now delete the entry MS32DLL (Use Delete key on keyboard)
7). Go to HKEY_CURRENT_USER –> Software –> Microsoft –> Internet Explorer –> Main and delete the entry Window Title “Hacked by Godzilla”
8). Now open the group policy editor by typing gpedit.msc in Start –> run and pressing enter.
9). Go to User Configuration –> Administrative Templates –> System. Double Click on entry Turn Off Autoplay then Turn Off Autoplay Properties will display.Do as follows: Select Enabled
10). Select All drives and Click OK
11). Now go to start –> Run and type msconfig there and press Enter.A system configuration utility dialogue will open.
12). Go to startup tab in it and uncheck MS32DLL .Now click Ok and when the system configuration utility asks for restart ,click on exit without restart.
13). Now go to Tools –> Folder Options on the top menu of some folder again and select the Do not show Hidden files and check Hide operating system files.
14). Go to your recyclable bin and empty it to prevent any possiblity of MS322DLL.dll.vbs lying there.
Now restart your PC once and you can now open your hard disk drives by double clicking on them
To view More Manual methods to remove autorun.inf virus visit
http://virushunt.com/a/autorun.inf-virus-removal.html
I personally use USB Threat Defender. They claim that it has a unique technology(Proactive + Definiton scan) which not only prevents USB viruses from spreading but also detects and removes exisitng viruses from systems which not even the best Anti-Viruses can detect. It also fixes damages done to system.
Disabling AutoRun or using a AutorunVirus remover will only wont, there are more viruses and not just the Autorun.inf help.
Read here: http://www.arzoosoft.com/usbthreats.html
All my office computers have this insatlled and it does a great job.
I recommend this to everyone for home and office.
http://www.arzoosoft.com/utdefender.html
Abhishek is right buddy..
U can enter the USB with Windows File explorer also….
Or best way is is create a blank autorun.inf on ur fresh USB. So, next time you insert your USB to an infected PC (Personal Computer …. :P) it will ask you to overwrite the blank Autorun.inf with the infected one. Select no.
This tip was also given by Abhishek….
Tweak UI is really great.. and is very effective….. thanks for sharing….
By the way.. your website is really amazing.. find many new things.. will comment on good one soon.. after I try those…..
Njoy!!!
nice procedure – but some times for removing a virus u need to know the functioning of the virus and the files it creates
i have read it before – and u can also delete all these files through explorer by opening the infected drive by typing drive letter in the address bar
and then delete the virus and its files.