Author Topic: Virus in pen drive hides all my files  (Read 3413 times)

0 Members and 1 Guest are viewing this topic.

Fluidic

  • Guest
Virus in pen drive hides all my files
« on: October 17, 2013, 09:52:13 AM »
a virus in my pen drive has hidden all files but shows used up space. i ran mc shield and dds. i'm attaching the log files here. please help me.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37549
  • Not a avast user
Re: Virus in pen drive hides all my files
« Reply #1 on: October 17, 2013, 10:05:58 AM »
follow instructions and attach logs (not copy and paste)  http://forum.avast.com/index.php?topic=53253.0

run in order listed
AdwCleaner / Malwarebytes / OTL / aswMBR

when done, removal experts will be notified and help you
when finish, all tools used will be removed



Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: Virus in pen drive hides all my files
« Reply #2 on: October 17, 2013, 11:34:09 AM »
a virus in my pen drive has hidden all files but shows used up space. i ran mc shield and dds. i'm attaching the log files here. please help me.
Hello,
I think that it only hides the files/folders -- so in settings of your file manager (explorer, Total commander, etc) set to view hidden files/folders.

Milos

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Virus in pen drive hides all my files
« Reply #3 on: October 17, 2013, 12:56:09 PM »
Hi Fluidic,
Code: [Select]
F:\autorun.inf > Suspicious > Renamed. (MD5: d41d8cd98f00b204e9800998ecf8427e)autorun file has been renamed to autorun.inf.vir to prevent his running.
Can you please open that autorun file via notepad and paste here its contents?
If autorun refers to some legit name.exe file (eg installation) it can be restore via MCShield > Whitelist tab.


Fluidic

  • Guest
Re: Virus in pen drive hides all my files
« Reply #4 on: October 17, 2013, 08:42:41 PM »
Hi magna86,

It says that windows can not open this file.

@Milos,
I have tried it, but it doesn't work.

I am attaching log report of dds here

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37549
  • Not a avast user
Re: Virus in pen drive hides all my files
« Reply #5 on: October 17, 2013, 08:53:40 PM »
it seems you have multiple AV install, avast and TrendMicro

you need to uninstall one.   http://www.avast.com/en-us/faq.php?article=AVKB11



Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Virus in pen drive hides all my files
« Reply #6 on: October 17, 2013, 09:01:36 PM »
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Trend Micro Titanium Maximum Security 2012 *Disabled/Outdated* {B7599298-8445-728A-A5C7-A26A082C8BDA}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Trend Micro Titanium Maximum Security 2012 *Disabled/Outdated* {0C38737C-A27F-7D04-9F77-991873ABC167}

TrendMicro is disabled as far as I can tell
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Virus in pen drive hides all my files
« Reply #7 on: October 17, 2013, 09:16:29 PM »
Alen, AV works on high system level, is not enough just to turn off one of antivirus. His drivers are still loaded and at that level occurs conflict with other AV.
You do need to uninstall one of them.


DDS shows some adware leftovers. We shall remove them with zoek:





Please download zoek.zip or zoek.rar by smeenk () from here or here and save it to your Desktop.
Unpack the archive...
  • Close any open browsers
  • Temporarily disable your AntiVirus program. (If necessary)
    If you are unsure how to do this please read this or this Instruction.

  • Double click on zoek.exe to run the tool .
    Please wait while the tool does not start...

  • Copy the text present inside the code box below and paste it into the large window in the zoek tool:
Code: [Select]
emptyclsid;
{4145006D-47F8-42F2-8186-2225AAFECDD3};c
C:\Windows\SysWow64\sho*.tmp
ipconfig /flushdns >> %temp%\log.txt;b
autoclean;
  • Click on button.
    Please wait until a logreport will open (this can be after reboot)

  • Save notepad to your Desktop and attach here zoek-results.log
    Note: It will also create a log in the C:\ directory named "zoek-results.log"
----------------------------------------------------------------


Quote
It says that windows can not open this file.
My bad. Rename autorun.inf.vir into autorun.inf (delete .vir extensions ) and then notepad shall see and read autorun file.
« Last Edit: October 17, 2013, 09:18:01 PM by magna86 »