I am having a problem. Whenever i plug in my usb in my office computer, the following folders appear.
If i try to copy any folder from my computer to my usb drive, it hides the folder the other folder is changed to .exe file.
Scanned it with MSE and it didnt show me anything....i tried deleting the files using cmd (attrib method) and deleted the files. I even did a quick format. But whenever i re plug in my usb these 2 files are always there in it.
This question is marked "community wiki".
asked Dec 01 '12 at 07:35
I never even heard of this one before so these are just suggestions.
My first thought is that the malicious files have processes running which are preventing the files from being deleted properly.
You could use task manager to search for these processes but first I would try assigning a different letter to the USB drive. For drives with software installed this almost always causes the software to stop working. With any malicious processes stopped you can do a full format on the USB drive which will hopefully nuke that SVCHost, its data folder and anything else on there.
In addition try using USB Oblivion to remove anything left behind In the registry on that computer by the infected USB drive. Here is the link http://code.google.com/p/usboblivion/
If that doesn’t work then there is a program called Autorun Eater which finds and removes malicious files from USB drives. I haven’t used it myself but its free and looks worth a try if no one else can help. Here’s the link http://oldmcdonald.wordpress.com/
If neither of these work, my only suggestion is to try another manual delete.
First check task manager for any processes that the files are running and end them. Then using an elevated command prompt to avoid any administrator rights that may be protecting the files, remove any read only attributes on the unwanted files and delete them. Then double check that they are deleted properly.
Use the command prompt to check for any other suspicious files or directories including hidden ones, end any processes they have running and delete them. Double check they are deleted and if not continue looking for any process that is preventing the delete.
Let me know how you get on