"My removable device" shortcut virus..

Anonymous
2013-02-25T20:21:23+00:00

When I plug my USB on my computer, a virus hides my files and creates a shortcut called "My removable device".

If I check shortcut's properties it shows this path "C:\windows\system32\rundll32.exe ~$WV.FAT32,_ldr@16 desktop.ini RET TLS " ".

I ran AVG Antivirus and it found the following:

Trojan horse Deflier.G

Windows/SysWOW64/svchost.exe

and it deleted it.

I format my usb, then I re-insert the USB and the shortcut is there.. again.

If I run a "show usb" program, it shows me the hidden files, there are

desktop.ini

thumbs.db

autorun,ini

~$WOSFVR.FAT32

a folder with no name where all my files were relocated by the virus

and the evil shortcut.

please help.

[Moved from Windows]

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2013-02-26T11:24:04+00:00

Hi Carlos,

Welcome to Microsoft Community and thanks for posting the question.

Based on the description provided, it looks like you are facing an issue while connecting USB to the computer.

It would be great if you could answer these questions in order to assist you further.

1.       Is the issue confined while connecting any particular USB?

2.       Have you made any changes to the computer prior to this issue?

I would suggest you to try the following methods and check.

Method 1:

I would suggest you to run the Microsoft Safety Scanner and check if there is any virus.

Microsoft Safety Scanner:  http://www.microsoft.com/security/scanner/en-us/default.aspx

Note: The Microsoft Safety Scanner expires 10 days after being downloaded. To rerun a scan with the latest anti-malware definitions, download and run the Microsoft Safety Scanner again. Any data files that are infected may be cleaned by deleting the file entirely, which means there is a potential for data loss.

 Method 2:

I would suggest you to Remove and reinstall all USB controllers.

To remove and reinstall all USB controllers, follow these steps:

a)    Click Start, click Run, type sysdm.cpl in the Open box, and then click OK.

b)    Click the Hardware tab.

c)     Click the Device Manager button.

d)    Expand Universal Serial Bus controllers.

e)    Right-click every device under the Universal Serial Bus controllers node, and then click Uninstall to remove them one at a time.

f)     Restart the computer, and then reinstall the USB controllers.

g)    Plug in the removable USB storage device, and then test to make sure that the issue is resolved.

Keep us posted on the status of the issue.

If you need any other information about Windows, feel free to post your questions and we will be glad to help.

Was this answer helpful?

4 people found this answer helpful.
0 comments No comments

66 additional answers

Sort by: Newest
  1. Anonymous
    2013-03-06T13:30:36+00:00

    I also had the same virus.

    One of the office PCs was infected.

    OS - Windows 8 pro 64bit

    AV - NIS 2013 updated definitions

    others -  Java 7 update 11 64-bit

    NIS was able to block infection of the flash drive but the virus itself

    kept trying to infect the flash drive every time a flash drive is plugged in.

    luckily, the user had a standard user type account(non-administrative).

    WARNING: I don't recommend doing following

    1. if you are not familiar with user account creation, maintenance or computer administration.
    2. if you dont want to delete a user account and its related files.

    I will not be held responsible for system instability or data loss.

    I was able to remove the infection by

    1. back up the user's data locally. I recommend storing it in a folder in a different partition accessible to authorized users.
    2. delete the infected user account(pick "Delete Files" when prompted)

    http://windows.microsoft.com/en-US/windows7/Delete-a-user-account

    1. create another user account
    2. copy over user's data from the back up folder created in step 1.

    This could probably work for administrative type accounts though i haven't tested it yet.

    So far, no symptoms of the virus

    1. flash drive infections
    2. icon only(no name) program running, viewed from task manager,
    3. svchost.exe having user's name running, its usually "SYSTEM" or blank viewed from task manager.

    Also, if you are not using java, i recommend removing it. if not, get the latest update always.

    I believe although not 100 percent certain that the virus came from the user browsing sites exploiting Java's zero day holes.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2013-03-04T18:04:00+00:00

    I tried scanning with Bitdefender. The anti-vir also found desktop.ini and Thumbs.db. But yeah, the problem's still there.

    Microsoft, help.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2013-03-03T15:15:27+00:00

    You got it right man..we have same idea on what is really happening.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2013-03-03T13:15:28+00:00

    Ok... so I tried your method again (I didn't unplug USB drive before restarting computer) and it doesn't work.

    Funny enough my Norton actually found viruses this time:

    "desktop.ini" is Downloader

    "Thumbs.db" is Trojan Horse

    Norton has removed those files but nevertheless problem still remains...

    So I guess it has infected computer to some point if even formatting USB drive and discovering viruses by Norton doesn't help.

    Was this answer helpful?

    0 comments No comments