"My removable device" shortcut virus..

Anonymous
2013-02-25T20:21:23+00:00

When I plug my USB on my computer, a virus hides my files and creates a shortcut called "My removable device".

If I check shortcut's properties it shows this path "C:\windows\system32\rundll32.exe ~$WV.FAT32,_ldr@16 desktop.ini RET TLS " ".

I ran AVG Antivirus and it found the following:

Trojan horse Deflier.G

Windows/SysWOW64/svchost.exe

and it deleted it.

I format my usb, then I re-insert the USB and the shortcut is there.. again.

If I run a "show usb" program, it shows me the hidden files, there are

desktop.ini

thumbs.db

autorun,ini

~$WOSFVR.FAT32

a folder with no name where all my files were relocated by the virus

and the evil shortcut.

please help.

[Moved from Windows]

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2013-02-26T11:24:04+00:00

Hi Carlos,

Welcome to Microsoft Community and thanks for posting the question.

Based on the description provided, it looks like you are facing an issue while connecting USB to the computer.

It would be great if you could answer these questions in order to assist you further.

1.       Is the issue confined while connecting any particular USB?

2.       Have you made any changes to the computer prior to this issue?

I would suggest you to try the following methods and check.

Method 1:

I would suggest you to run the Microsoft Safety Scanner and check if there is any virus.

Microsoft Safety Scanner:  http://www.microsoft.com/security/scanner/en-us/default.aspx

Note: The Microsoft Safety Scanner expires 10 days after being downloaded. To rerun a scan with the latest anti-malware definitions, download and run the Microsoft Safety Scanner again. Any data files that are infected may be cleaned by deleting the file entirely, which means there is a potential for data loss.

 Method 2:

I would suggest you to Remove and reinstall all USB controllers.

To remove and reinstall all USB controllers, follow these steps:

a)    Click Start, click Run, type sysdm.cpl in the Open box, and then click OK.

b)    Click the Hardware tab.

c)     Click the Device Manager button.

d)    Expand Universal Serial Bus controllers.

e)    Right-click every device under the Universal Serial Bus controllers node, and then click Uninstall to remove them one at a time.

f)     Restart the computer, and then reinstall the USB controllers.

g)    Plug in the removable USB storage device, and then test to make sure that the issue is resolved.

Keep us posted on the status of the issue.

If you need any other information about Windows, feel free to post your questions and we will be glad to help.

Was this answer helpful?

4 people found this answer helpful.
0 comments No comments

66 additional answers

Sort by: Oldest
  1. Anonymous
    2013-03-04T18:04:00+00:00

    I tried scanning with Bitdefender. The anti-vir also found desktop.ini and Thumbs.db. But yeah, the problem's still there.

    Microsoft, help.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2013-03-06T13:30:36+00:00

    I also had the same virus.

    One of the office PCs was infected.

    OS - Windows 8 pro 64bit

    AV - NIS 2013 updated definitions

    others -  Java 7 update 11 64-bit

    NIS was able to block infection of the flash drive but the virus itself

    kept trying to infect the flash drive every time a flash drive is plugged in.

    luckily, the user had a standard user type account(non-administrative).

    WARNING: I don't recommend doing following

    1. if you are not familiar with user account creation, maintenance or computer administration.
    2. if you dont want to delete a user account and its related files.

    I will not be held responsible for system instability or data loss.

    I was able to remove the infection by

    1. back up the user's data locally. I recommend storing it in a folder in a different partition accessible to authorized users.
    2. delete the infected user account(pick "Delete Files" when prompted)

    http://windows.microsoft.com/en-US/windows7/Delete-a-user-account

    1. create another user account
    2. copy over user's data from the back up folder created in step 1.

    This could probably work for administrative type accounts though i haven't tested it yet.

    So far, no symptoms of the virus

    1. flash drive infections
    2. icon only(no name) program running, viewed from task manager,
    3. svchost.exe having user's name running, its usually "SYSTEM" or blank viewed from task manager.

    Also, if you are not using java, i recommend removing it. if not, get the latest update always.

    I believe although not 100 percent certain that the virus came from the user browsing sites exploiting Java's zero day holes.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2013-03-07T02:41:02+00:00

    Hi. I might try your method out later. Thanks!

    Though, I'm still dying to know how to remove the infection from my thumbdrives and EHDs without risking too much data loss and risking my PC getting infected again.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2013-03-07T04:16:19+00:00

    Hi Koac,

    First off, if you haven't done it yet.

    I strongly suggest disabling "Auto-play" for flash drives in your computers.

    Also, update your windows and anti-virus software.

    WARNING: I don't recommend doing following 

    1. if you are not familiar with computer administration, formatting flash drives, using the command prompt.
    2. if you don't want to delete the contents of the flash drive.
    3. if you haven't removed the virus from the infected computer
    4. if you are not willing to risk infecting the computer to remove the flash drive infection

    I will not be held responsible for system instability or data loss.

    The method I provide worked for my situation.

    However, there is no guarantee that this method will work for you.

    Because the virus moves the contents of your flash drive to a hidden folder with no name.

    1. display the hidden no-name folder of the flash drive.

        open command prompt

        run "attrib -h -r -s /s /d F:\*.*"  assuming "F" is drive letter of your flash drive        

    1. rename the hidden no-name folder
    2. copy the contents of the renamed folder to a folder in your hard drive
    3. verify if the copy was successful, check the contents of the copy to be sure
    4. format the flash drive
    5. unplug the flash drive and plug it back in.

       if your AV does not detect viruses and

       if the contents of the flash drive is not similar to that mentioned in the OP

       then the infection should be gone

    you can move or copy back the files you copied in step 3 to the flash drive.

    Was this answer helpful?

    0 comments No comments