Lately, my USB thumbdrive was infected with a trojan virus, Boot.exe. Most probably, the virus was written onto my thumbdrive from one public computers that I usually frequent. I was notified by the existence of the virus when my anti-virus started complaining that it found a Trojan in my thumbdrive. Since the virus is a high level threat, the anti-virus did a viral quarantine and deletion. That was when the real ordeal started.
After deletion, the USB thumbdrive is unable to be “left-double-clicked”. When double-clicked, Windows will launch a windows complaining that Boot.exe cannot be found. Thus, I began my forensic work. What I found was that my Autorun.inf file (the file that is used to Autorun specified programs) has commands to launch Boot.exe. Apparently, the virus overwrites the old Autorun.inf to an infected one which launches the virus everytime the thumbdrive is placed into a PC. Thus, this is the solution that you should do if you are facing the same problem. I’m using a Sandisk Cruzer micro. It should work with other USB thumbdrives.
The first option is to reformat all the data in the thumbdrive. This is the easiest option but it’s not the most sophisticated one.
What I’m suggesting is to first; do a virus scan (after updating your virus database) on your thumbdrive. Next, backup your data (just to be safe) to a hard disk. Lastly, change your Autorun.inf like so:
1. Go to tools -> folder options -> view tab: check show hidden files and folders and click OK.
2. Go to My Computer -> Right-click your thumbdrive -> explore.
3. In your Windows explorer, double click Autorun.inf (which is by default in your thumbdrive’s root directory)
4. Delete all the contents inside the file, and replace the contents with:[Autorun]
shell=OpenWell, if you can’t find the autorun.inf, download the file here (right-click and save as) and save it in your USB thumbdrive root directory. Unmount your thumbdrive (remove it the correct way) and re-insert it back again. Now you should be able to Double-click it without any problems! Cheers!
taken from techie-talks
Now children, say thank you to Mr firdooze! Eh buddy, sorry if I jacked your post, but hey…inbound links for you!

Leave a Reply