• How to check and clean a flash drive from viruses online for free (Windows program). USB Disk Security – protect your computer from viruses from USB flash drives

    Read, how to remove a virus that converts files and folders into shortcuts. How to recover data that was lost as a result of such a virus. Have your files and folders on a USB flash drive or memory card become shortcuts? Does a USB flash drive or memory card appear as a shortcut after connecting to a computer? Are you looking for how to recover data and remove a virus that converts files and folders into shortcuts? Are you using an antivirus, but your computer is still infected? Unfortunately, not all antiviruses can protect you from such infections.

    Types of shortcut viruses

    Today, there are two most common types of viruses that create shortcuts: the first create shortcuts instead of files and folders on a flash drive or memory card, others create shortcuts to removable drives instead of the flash drives themselves, external USB drives and memory cards.

    Names of the most common viruses:

    • Bundpil.Shortcu;
    • Mal/Bundpil-LNK;
    • Ramnit.CPL;
    • Serviks.Shortcut;
    • Troj/Agent-NXIMal/FakeAV-BW;
    • Trojan.Generic.7206697 (B);
    • Trojan.VBS.TTE(B);
    • Trojan.VBS.TTE;
    • VBS.Agent-35;
    • VBS.Serviks;
    • VBS/Autorun.EY worm;
    • VBS/Autorun.worm.k virus;
    • VBS/Canteix.AK;
    • VBS/Worm.BH;
    • W32.Exploit.CVE-2010_2568-1;
    • W32.Trojan.Starter-2;
    • W32/Sality.AB.2;
    • Win32/Ramnit.A virus;
    • Worm:VBS/Cantix.A;

    A virus that converts files and folders into shortcuts

    This virus duplicates your files and folders, then hides and replaces them. The virus is a combination of a Trojan and a worm. The danger is that you run a virus every time you want to open your file or folder. Once launched, the virus spreads itself, infecting everything more files and often installs additional malware that can steal password data and credit cards, saved on your computer.

    Virus that converts flash drives and memory cards into shortcuts

    This is a purebred Trojan virus, which hides any removable devices connected to the computer and replaces them with shortcuts to those devices. Each time you click on the shortcut, you again launch the virus, which searches your computer for financial information and sends it to the scammers who created the virus.

    What to do if infected

    Unfortunately, not all antiviruses can detect danger in time and protect you from infection. That's why best protection will not use automatic start removable devices and do not click on shortcuts to files, folders or drives. Be careful not to click on shortcuts that you did not create yourself. Instead of double-clicking to open the disk, click on it right mouse button and select Expand in Explorer.

    Recovering data deleted by a virus

    To reliably recover data deleted by this type of virus, use Hetman Partition Recovery. Since the program uses low-level disk functions, it will bypass virus blocking and read all your files.

    Download and install the program, then analyze the infected flash drive or memory card. Perform data recovery before cleaning the media from the virus. The most reliable treatment option is to clean the flash drive using the DiskPart command; this will delete all information on it.

    Removing a virus from a memory card or USB flash drive

    After recovering data from a flash drive, you can completely clear it using the DiskPart utility. Deleting all files and formatting the device may leave behind a virus that will hide in the boot sector, partition table, or unallocated area of ​​the disk. Watch the video to see how to properly clean a flash drive.

    Removing a virus from a flash drive using the command line

    This method does not guarantee to clean the flash drive from all types of viruses, but it can remove a virus that creates shortcuts instead of files. You won't need to download and install third party utilities, removal is done using the built-in Windows version tool.


    Removing a virus from a computer

    The simplest and most reliable way to clean your computer from a virus is complete reinstallation Windows with removal of the system partition.

    But if you are experienced user, you can try the following method:


    It's no secret that a flash drive is one of the most common ways to infect your personal computer virus, because often for work or other issues we insert it into different computers where we cannot guarantee that they are not infected.

    If your flash drive catches a virus, then in almost 95% of cases it infects the computer through autostart after you inserted the flash drive into your device. To avoid this, you should suspend such actions. Nowadays there are a lot of programs that block startups from flash drives (USB Guard, USB Disk Security), but the most best option disable autoloading in the operating system.

    To do this, go to the “Start” menu, select “Control Panel”, then select “Devices and Sound” and then click on “Startup”. The next step is to uncheck “Use startup for all media and devices” and then click “Save” for the changes to take effect. Now, if a virus gets onto your flash drive, it will no longer load onto your computer on its own.

    We've protected ourselves from downloading viruses to our computer, but that's only half the battle. After using the flash drive for potentially dangerous computer It should always be checked for viruses before working on your computer, so as not to mistakenly launch a virus yourself.
    This is where antis come in handy. virus programs. After connecting the flash drive, you should immediately check it for viruses and if any are found, you should immediately remove them, disconnect the flash drive, reconnect and check again. Here I will immediately note that you should not skimp on anti-virus protection and you should always use paid anti-virus programs that work with up-to-date databases.


    If the funds for good antivirus you do not have, then you should check the flash drive for suspicious and hidden files. It’s very easy to do this; to do this, go to your flash drive, click on top menu“View” and check the box next to “ Hidden elements».


    If new ones unknown to you have appeared next to your files, most likely these may be virus programs, and if your antivirus has not responded to them in any way, then it is better to delete them. After deleting, be sure to disconnect the flash drive and connect it again, carry out the verification procedure again, if the files appear again, then you will have to format the flash drive.

    These methods usually will not protect your personal computer 100%, but they are quite effective in fighting malware. It should be remembered that a flash drive is a potential target for attackers and if it contains files that are important to you, it is better to keep a copy of them in a safe place.

    The above methods are completely free and are designed to ensure that the user understands what information is available on his flash drive.

    Lim Flash Security – recovers hidden files on flash drives

    The program is able to restore the functionality of all usb drives, infected with a virus that creates malicious shortcuts in place of programs, and makes the files themselves hidden. Free software, which allows you to return hidden files on USB drives and clean them of viruses.

    Panda USB Vaccine – antivirus for flash drive

    Using the program, you receive a double level of proactive protection against infection through usb flash drives. Panda USB Vaccine disables autorun both on the computer and on USB drives and others external devices ah ( external hdd, players and phones).

    USB Ports Disabler – disable/enable usb ports on the computer

    The program prevents Windows from detecting and identifying USB devices. Allows you to quickly disable and enable USB ports without interfering with your work USB keyboards and mice. By disabling USB ports, you will at least be protected from infecting your computer with viruses from portable devices, and will also prevent the theft of personal information.

    Ninja Pendisk – protect your computer from infection via USB

    Ninja Pendisk - is popular and free solution, designed to protect computers from viruses transmitted via USB drives. If malicious files are detected on removable drives, they will be deleted.

    Ntfs Drive protection - how to prevent writing to a flash drive

    The program will help you protect your removable drives, and even when your flash drive is inserted into a computer with viruses, they will not be able to write to it and create an autorun file autorun.inf.

    USB Hidden Recover – to recover hidden files and folders

    If your files are lost due to viruses, you can try to recover them using free USB utilities Hidden Recovery. It will help after viruses that hide data on flash drives, try to change the attributes of files and folders so that in a standard way It's not always possible to unlock them.

    USB Disk Security – the enemy will not pass!

    Protecting your computer from possible intrusion the latest viruses, “worms” and other harmful software through USB media. The principle of operation of the program is that it automatically disables autorun of all removable media, passing them through yourself.

    Antirun – protection against infection via a flash drive

    Convenient antivirus solution to protect the system from infection threats from USB drives. Features: controls the connection of USB devices, allows you to safely open or remove the device, protects the flash drive from viruses, completely disables autorun.

    USB Hidden Folder Fix - restoring hidden folders after the virus

    The utility allows you to return hidden folders on a USB drive after they have been exposed to viruses. There are viruses that infect flash drives and external hard drives malicious code, and change the attributes of folders and their attachments, after which they become hidden.

    USB Port Locked – block USB ports

    The program helps to completely block access to the computer via USB ports. The program only blocks flash drives and external USB drives, USB mice and keyboards continue to work as expected.

    Dr.Web LiveDisk – anti-virus bootable flash drive

    Creation boot disk Dr.Web LiveDisk is an anti-virus disk that will help remove and neutralize viruses on a non-working system, and can also be used to transfer important information from an infected computer to another PC or to a flash drive.

    LimFlashFix – show hidden folders on a flash drive

    LimFlashFix - free utility for treating flash drives if the virus has made files and folders on them hidden. If your flash drive is empty, but you are sure that there are files on it

    USB Protection & Recovery – protecting your computer from viruses on a flash drive

    USB Protection & Recovery free program to protect your computer from viruses that can enter it via USB media. Using the utility you can restore hidden by viruses files on a flash drive. Program

    USB Flash Security - how to protect data on a flash drive

    It’s a shame when a flash drive is lost, and it’s doubly a shame when any important data (secret documents, photographs or videos) is recorded on it. And whoever finds your flash drive can easily read these

    Anvide Flash Lock – protect the flash drive from being written to

    Anvide Flash Lock is a tiny utility with which you can easily prevent writing to a flash drive or portable hard drive. This opportunity will protect your drive from viruses that can “climb” onto it

    USB control. USB Tool is a small program that can protect your computer from infected flash drives, as well as protect the flash drive from infection. The main purpose of the program is to prevent infection of the operating system and, as a consequence,

    Keen Eye is a small free utility (antivirus) that is designed to find and isolate viruses that spread through flash drives using Autorun files (Autorun.inf).

    USBDummyProtect – protect the flash drive from viruses

    We already know how to protect your computer from an infected flash drive. great program which is called Antirun. What and how to do when the flash drive is already infected and the files on it are hidden, we too

    Bitdefender USB Immunizer – protector against infection via flash drive

    Check and delete suspicious "autorun.inf" files in automatic mode! Autorun Eater was developed in response to the increase in malware malware distributed using "autorun.inf", be it flash drives, removable hard drives

    Windows 7 Autorun Disabler - disable autorun of mounted devices

    Free Windows program 7 Autorun Disabler allows you to disable autorun in Windows 7. Windows 7 Autorun Disabler is a portable program; in order to work, it is necessary that the user using it has the appropriate rights to

    Flash Defender - protect removable media

    Flash Defender – has high functionality, you can create your own autorun.inf which cannot be deleted standard means, in addition, it is possible to install a number of folders such as autorun.ini, desktop.ini, folder.tmp,

    A USB drive is a “tidbit” for viruses. There is even a separate category of “digital strains.” They are aimed specifically at external drives. Trojans and worms secretly penetrate a flash drive, install their elements (startup modules, startup file, shortcuts) and carefully disguise them, delete or damage user folders and files. They also interfere with the operation of the USB drive: they do not allow you to open a partition and individual folders, they prevent safe removal devices imitate system errors(fake messages appear).

    Let's look at how to clean a flash drive from viruses using various methods.

    Method #1: antivirus cleaning

    Disabling autorun

    The first step is to secure the operating system of the computer on which the scan will be performed. Disable in Windows autorun. So that the virus, after connecting a USB flash drive, cannot automatically start and secretly penetrate the PC’s hard drive.

    This procedure is performed as follows:

    in Windows 7

    1. Press the key combination “Win” and “R”.

    2. In the Run panel line, enter the directive - gpedit.msc.

    3. Click OK.

    4. In the editor window group policy select the “Computer Configuration” section.

    5. Open the “Administrative Templates” subsection.

    6. From the list of options, select Windows Components.

    7. Go to “AutoPlay Policies” → “Disable AutoPlay” settings.

    8. In the settings window that opens:

    • by clicking the left mouse button, turn on the radio button next to the “Enable” add-on;
    • Click the "Apply" and "OK" buttons.

    in Windows 8.1

    1. Right-click on Windows icon on the taskbar.

    2. B context menu select Find.

    3. B search bar type - autorun.

    4. Click in the search results - “Enable or disable autorun”.

    5. In the “Computer and Devices” panel, go to the “Startup” section.

    6. In the block on the left, set the value “Do not perform any actions” in the “Removable media” and “Memory card” fields.

    Advice! If you want to completely disable the AutoPlay feature, click the slider at the top of the block to “Off.”

    Scanning a flash drive

    1. After disabling autorun, connect the USB flash drive to the PC.

    2. Press "Win+E".

    3. In the window that opens, right-click on the USB drive icon.

    4. To check the flash drive for viruses, select “Scan…” from the list of options. (IN in this case This ESET Smart Security).

    5. Remove all malicious objects found.

    Advice! You can perform cleaning using alternative anti-virus scanners - Dr.Web CureIT!, Free Anti-Malware or Kaspersky Virus Removal Tool. Before the scan is performed, do not forget to check the box next to the flash drive in the list of partitions.

    Method #2: formatting

    (removing all data - virus and user files)

    Note. This option is appropriate to use when there is no valuable information on the media or when it is not possible to remove the virus from the flash drive using other methods.

    1. Make sure that AutoPlay is disabled on your computer. And then connect the infected media.

    2. Press the “Win” and “E” keys simultaneously.

    3. Hover over the USB shortcut. Click the right button. IN system menu select "Format...".

    4. In “Formatting...” set the following values ​​in the settings:

    • “File system” - NTFS;
    • “Cluster size” - “Standard size...”;
    • “Volume label” - the name of the flash drive (optional; you don’t have to change it);
    • “Format methods”: in the “Quick” window, check the box to perform superficial (quick) cleaning.

    5. Click the "Start" button.

    6. B additional window confirm the action: click “OK”.

    7. When the procedure is complete, in the “Formatting...” window, click “OK” again.

    8. In the settings window, click “Close”.

    Now the flash drive is clean and ready for full use.

    Method #3: manually removing viruses

    (for advanced users only)

    This cleaning algorithm is advisable to use if you want to save as much useful data as possible located on an infected flash drive.

    1. Turn on Windows display hidden files and folders:

    • press "Win+E";
    • in the window that appears, press “Alt”;
    • V top panel open: Tools → Folder Options;
    • go to the “View” tab;
    • in the last paragraph of options, turn on by clicking “Show hidden files...”;
    • Click the “Apply” and “OK” buttons.

    2. Check your autorun settings. It must be disabled (see Method #1).

    3. Connect and open the contents of the flash drive.

    4. Analyze the files. Elements of the malware may look like this:

    • files with extension .bat;
    • labels;
    • Recycler folder ( a clear sign presence of the virus).

    5. Right-click on each of them and view the “Object” setting in the properties (click → item in the “Properties” menu). IN virus files, in “Object” is usually displayed executable file a “microbe” that attacked a USB drive.

    6. Delete everything malicious files and shortcuts, as well as the executable element of the virus to which they access (listed in the “Object” line).

    Vaccination of flash drives

    A vaccine for a flash drive is a kind of software protection in the form special file(Autorun.inf). It prevents the virus from “settling” on the flash drive: it blocks its functions. Used exclusively as a prophylactic and warning agent on “healthy” USB drives. Created manually and using special programs. We will get to know some of them better.

    Panda USB Vaccine

    A utility from the famous antivirus company Panda. Has a volume of less than 1MB. However, very useful. Available free of charge on the official website. After the first USB launcher Vaccine in the panel, check the boxes next to “Hide tray icon...” and “Enable NTFS...”. And then click “Next”. Connect the USB flash drive and click the “Vaccinate USB” button in the application window.

    Autostop

    Does not require installation. Runs in the MS-DOS console. At the request of the user, he can not only “vaccinate” the flash drive, but also disable autorun by changing the registry settings, and prohibit writing data on the media.

    USB Defender

    An effective tool with graphical interface. Activates USB storage protection in one click (and disables it in the same way). Carefully hides the presence of the “grafting” AUTORUN.INF on the flash drive.

    Let your USB drives avoid viruses!

    From time to time it becomes necessary to remove a virus from a phone flash drive.

    A very simple situation arises - the phone begins to glitch, constantly freezes, some data may disappear from it and other disasters may occur. The reason for this is a virus.

    Employees can tell you this service center or you decide it yourself. This is very easy to do - the phone freezes when working with a flash drive and data disappears from it. In general, it will be clearly visible that the problem is in the removable storage media.

    There are 3 really working ways to solve this problem. We will look at all of them step by step.

    1. Antiviruses for phones

    There are quite a lot of good antivirus programs that work on smartphones and tablets.

    A prominent representative is Kaspersky Internet Security, which can be downloaded from Google Play And Apple Store. We will consider its operation using the example of a device running Android OS.

    Step-by-step instructions for using this antivirus program looks like this:

    • First, Kaspersky Internet Security needs to be downloaded and installed. To do this, go to the Google Play page and complete all the operations described above. There's nothing fancy here, and the app installs just like any other.
    • Then click on the icon to reveal additional functions. Initially, it is a circle with an upward arrow. After clicking, a down arrow appears. These same ones will appear additional features. From the entire list we will need “Verification”. So just click on the magnifying glass picogram with this inscription.

    • In the next window, you just need to click on “Check folder”. This will give us the opportunity to check the memory card and all the folders on it.

    • Now, in fact, a window will be displayed with options for checking a folder in the device’s memory or on the built-in card. We need a second option. Therefore on at this stage You should click on the magnifying glass next to the words “Built-in memory card.”

    That's all. If any viruses are detected on the memory card, you will be asked to delete them or quarantine infected files.

    Everything happens exactly the same as when working with the version in Kaspersky Internet Security for personal computers.

    Clue: If no viruses were found on the memory card, perform a full scan of the entire device. This means that the problem is not with the built-in card.

    2. Computer help

    The second method is painfully simple and banal, but effective. And in most cases it is he who helps.

    To put it simply, in this case you need to remove the memory card from the phone and insert it into the computer. Next you will need to take one of the good anti-virus programs and scan the flash drive with it.

    Just simply taking and inserting a flash drive from your phone into a computer will not work - not a single PC or laptop has exactly the same connector.

    Two devices can come to the rescue: an adapter and a card reader. The first one usually comes bundled with microSD. The second one will have to be purchased additionally. Both devices are shown in Figure 4 - the adapter is on the left, and the card reader is on the right.

    Actually, the card from the phone is inserted into one of these devices, and then into the computer. The card reader works with a USB port. There is definitely one on every computer.

    After you have inserted your flash drive from your phone into your PC or laptop this way, it will detect it as regular card memory. After this, you need to launch the antivirus and select it to check there.

    For example, in Kaspersky Free to do this you need to do the following:

    • In the main program window, click “Check”. We get to the scan menu for this antivirus program.

    • In the menu on the left we see everything possible options checks. Select “Check external devices”. A large area appears on the right where you can select which device we will check. If we only connected a flash drive, there will only be one device there. All you have to do is click the “Start scan” button next to it and wait for this process to complete.

    • After this, as usual, when a virus is detected, several options for solving the problem will be offered. Or maybe there will be only one. In any case, you will delete the infected file or virus from your phone’s flash drive, and this is the most important thing.

    In addition to full-fledged antivirus programs, you can also use small utilities to remove viruses.

    Here is a list of good similar programs:

    • Dr. Web CureIt;
    • Kaspersky Virus Removal Tool;
    • AdwCleaner;
    • Anti-Malware;
    • Spybot Search & Destroy;
    • HitmanPro.

    3. Formatting a flash drive

    If the methods described above do not help, there is only one thing left to do - format removable media information. Then all settings and files on it will be deleted along with the virus.

    Therefore, before performing this procedure, copy all necessary files to the computer. To do this, use the above-mentioned card reader or adapter.

    Advice: After copying files from the flash drive, check the folder where you copied them with your antivirus. It is possible that the virus will be transferred to the computer, but it will be much easier to detect and remove it there.

    • Go to This PC. Find us your removable storage device.
    • Right-click on it. In the drop-down list, select “Format...”.

    • Uncheck the “Quick...” item if it is there. Click the "Start" button.

    Once formatting is complete, the removable media will be completely clean and free of viruses.

    A flash drive is a very convenient device, but often it becomes a source of spreading viruses. Modern viruses, try to infect a flash drive immediately after connecting to an infected computer. Once a virus appears on a flash drive, it becomes dangerous for other computers. The degree of danger depends on what antivirus is installed on the computer. Some users do not install on computers and laptops at all antivirus protection, thereby putting your data and programs at risk.

    1 way to remove viruses

    To clean a flash drive from viruses, you can use a computer or laptop (netbook) with a reliable antivirus. A reliable antivirus means paid version antivirus program, for example or Dr.Web Security Space. If your computer has free version antivirus, for example AVAST Free Antivirus, then it’s better not to take risks - if you connect an infected flash drive, your computer may be infected.

    IN specific case, we will remove viruses using Kaspersky Internet Security 2013 with the latest databases.

    We connect the flash drive to the computer. KIS will prompt you to check the connected removable drive. Choose an option Full check, which will thoroughly scan all files on the removable drive.

    Select the “Full scan” option

    In the very first seconds of the scan, the antivirus detected a threat on the flash drive.

    A threat was detected during the scan

    Upon completion Kaspersky checks Internet Security removed the virus itself.

    According to the report, the flash drive contained Trojan horse("Trojan") Trojan.Win32.Inject.

    As a result of the virus, folders and files (except for the file with the .exe extension) became shortcuts.

    The virus hid files and folders, and instead created shortcuts with the same name. If you click on such a shortcut on an infected flash drive, a copy of the virus will launch. In this particular case, Kaspersky removed the virus, so when you double-click on the shortcut, a message appears that the executable file could not be found.

    The virus file has been deleted, so when you double-click on the shortcuts, nothing criminal happens

    How to return files on a flash drive to their original state?

    Shortcuts that have replaced files and folders on the flash drive can be deleted - they are no longer needed. To restore the visibility of files, you can use file manager FAR Manager. Read the article on how to do this. With a high degree of probability, you can restore file displays using a healing utility, which will be discussed when describing the second method.

    Method 2: removing viruses and shortcuts + recovering files

    This method is suitable if:

    • not only the flash drive is infected, but also the computer to which it is planned to be connected for virus treatment;
    • there is no antivirus installed on your computer, or an antivirus is installed, but you doubt its reliability.

    Dr. Web CureIt will remove viruses from both your computer and flash drive. Moreover, the utility will delete shortcuts created by the virus on the flash drive and try to restore the display of files hidden by the Trojan. As an experiment, let’s run a scan of only the flash drive (let me remind you that the virus has already been removed using Kaspersky anti-virus, but all the files from the flash drive “disappeared” and shortcuts appeared in their place).

    We run a custom scan - select only the flash drive

    The healing utility detected 8 BackDoor.IRC.NgrBot.42 threats. Please note that Kaspersky Lab listed the Trojan as Trojan.Win32.Inject. This is not surprising, since different developers They call their “wards” differently.

    8 threats detected BackDoor.IRC.NgrBot.42

    It should be noted that the utility obviously played it safe and added all the shortcuts leading to the previously deleted virus to the list of threats. All we have to do is click on the Disarm button.

    After the detected threats are neutralized, you can open the flash drive and evaluate the result of the work. Dr. utility Web CureIt worked 100%: threats were neutralized and files were restored.

    Conclusions

    The devil is not as scary as he is painted. With certain knowledge, in many cases, you can deal with viruses without losing your data. The main thing is not to fuss or make sudden movements.

    Do not forget that an antivirus program must be installed on your computer or laptop.