Tuesday, November 10, 2009

How to identify and Avoid the USB drive affected with virus

Virus and worms are easily spread by carrying it on a removable medium such as ,USB drive , I-Pod, CD, Floppy. USB drive is otherwise called as “Flash Drive”,”Thumb Drive” ,”Memory stick” ,”External USB Hard Disk”. Even though we have very good Antivirus , New Viruses are one step Ahead than Antivirus. We cannot restrict USB Drive , but we can avoid spreading of virus and worms through USB Drive. So we have to be little bit careful while working with USB Drive, some precautionary steps are follows.

How to identify the USB drive affected with virus

After Inserted USB drive

This screen shot shows the USB drive which is affected with virus


How to Enable Hidden files and folders

• Goto Tools -> Folder options -> click view tab
• Under view tab goto -> Advanced settings -> Hidden files and folders
• Click radio button “show hidden files and folders”
• Remove check mark “Hide extension for known file types”
• “Hide protected operating system files”
• Click Apply , ok.


After Enabled the hidden files you can view the virus in the USB drive

What is inside the Autorun.inf?

Autorun.inf script
;2wKsL0qj9D5s91DaJdDkiakaaq22ww
[AutoRun]
;jU3wwLJ34ik9roLjds8ra21SdLsSwiDI2qijKpKKjq0
s03okaSDafSskKDKDrswaLa81l4
open=p83gjy.exe
;wkkLKi8sSdkL24
shell\open\Command=p83gjy.exe
;Ld4faAj21fw2lss0aasasA6pJooskL9
shell\open\Default=1
;dO4ias5k3rHkwscwr
shell\explore\Command=p83gjy.exe
;aL0Hd8rZdaiU4qwaaJr1ojAowini32o321s4


NOTE: Script & exe files may vary

How to avoid ???

STEP 1:
Don’t allow the USB Drive to Auto Play after plug in, cancel it.

STEP 2:
 Go to My computer
 Devices with Removable storage
 Do not Double click the USB Drive
 Note the drive letter assigned to USB Drive as mentioned in the Fig
 Here E:

STEP 3:
• Go to -> Start -> Run -> Type E:

• Now you can view the Contents of your USB Drive

• Copy the necessary files
• Repeat the Process while using USB Drive
• Now your Laptop is free from viruses & worms.
• It is a time consuming process, but no other way to avoid the virus.

No comments:

Post a Comment