Subscribe to How-To Geek

Welcome to the How-To Geek Forums

We encourage you to register on our forums and post any questions you might have. The How-To Geeks monitor this forum and will respond to your question quickly.

How-To Geek Forums » Windows Vista

external hard drive infected with Trojan.dropper and it can't be removed

(45 posts)
  • Started 5 months ago by SarahJames
  • Latest reply from SarahJames
  • Topic Viewed 1709 times


SarahJames
SarahJames
Posts: 772

Edit: now that my system is back to normal again I still have to take a look at that external HDD and remove the virus ...

Knoppix is not my first choice as a means to get there (now wonder why that should be ...),
so would it be safe to do it from the VistaPE bootCD?
And how do I get the antivirus program on the bootCD up to date? Strong antivirusprotection seems a requirement here, don't you think? LOL

That's one thing I don't understand about Live CD's - where do they write their data to?
Not to the CD - that's impossible.
To my HDD? But when I remove the bootCD I don't see a single trace of it and I've read topics that it is a good idea to start from a bootCD if you had a systemcrash and you want to save your data to USB / external drive etc. before doing a restore, because when you use the bootCD no data get's overwritten on your original system.
So how does this work?
(Ok not a need to know part of getting the virus off the external drive, I'm just being curious)

Sarah.

Posted 5 months ago #
 
whs
whs
Posts: 6597

Sarah, maybe this helps. http://en.wikipedia.org/wiki/Live_CD

Posted 5 months ago #
 
SarahJames
SarahJames
Posts: 772

Hi Guys,

Today I finally go round to formatting the external drive.
So far it looks good.

It is divided into two parts (I'm working on the laptop btw, not on my own computer). Drive H, which I formatted and it looks good.
But there is also a drive G, which is called Password, about 15 MB in size and it acts like a CD.
I tried formatting it in cmd, since in Computer> Beheren (Management?) there was no option to format.

When in cmd I get this:

In general: I need to add the name Password or it won't work to start with.
And then it starts, but stops because 'the drive is writeprotected'.

But AVG clearly indicates the virus is on this drive, I think it is vital I clean this thing up.

Any suggestions?

Posted 4 months ago #
 
SarahJames
SarahJames
Posts: 772

LOL - I'm not really sure what I did and if it is a problem or that it actually solved my problem.
When I rightclicked G and selected Properties, at first I checked if there were new drivers.
There were no new drivers.
I also had the option to select to remove the drive, which I did andnow the whole drive G is gone, but H works all right (not sure what will happen after a reboot ...).

When on H I can select to get G back, but I thought maybe this will enable me to leave H on and not having to worry the laptop get's infected. True?

I'll leave the external drive disconnected, till I've heard from you:)

Cheers,
Sarah.

Posted 4 months ago #
 
SarahJames
SarahJames
Posts: 772

Posted 4 months ago #
 

RSS feed for this topic

Reply

You must log in to post.

Sponsored Links
Getting Started
About How-To Geek
What Is That Process?
svchost.exe
jusched.exe
dwm.exe
ctfmon.exe
wmpnetwk.exe
wmpnscfg.exe
rundll32.exe
wfcrun32.exe
Ipoint.exe
Itype.exe
Wfica32.exe
Mobsync.exe
Cmd.exe
Dpupdchk.exe Adobe_Updater.exe

Copyright © 2006-2009 HowToGeek.com. All Rights Reserved.