Solved Windows Defender - delete virus, rescue data

brato92

New Member
Messages
20
Hi everyone, i have a problem with my USB stick: i've borrowed it to a colleague 20 minutes, and now, when he returned me i have a little surprize: instead of finding my personal data from faculty, i found these shorcuts, who turns out that are viruses (Windows Defender alerted me).
stick.JPG

The stick was used in one of our laboratory class. I want to recover my data because i have about 1.5gb of files which are very important to me. When i scan the USB with Malwarebytes Anti-Malware, it detects nothing, but scans even my personal files, despide i cannot see them (even if i pick 'Show hidden folders and files' option), only Windows Defender finds the viruses.
stick2.JPG

Is it possible to delete the viruses and save my personal files (txt's, doc's and pdf's), without formatting the stick ? Thanks !
stick3.JPG
View attachment mbam-log-2013-11-20 (11-05-07).txt
 

My Computer

System One

  • OS
    Windows 8 Pro 64-bit
    Computer type
    Laptop
    System Manufacturer/Model
    SONY VAIO
if the virus deleted your files and overwrote them...it's unlikely you can recover them.....you did back them elsewhere up didn't you ?
 

My Computer

System One

  • OS
    Windows 8 Pro
    Computer type
    PC/Desktop
    Memory
    6 GB
    Screen Resolution
    1280 x 1024
    Hard Drives
    12 TB in 6 disks
    PSU
    TX650
    Keyboard
    G15
    Mouse
    Intellimouse 3.0
    Internet Speed
    100 Mbits
    Browser
    Chrome
    Antivirus
    Trend Micro
No, unfortunately i didn't back up all of them. This means that i have no chance getting back them (most of them are Office documents) ?
 

My Computer

System One

  • OS
    Windows 8 Pro 64-bit
    Computer type
    Laptop
    System Manufacturer/Model
    SONY VAIO
There are "file undelete" tools available, although I have not used one in a long time. There is a chance that you could recover some of your files with one.

Perhaps someone here knows of a good one. Googled for "file undeleter" and found this among many others:

15 Free Data Recovery Software Tools (Free File Recovery Software)
 

My Computer

System One

  • OS
    Windows 8.1 consumer 64 bit
    Computer type
    Laptop
    System Manufacturer/Model
    Acer Aspire M5 481PT-6644
    CPU
    Intel Core I5
    Memory
    6 GB
    Hard Drives
    Spinning/SSD hybrid 500GB/20GB
    Mouse
    ELAN Trackpad
    Internet Speed
    18mbs/5mbs
    Browser
    Chrome
    Antivirus
    Windows Defender
Viruses like to play hide the files in some instances.

Have you deleted the virus successfully? If not, another suggested AV program is SuperAntiSpyware. The free version will work fine.

SUPERAntiSpyware - Downloads

The files may/may not still be there. The virus has probably changed the attributes of the files to render them hidden. Once you have cleaned the FD, Have a look at these articles, they will guide you through unhiding them using the command prompt:

~~Long title is long~~: TIPS: Unhide hidden files (caused by viruses)

How to Open the Hidden Files in a USB Pen Drive: 6 Steps
 

My Computer

System One

  • OS
    Win 7 32, Win 7 64 Pro, Win 8.1 Pro
    Computer type
    PC/Desktop
    System Manufacturer/Model
    It's a Dell, Dude.
    CPU
    Intel Caffinated Core Duo
    Motherboard
    Father is bored too.
    Memory
    4 GB
    Graphics Card(s)
    NVidia something-or-another
    Monitor(s) Displays
    24" HD TV/Monitor/Alternative Dimensional Viewing Portal
    Screen Resolution
    Fuzzy after a couple drinks
    Hard Drives
    2 or 3, depending on if it's a night they're arguing about having a "split personality crisis" because I partitioned the drive.
    Case
    Don't get on my case....man
    Cooling
    Scotch on the rocks on the weekends..
    Keyboard
    Mad Catz Cyborg V7. Or maybe Cyborg Catz Are Mad At V7's??? I know it lights up...far out.
    Mouse
    currently being stalked by the cat...
    Internet Speed
    Never fast enough...
    Browser
    Defeated by Mario...wait...OH...BRowser...
    Antivirus
    Various
Windows Defender doesn't have a 'Delete' option for quarantined items. The virus is quarantined. Also, Super Anti-Spyware didn't detect anything suspect. Maybe i need another tool to remove it.

EDIT: i just followed your first tutorial, and i managed to unhide my files in 2 steps. The files were stored in a new folder. There were more shortcuts, but i've deleted them. I'll copy the files to my HDD, then format the Stick to delete the virus. Thanks ! Just didn't know it was so simple.
 
Last edited:

My Computer

System One

  • OS
    Windows 8 Pro 64-bit
    Computer type
    Laptop
    System Manufacturer/Model
    SONY VAIO
Glad you got your files back. :D You may want to consider immunizing your FD's with this tool.

USB Immunizer | Bitdefender Labs

It disables autorun-related threats before they access the computer. Once installed, it constantly watches for newly inserted USB storage devices and immunizes them on the fly. If you accidentally plug in an infected USB drive that has not been immunized, the computer will not auto-execute the piece of malware located on the USB storage device.

To check to see if your saved files have been compromised, you can upload them to Virus Total (Maximum file size: 64MB)

https://www.virustotal.com/

VirusTotal is a free service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware.

Thanks ! Just didn't know it was so simple.

Yepperz, the command line still proves useful & knowing some basic commands is a good thing to learn :D
 

My Computer

System One

  • OS
    Win 7 32, Win 7 64 Pro, Win 8.1 Pro
    Computer type
    PC/Desktop
    System Manufacturer/Model
    It's a Dell, Dude.
    CPU
    Intel Caffinated Core Duo
    Motherboard
    Father is bored too.
    Memory
    4 GB
    Graphics Card(s)
    NVidia something-or-another
    Monitor(s) Displays
    24" HD TV/Monitor/Alternative Dimensional Viewing Portal
    Screen Resolution
    Fuzzy after a couple drinks
    Hard Drives
    2 or 3, depending on if it's a night they're arguing about having a "split personality crisis" because I partitioned the drive.
    Case
    Don't get on my case....man
    Cooling
    Scotch on the rocks on the weekends..
    Keyboard
    Mad Catz Cyborg V7. Or maybe Cyborg Catz Are Mad At V7's??? I know it lights up...far out.
    Mouse
    currently being stalked by the cat...
    Internet Speed
    Never fast enough...
    Browser
    Defeated by Mario...wait...OH...BRowser...
    Antivirus
    Various
I'll try USB Immunizer. Good to know about it. Thanks again !
 

My Computer

System One

  • OS
    Windows 8 Pro 64-bit
    Computer type
    Laptop
    System Manufacturer/Model
    SONY VAIO
Windows Defender doesn't have a 'Delete' option for quarantined items. The virus is quarantined. ...
...
Hmmm...when I look at the History tab in Windows defender, there is a Remove and a Remove All option. In fact, I see a Remove button in your screen shot in your first post.
 

My Computer

System One

  • OS
    Windows 7 Professional
That button removes the viruses from History tab, not remove it permament. It is still there.
 

My Computer

System One

  • OS
    Windows 8 Pro 64-bit
    Computer type
    Laptop
    System Manufacturer/Model
    SONY VAIO
Back
Top