LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 10-14-2009, 08:55 AM   #1
adityavpratap
Member
 
Registered: Dec 2004
Location: Hyderabad, India
Distribution: Slackware 13, Ubuntu 12.04
Posts: 440

Rep: Reputation: 32
unable to remove autorun.inf (probably infected) from flashdrive


Hi,

I have a pendrive that contains a file autorun.inf with the following contents -

Quote:
[AutoRun]
;ntqcyasgw WKekPc
;
sHEll\opEN\Default=1
;
opEn= iyvda.exe
sHELl\oPEN\cOmmaND= iyvda.exe
;ggHCpmEXOmiVNpouKrDHgbrrQky rjCmChrCRuRFUqKtyOmypPslPhaVLkxwBU
sHell\explOrE\COMmaND = iyvda.exe
;
shelL\AUtoplaY\CoMmand= iyvda.exe
clamscan says that this file is infected. So I tried to use the --remove option of clamscan. It complained about the file system being read-only. Then I tried to delete the file manually as root. Still the same message
Quote:
rm: cannot remove `/media/74DE-7E42/autorun.inf': Read-only file system
I tried googling but all solutions I found were Windows-specific.

Any idea how I can remove the file?

P. S. There is no file named iyvda.exe in the pendrive.
 
Old 10-14-2009, 09:11 AM   #2
Woodsman
Senior Member
 
Registered: Oct 2005
Distribution: Slackware 14.1
Posts: 3,482

Rep: Reputation: 546Reputation: 546Reputation: 546Reputation: 546Reputation: 546Reputation: 546
Perhaps you are using a Sandisk Cruzer USB device? Or, more specifically, a USB device using U3 technology? Perhaps then you might want to read a recent discussion about that problem:

Fooling The System That A Read-Only Device Is Read-Write
 
Old 10-14-2009, 09:18 AM   #3
adityavpratap
Member
 
Registered: Dec 2004
Location: Hyderabad, India
Distribution: Slackware 13, Ubuntu 12.04
Posts: 440

Original Poster
Rep: Reputation: 32
Yes it is a Sandisk pendrive. I'll read up the link you have posted.
 
Old 10-17-2009, 11:36 PM   #4
willysr
Senior Member
 
Registered: Jul 2004
Location: Jogja, Indonesia
Distribution: Slackware-Current
Posts: 4,661

Rep: Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784Reputation: 1784
have you tried to run chmod 777 autorun.inf and then deleting it?
 
Old 10-18-2009, 12:09 AM   #5
slackd
Member
 
Registered: Sep 2009
Location: Bangalore, India
Distribution: Fedora, Slackware, Arch Linux
Posts: 260
Blog Entries: 1

Rep: Reputation: 60
i saw this autorun virus many times in pen drives..
i fixed it from windows by going to command prompt

type:


Code:
attrib -s -r -h autorun.inf
then delete the file from the pendrive..its a superhidden file in windows.

edit: i have a cruzer micro myself, never faced this problem myself, however i dont use the worthless U3 system that i comes with.

Last edited by slackd; 10-18-2009 at 12:21 AM.
 
Old 10-18-2009, 02:01 AM   #6
adityavpratap
Member
 
Registered: Dec 2004
Location: Hyderabad, India
Distribution: Slackware 13, Ubuntu 12.04
Posts: 440

Original Poster
Rep: Reputation: 32
OK, the chmod 777 bit did it. Thanks willysr.

Slackd, I didn't want to enter windows, lest the virus did some harm. But thanks any way. I don't know much about the U3 system. I'll read up on it. :-)

I read somewhere on the net that if I create a autorun.inf folder in the pendrive, it will prevent any future attempts by malicious programs to create a autorun.inf file and hence they will not be able to autorun themselves. Has any one tried it actually?
 
Old 10-18-2009, 03:16 AM   #7
jedi_sith_fears
Member
 
Registered: Jan 2008
Location: Kolkata
Distribution: Debian GNU/Linux bookworm/sid
Posts: 136
Blog Entries: 1

Rep: Reputation: 29
Smile

Usually when you face this kind of problem, check once if the Flash Drive is in NTFS, and mounted in read-only mode. If its read-write, then you will be easily able to delete the files.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
My Kingston DT 101 II 2GB infected by autorun.inf & gi2ky.exe and becom read-only!! YassBoss Linux - Hardware 23 07-11-2009 09:57 AM
Need to remove virus {JS:ScriptsSH-inf[Trj]} patrickgpg Linux - Newbie 2 06-03-2009 12:02 PM
USB Thumbdrive Win32/Linux Encrypt & Stop Write to autorun.inf jago25_98 Linux - Hardware 1 06-01-2009 09:14 AM
How to write an autorun.inf file Digital Surgeon Programming 6 04-04-2006 03:46 PM
unable to get inf file for inspiron 2200 SlipAway172 Linux - Wireless Networking 1 02-24-2006 08:29 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 09:18 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration