Please suggest some safety measures for analysing viruses on the pendrive

malware

My pendrive have been infected by virus and my antivirus fails to detect it. Several folders on my pendrive have been hidden and the virus has spread all over my computer. I see many strange changes in my computer like BiBin.exe appears everywhere, several shortcuts get created when several other portable devices get connected. I identified this as a shortcut virus but there are many other viruses in my portable drive.

I want to analyse all the viruses present in my drive in a safe environment. But when I connect my drive to another computer I'm quite sure it will infect that too. So how shall I analyse the viruses present in my drive without infecting my windows PC

Best Answer

If possible, you should attempt to only insert the drive into a secondary PC running some live version of a linux distro, preferably one you wouldn't mind completely wiping afterwards.

If not, just cut your losses and physically destroy the pendrive. USB viruses are extremely efficient these days, and are more frequently able to persist in hardware between wipes (either on small partitions on the pendrive, or by loading themselves into the firmware of the infected machines hardware).


Examples:

-badUSB

--- SRLabs badUSB BlackHat Slides

-UEFI rootkits

--- Hacking Team write up on TrendMicro


To more directly answer your question: No, there is no way to insert the drive into any new machine and assume it hasn't infected it at some level.

If you need to view the files on the drive (maybe so you know what you've lost / so you can physically print and recreate them by by hand), I'd recommend viewing them on your already infected machine after unplugging any network cables, since it can't really get any worse.

Related Question