How to get data of an infected USB thumb drive?

El Koeno

Emperor
Joined
May 22, 2006
Messages
1,926
I recently went on a research trip to Sierra Leone. I brought back a thumb drive with survey data that was entered by people there. Now every single computer there is absolutely crammed with viruses. So the thumb drive is infected as well. However, I'd really like to get the data from the drive without risking anything. Would getting the data from the drive on a Linux system, and then transferring it to a Windows box be safe? Should I run a virtual box? Or is updated anti-virus sufficient protection?
 
Simple: I'd disable autoplay so nothing pops up then simply scan it on Windows.

If youre real worried I think you could also use a Linux Live CD (isn't Clam AV a virus scanner for Linux?)
 
Linux liveCD is a really good idea. Pull the data off, save it to non-infected media (such as a CD) and then transfer it to your windows machine. Do not allow anything to autorun, and make sure your antivirus/antimalware is as up-to-date as possible.

And yes, Id use Clam AV on the data as a precaution too (You can install it on the live CD temporarily if it doesnt come with it.)
 
plug into macintosh->use anti-virus->use like normal
 
"This USB drive is synced with another computer. Would you like to sync it with this computer?"

(I know it wont do that...but thats the first thing that comes to mind when I think of mass usb storage and macs)
 
"This USB drive is synced with another computer. Would you like to sync it with this computer?"

(I know it wont do that...but thats the first thing that comes to mind when I think of mass usb storage and macs)

The closest thing I've seen to that is when you plug in an iPod/iPhone/iPad
 
My PC does that too... and my Mac mostly wants to know if it should copy all iTunes bought music to the Mac

My Ubuntu box does not. It just adds songs in addition to what you already have.
 
Well, I ended up opening it in Ubuntu, deleting everything remotely suspicious, after which I took it to a uni pc which I figured would have good security. Scanned it, and it all worked nicely (I hope...).
 
Back
Top Bottom