Kaspersky
Question

trojan.BAT.Starter.nf [E:\TOSHIBA 30GB (Secured by Kaspersky Internet Security 2017).bat]


How do i remove this trojan ? my USB keep getting infected by this thing, help pls

28 replies

Userlevel 7
Badge +4
Welcome. Please pass your mouse cursor over the Kaspersky tray icon and tell us the full, complete name and version number of your Kaspersky product.

Please post the full, complete detection details. Full file name, full path, full location, detection verdict.

Post screenshot of Reports > Detailed reports > Detected objects.
Main Kaspersky window > More Tools > Reports > upper right > Detailed reports > at the upper left, drop down from All Events to Detected objects.

How to take and post screenshot: https://support.kaspersky.com/common/diagnostics/492

PrtSc (Print screen) key (upper right part of keyboard)> open Paint (Start > All programs > Accessories) > Edit > Paste, File >
Save as (jpeg or png, Not bmp). When replying, bottom left of reply box > Drag files here to attach, or choose files... Submit reply.

kaspersky cant remove the trojan inside my usb, and because of it i cant use my usb without worrying itll infect other ppl
Userlevel 7
Badge +9
kaspersky cant remove the trojan inside my usb, and because of it i cant use my usb without worrying itll infect other ppl
Hello @hazzy,
As well as the information posted by @richbuff.
  • IF you MUST keep the USB:
A. BEFORE attaching the USB - create a System Restore Point.
B. Start Windows in SafeMode with Networking
C. Make sure KAV is active.
D. Attach contaminated USB drive.
E. Follow every step Remove a virus from USB carefully.
F. Make sure every detected object shown in your image is deleted.
G. AFTER performing all the steps in E
  1. Remove USB
  2. Return system to Normal mode.
  3. Make sure KAV is active
  4. Run KAV manual Database Update - allow it to complete & do not use the computer while it's running
  5. Run manual FULL scan - allow it to complete & do not use the computer while it's running.
  6. Attach USB - run ANOTHER manual FULL scan - allow it to complete & do not use the computer while it's running.
  7. Check:
  • Issue resolved👌🏽
  • Not resolved😰, let us know?
  • IF you don't have to keep the USB, destr💣y it.
Thank you
i have already tried that method before posting the question here, kaspersky would keep on deleting the trojan but it comes back again, and the cycle repeat, it never ends even after i tried it for the an hour. It even affect the new usb that i bought, what should i do if kasperksy cant remove the trojan ? does it mean i cant use any USB for my PC ?
Userlevel 7
Badge +9
i have already tried that method before posting the question here, kaspersky would keep on deleting the trojan but it comes back again, and the cycle repeat, it never ends even after i tried it for the an hour. It even affect the new usb that i bought, what should i do if kasperksy cant remove the trojan ? does it mean i cant use any USB for my PC ?
Hello @hazzy,
It helps us, help you if you tell us specifics AND "history", that way we don't waste your time or ours.
If you have licensed Kaspersky software please contact Kaspersky Lab Technical Support
Thank you.
i dont have the license, im using free trial, i dont even know how the trojan got into my usb, if kaspersky cant delete the trojan then must be some new trojan that is not in the database am i right ?
i even scanned my PC and disinfect everything already
Userlevel 7
Badge +9
KSCloud Free. .i scanned my PC, disinfected everything already.

Hello @hazzy,
  1. Did the issue begin BEFORE or AFTER Kaspersky was installed?
  2. Please export the Report, save as TEXT file, upload to your post, using the Upload icon.
  3. Run Privacy Cleaner, including Reboot
  4. AFTER Privacy Cleaner AND REBOOT, run GSI & Windows Logs, upload the zip folder to cloud & PM the link please?
  • ***Do not use the computer while GSI is running***
Im not sure, but i think the issue begin before Kaspersky is installed
Already run the privacy cleaner and reboot afterwards

here is the report
Userlevel 7
Badge +9
Im not sure, but i think the issue begin before Kaspersky is installed Already run the privacy cleaner and reboot afterwards. here is the report
Hello @hazzy,
Thank you for the data.
  1. When you say: "Already run the privacy cleaner and reboot ", do you mean, you'd run it before (me) asking "Run Privacy Cleaner, including Reboot", or you've run it since I requested step 3?
  2. What date did the issue begin?
  3. Exactly what happened when the issue started? Everything in the 24hours leading up to the first moment you knew there was an issue?
  1. i run it after you request it 🙂
  2. im not sure when the issue begin , its been one or two week before i notice it was a trojan
  3. at first i notice theres a file in the usb , i thought it was some protection thing from kaspersky program, but then i remember i dont have any kaspersky installed at that moment, and then after googling for answer i cant find any, i install kaspersky to try removing the file but i still couldnt , so here i am
Userlevel 7
Badge +9
@hazzy,
AS well as my last post, please redo the REPORT, select ALL events, select 30days, export, save as text file, upload to your post.
Thank you.
Here it is
Userlevel 7
Badge +9
Hello @hazzy,
When (what date) did you install Kaspersky software?
if im not wrong i installed it at 29th September
Userlevel 7
Badge +9
Hello @hazzy,
From this point forward don't make any changes at all, just provide info and follow exactly any steps I post. I will post as I work thru this, not all at once - ok?
--
  1. Have you consciously installed KMSpico? If "yes", when - date?
i dont think i ever install KMSpico, and i only notice it after kaspersky scan it , so i remove it with kaspersky
no i dont consciously install KMSpico
Userlevel 7
Badge +9
Please do the following:
  1. Exit every application except Kaspersky - nothing is to be used or running.
  2. KSCloud, select Settings⚙, select Additional, select Reports & Quarantine, select Clear
  3. KSCloud, select Settings⚙, select Manage Settings, select Restore Settings
  4. Shutdown computer using FULL shutdown, not Restart.
  5. When computer is fully off, restart computer, login
  6. Make sure the ONLY application active is KSCloud,
  7. KSCloud, select Settings⚙. select Manage Settings, select Maximum Security Level
  8. Run manual Database Update - allow it to complete.
  9. Run manual FULL Scan, allow it to complete - do not use the computer while it's running.
  10. When FULL Scan is complete, KSCloud, export the ALL Events Report and upload to your post please?
Here you go
Userlevel 7
Badge +9
Hello @hazzy,
Was All Events selected?
yes this is already all event
Userlevel 7
Badge +9
Hello @hazzy,
As per my earlier post, may I have another GSI & Windows Logs please?
Thank you.
i think i already PM u the GSI & windows logs
Userlevel 7
Badge +9
Hello Hazzy,
Now you've run the requested procedures, I'd like a new GSI & Windows Logs please?
Thank you.

these are the document u requested

Reply