forumNew topic

Employee plugged in a USB stick they brought in, and I immediately started getting all sorts of warnings. Should I run a virus scan?

FFurkan Y***MemberCommunity member
Joined
Jan 2024
Message
11
#1

When I plugged in the USB drive I got from our subcontractor with a project file, my antivirus suddenly started alarming. Then a few tabs opened in the browser, loading weird videos under the name YouTube. I pulled the USB out in fear but the computer is acting weird — especially CPU usage is stuck at 80%.

I can't even see which files are on the USB it gives an 'Access Denied' error. The antivirus says it's a USB contaminated intentionally or accidentally by a student, but I don't know exactly what's going on.

What happens if I shut down the computer? Should I run an antivirus product or wait a bit? I need to plug the same USB into my friend's computer too, but I don't want to take the risk. What should I do?

MMurat G***Member
Job title
Purchasing manager
Sector
Sports and fitness
Organization type
20-person company
Joined
Apr 2023
Message
2
Most Helpful#2

USB Pendrive viruses usually start with the autorun.inf file (most Windows systems run this automatically). Steps: 1) Restart the computer and enter Safe Mode with Networking (antivirus will be active), 2) Run a full antivirus scan (can take 2-3 hours), 3) Do a second scan with another antivirus product like Hitman Pro, 4) Absolutely do not plug the USB into another machine, 5) To check who was on the USB: inspect the USB contents from another computer using a Linux Live USB (since Linux has fewer viruses). 6) Do not copy files, only read them (hex editor etc.), 7) Inform the subcontractor. Viruses quarantined by antivirus are usually cleaned, but full disinfection might not happen — registry values may remain, so the safe mode scan process is important.

BBurak A***Member
Job title
IT manager
Sector
E-commerce
Organization type
early-stage startup
Joined
May 2023
Message
126
#3

usb viruses are common, epecially on shared computers... run an antivirus scan then check the files via linux live usb. btw and ask the source — why did the subcontractor send a contaminated usb...

MMert K***Expert
Job title
Data entry clerk
Sector
Leather
Organization type
40-person manufacturing company
Joined
Jun 2023
Message
18
#4

Looks like an Autorun.inf virus + Worm combo. Open CMD (Safe Mode), run these commands: tasklist | findstr /V (find executables), HKCU\Software\Microsoft\Windows\Run (check registry startup keys), check if any device started independently of the USB. If there's malware persistence, you need to clean the startup items. Mounting the USB via Live Linux USB (Ubuntu) to check files would be safer.

SSena P***New member
Job title
Logistics planning
Sector
Construction
Organization type
chain store
Joined
Jul 2026
Message
389

Doki · Interface design · 2023

#5

the subcontractors computer must be in terrible shape, there are a lot of viruses on the USB then but dont panic, the antivirus is good quality (an antivirus product is good) run a scan immediately. shutting down the computer doesnt mean the problem is over, the virus can remain in the registry. honestly do a full scan itll take 2-3 hours comfortably. but never plug this USB into another computer...

AAyberkExpert
Job title
Mobile developer
Joined
Jul 2023
Message
208
#6

Mechanism of USB Media transfer viruses: 1) autorun.inf starts an exe file, 2) Persistence is set in the Registry (Run RunOnce), 3) File association is changed, 4) DNS redirection is performed. Phishing/spyware can also be added. Prevention: 1) Disable Autorun via GPO in gpo.msc (HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Explorer\DisableAutoRun), 2) Set USB restriction (read-only), 3) Set up a USB white-list, 4) Prefer file transfer via email.

HHatice T***ExpertCommunity member
Joined
Mar 2025
Message
222
#7

virus!!! this is really bad. tbh turn off the PC immediately, physiccally disable the USB port. run a strong antivirus, one product is good but not enough, install another one too then and look... if there's network code inside, the whole company network is at risk...

LLale T***Member
Job title
Supply chain manager
Sector
IT services
Organization type
family business
Joined
May 2024
Message
338
#8

Let me summarize the topic, since several different answers were given. When making a decision, first look at what data you have on hand.

Most time waste accumulates in tasks waiting for approval.

YYağmur E***Expert
Job title
Country Manager
Sector
E-commerce
Organization type
boutique agency
Joined
May 2023
Message
115
#9

Let me summarize the topic, since several different answers were given. An automated scan report is not the same as a penetration test.

Trying to do this alone is the most expensive way. If I were you, I'd go this route.

SSelinMember
Job title
Frontend developer
Organization type
20-person company
Joined
Feb 2024
Message
164
#10

I have a question. Forgotten test environments are more often the entry point than live systems.

HHakan B***Expert
Job title
Human Resources Specialist
Sector
Plastic
Organization type
early-stage startup
Joined
Jan 2026
Message
409
#11

Yes that's exactly how it is with virus spread via usb. The harder it is to reverse a decision the slower you should make it.

The biggest time-waster for us was not knowing who had the final say. Good luck with that.

BBeren B***MemberCommunity member
Joined
Oct 2023
Message
114
#12

The most overlooked point about virus spread via usb is this: An automated scan report is not the same as a penetration test.

When we decide without measuring, we always end up in the same place. If you have questions, write them; I'll answer as best I can.

MMurat K***MemberCommunity member
Joined
Feb 2023
Message
6
#13

There's a common mistake people make when doing this. When you try to change everything at once, nothing settles.

That's all, sorry if I went on too long.

KKader K***Member
Job title
Store Manager
Sector
Printing
Organization type
8-person team
Joined
Feb 2022
Message
4
#14

You're right, I've been down that road too. Trying to do this alone is the most expensive way.

If it's your first time, start small; scaling comes later.

PPınar B***Member
Job title
Technical service technician
Sector
Packaging
Organization type
a company within a holding
Joined
Jul 2025
Message
263
#15

My question might sound amateurish, sorry about that. Mistakes made on the virus spread via usb side are usually reversible but expensive.

This is my opinion, I'm not claiming it's absolute truth.

BBurcu A***Member
Job title
Operations director
Sector
Cosmetics
Organization type
regional distributor
Joined
Jan 2022
Message
5

Doki · Mobile app · 2026

#16

Let me speak from the other side; I'm on the supplier side... Your time to detect an issue directly determines its cost.

Good luck with that.

HHasan G***Member
Job title
QA Tester
Sector
Printing
Organization type
cooperative
Joined
Mar 2022
Message
8
#17

I'll try it. Just because everyone does it doesn't mean it's right.

If you have questions, write them; I'll answer as best I can.

KKORİDoki team
Job title
Forum moderator
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Jan 2023
Message
2,840
Sentinel#18

This question comes up often on the forum, so I'll leave a consolidated answer: start with an inventory — what you have, where it's located, and who has access. Every measure taken without an inventory leaves an unseen door open.

RReyhan K***MemberCommunity member
Joined
Jun 2025
Message
1
#19

Thanks a lot Ill try it today. Payment information changes are never verified through the channel they came from.

Good luck with that.

OOsmanMember
Job title
Agricultural machinery dealer
Joined
May 2024
Message
70

Doki · Incident response support · 2023

#20

You're right. An untested backup is not a backup.

An automated scan report is not the same as a penetration test.

Reply