UnderstandDetectRemovePreventEncryptTeamsDispose

USB Drive Viruses — How to Detect, Remove & Prevent Malware on USB

A USB drive can carry infected files, launch deceptive shortcuts, or impersonate another device. This guide explains how to inspect a drive safely, clean common infections, reduce future risk, and protect the data stored on it.

USB Safety Desk Editorial TeamUpdated July 202618 min read
QUICK ANSWER

Do not open an unfamiliar USB drive immediately. Scan it with current security software, show hidden files, inspect unexpected shortcuts or executables, and copy only verified files. Formatting usually removes file-based malware, but it does not reliably address malicious USB firmware such as BadUSB. For sensitive data, combine safe handling with encryption and a trusted-device policy.

USB flash drive surrounded by visual malware and protection symbols
Fast answers to common searches

How to Remove Virus from USB Drive

Disconnect the drive from other computers, update your antivirus, reconnect it without opening files, and run a custom scan of the USB volume. Quarantine detected items, reveal hidden files, and verify documents before copying them to a clean location. If the infection keeps returning, wipe and reformat the drive after backing up only known-safe files.

Does Formatting a USB Drive Remove Viruses?

A full format generally removes malware stored in the visible file system. A quick format may leave recoverable data, and neither method proves that device firmware is trustworthy. Replace a drive that behaves like an unexpected keyboard, network adapter, or other device.

How to Remove Virus from a Flash Drive

Use the same isolate, scan, quarantine, verify, and reformat sequence. Avoid random “USB cleaner” downloads. Use your operating system’s security tools or security software from a known vendor.

Threat context

Why USB Drives Are a Major Security Risk

File-based

Infected files

Documents, installers, scripts, archives, and shortcuts can carry or launch malware. The risk increases when file extensions are hidden or when users open files before scanning.

Device behavior

BadUSB and HID attacks

A reprogrammed device may identify itself as a keyboard or network adapter. Traditional file scanning cannot inspect all controller firmware.

Data exposure

Loss and copying

An unencrypted drive can expose private files if it is lost, borrowed, or connected to a compromised computer. Write protection and encryption address different parts of this risk.

Portable USB drive illustrating removable storage security risks
Detection

How to Detect a Compromised USB Drive

Inspect the physical device

Check for a broken shell, altered label, unexpected adapter, loose connector, or signs that the enclosure has been opened. Treat unexplained changes as a reason to replace the drive.

Connect only to a low-risk, updated computer

Do not test a suspicious drive on a production workstation or a computer that holds irreplaceable data. Organizations should use an isolated scanning station.

Scan before browsing

Run a custom scan against the drive letter or mounted volume. Keep real-time protection enabled and avoid double-clicking the drive in an old or unpatched environment.

Look for behavioral warning signs

Unexpected command windows, rapid automated typing, new network interfaces, disabled security controls, missing files, shortcut-only folders, or repeated reinfection are serious warning signs.

Signs of a shortcut virus

Your folders appear as shortcuts, original files become hidden, unfamiliar .lnk, .vbs, .cmd, or .exe files appear, or the infection returns after deleting visible shortcuts.

Windows File Explorer displaying a connected removable USB drive
Method 1

How to Remove Virus from USB Drive Using Built-In Tools

Windows: scan, reveal, verify, then reformat if needed

  1. Update Windows Security and disconnect other removable drives.
  2. Insert the USB drive while holding off on opening any files.
  3. Open Windows Security, choose Virus & threat protection, Scan options, Custom scan, and select the USB drive.
  4. Quarantine detected items and restart if Windows requests it.
  5. In File Explorer, enable file-name extensions and hidden items. Do not open suspicious shortcuts or scripts.
  6. Copy only verified personal files to a temporary clean folder, scan them again, then format the USB drive when confidence is low.
Best for
Common file-based malware and shortcut infections.
Limitation
Cannot establish that USB controller firmware is clean.

Optional owner-safe command

The following command removes hidden and system attributes from files so you can inspect them. Replace E: with the correct USB drive letter. It does not remove malware by itself.

attrib -h -r -s /s /d E:\*.*

Confirm the drive letter carefully. Never run destructive commands against a drive you have not positively identified.


Mac: scan with trusted software and erase when necessary

macOS does not include a general-purpose manual USB malware scanner comparable to a custom Windows Security scan. Keep macOS and its built-in protections current, inspect files carefully, and use reputable security software when the drive came from an untrusted source. To erase and encrypt a device, use Disk Utility, select the physical device, and choose an appropriate format. Erasing destroys existing data.

Security illustration showing prevention of malware spreading from a USB device
My situation is…

Choose the safest next step

Where did the drive come from?
Does it show suspicious behavior?
How sensitive is the computer?
Prevention

USB Safety Best Practices

Trust the source
Use organization-issued or personally purchased drives. Never connect a USB device found in public, received unexpectedly, or handed out without a clear chain of custody.
Highest impact
Scan first
Keep security software current and scan the mounted volume before opening files. Enable file extensions so a disguised executable is easier to spot.
Easy
Limit write access
Use a physical write-protect switch where available, or mount media read-only in controlled workflows. This reduces accidental changes but does not neutralize malicious device firmware.
Situational
Encrypt sensitive data
Use BitLocker To Go, encrypted APFS storage, a cross-platform encrypted container, or a dedicated USB protection tool. Store recovery information separately.
For lost-drive risk
Avoid public computers
A password-protected drive can still be exposed after you unlock it on a compromised computer. Use a trusted device, secure browser workflow, or a disposable transfer process.
Travel
USB flash drive security best practices and safe handling illustration
Firmware-level risk

The BadUSB Threat — How It Works and How to Prevent It

BadUSB describes attacks that alter a USB controller’s firmware so the device can impersonate another class of peripheral. A storage drive may also present itself as a keyboard and issue commands, or as a network adapter and influence traffic. Because the malicious behavior is below the ordinary file system, deleting files or formatting the storage partition is not a dependable fix.

Practical defenses

  • Do not connect unknown devices.
  • Use device allowlisting and block unnecessary USB classes in managed environments.
  • Use dedicated transfer stations for high-risk or air-gapped networks.
  • Buy tamper-evident or security-focused devices from traceable suppliers.
  • Replace a drive that unexpectedly identifies as multiple devices.
Blocked USB port representing device control against untrusted peripherals
Data protection

How USB Encryption Protects Your Data

Encryption protects files if the drive is lost or stolen. It does not block malware already on the device, and it cannot make an untrusted USB controller safe.

BitLocker To Go

Windows encryption for removable drives. It is convenient in Windows-centered environments and can protect FAT, FAT32, exFAT, and NTFS removable volumes. Recovery-key handling is essential.

Best for Windows

Encrypted APFS

Mac users can erase and format a removable device with encryption through Disk Utility. Native convenience is strong, while Windows interoperability is limited.

Best for Mac

Cross-platform software

Tools such as encrypted containers or portable USB protection can support mixed environments. Verify platform support, update requirements, and recovery options before deployment.

Best for mixed devices
USB disk security software protecting files with encryption
At a glance

BitLocker to Go vs Third-Party USB Security

MethodDifficultySecurityCostBest forLimitations
Scan only●●○○Malware detectionUsually includedRoutine inspectionNo lost-drive protection
BitLocker To Go●●●○Strong data encryptionWindows edition dependentWindows fleetsCross-platform friction
Encrypted APFS●●●○Strong data encryptionIncluded with macOSMac-only useLimited Windows access
VeraCrypt container●●●●Strong encrypted containerFreeTechnical usersSoftware and setup required
Hardware-encrypted USB●●○○Dedicated device encryptionHigher device costRegulated or high-risk dataVendor and certification vary
The tool we recommend for straightforward USB locking

USB Secure makes password protection easier to carry between PCs

Of the options covered here, we recommend USB Secure for people who want a focused, portable way to password-protect files on a USB drive without managing a more technical encrypted-container workflow. It is developed by NewSoftwares.net.

Its limitation matters: USB Secure protects access to data. It does not replace antivirus scanning, device-control policies, or defenses against malicious USB firmware.

Portable protectionSimple lock workflowWindows-focusedRecovery planning required

USB Secure

Removable Drive
Files protected
Locked

Protection status: active

USB Secure software box artwork for password protecting removable drives
What the recommended tool adds

USB Security Software Features That Matter

1
Portable locking

Protect access to files stored on a removable drive without relying on the computer’s account password.

Best for travel
2
Password workflow

A focused lock and unlock process can be easier for nontechnical users than managing partitions or encrypted containers.

Best for simplicity
3
Data confidentiality

Helps reduce exposure if the drive is lost or casually accessed. Strong passwords and secure recovery practices remain necessary.

Not malware removal
4
Mixed-use caution

Test every destination computer before relying on portable protection, especially across Windows editions or managed workplace devices.

Verify compatibility
USB Secure software interface and removable-drive protection overview
Step by step

How to Password Protect a USB Drive Using USB Secure

Back up the drive

Copy important data to a trusted location and scan the backup. Any operation involving protection or formatting should begin with a verified backup.

Download from the developer

Use the official NewSoftwares.net product page. Avoid repackaged installers from download portals.

Install or copy the protection component

Follow the current installer prompts and select the intended removable drive. Confirm the drive capacity and label before proceeding.

Create a strong, unique password

Use a long passphrase that is not reused elsewhere. Save recovery or license information separately from the USB drive.

Lock, safely eject, and test

Lock the drive, eject it properly, reconnect it, and verify both successful unlocking and access from the computers you expect to use.

USB Secure password dialog used to unlock protected portable-drive files
Technical overview

How USB Drive Protection Works

Security software compares files and behavior against signatures, reputation data, and detection rules. It helps with file-based threats but cannot prove firmware integrity.

Encryption transforms stored data so it cannot be read without the key. A user-facing lock may control access to an encrypted area or protected application workflow.

Hardware write protection can stop the host from modifying storage contents. Software policies can restrict writing too, but administrative control and device behavior affect reliability.

Native formats and encryption work best inside their own ecosystems. Mixed Windows and Mac use often requires exFAT plus a compatible protection layer, or separate transfer procedures.

Virtual drive workspace for viewing protected USB files
Platform-specific notes

Cross-Platform USB Encryption — Mac and Windows

Choose the protection method based on every computer that must unlock the drive. A format that mounts on both operating systems does not guarantee that its encryption layer will work on both.

Air-gapped networks need stricter controls

Encryption protects confidentiality during transfer, but removable media can bridge otherwise isolated systems. Use dedicated drives, one-way workflows where possible, an isolated scanning station, device inventories, and explicit approval for every transfer.

Do not reuse the same drive between internet-connected and critical systems without an approved sanitization process.

Universal file-system support for removable storage across computers
Device options

Hardware-Encrypted USB Drives vs Software Encryption

ConsiderationHardware-encryptedSoftware-encryptedEditorial note
Key handlingInside device or keypad workflowManaged by OS or applicationRecovery design matters more than convenience claims
Cross-platform useOften OS-independent after unlockDepends on software and formatTest on managed endpoints
CostHigher per deviceFree to moderateInclude support and replacement costs
CertificationSome models validatedProduct and environment dependentCheck the exact module and certificate status
BadUSB exposureNot automatically eliminatedNot addressedFirmware trust is a separate control

What FIPS 140-2 or FIPS 140-3 means

FIPS validation applies to a specified cryptographic module and configuration, not every security claim made about a product family. Organizations should verify the exact certificate, status, module version, and required operating conditions rather than relying only on packaging language.

External hard drive and USB storage protected by security software
Common errors and fixes

USB Drive Troubleshooting Guide

ProblemLikely causeSafe fix
Files became shortcutsShortcut malware or hidden attributesScan, quarantine, reveal extensions, restore attributes, verify files, then reformat if needed.
USB drive is write-protectedPhysical switch, policy, file-system error, failing flashCheck the hardware switch and organization policy, test read-only recovery, back up readable data, then replace a failing drive.
Cannot remove a partitionMounted volume, permissions, protected layoutBack up data, use Disk Management or Disk Utility as the owner, and confirm the correct physical disk before deleting partitions.
Forgot the USB passwordLost password or recovery materialUse the saved recovery key, vendor-supported account or license recovery, or restore from backup. Do not use password-cracking tools.
Virus returns after formattingInfected computer, restored infected files, or firmware concernIsolate and scan the computer, do not restore unknown files, and retire the USB device if suspicious behavior persists.
Drive not recognizedPort, power, file system, controller, or physical failureTry a trusted computer and port, inspect Disk Management or Disk Utility, avoid repeated writes, and use professional recovery for valuable data.
Google Drive download blockedSecurity scan, sharing policy, account restrictionAsk the owner or administrator to verify the file and permissions. Do not bypass warnings or access controls.
Organizations

USB Security Policies for Teams and Organizations

A workable policy defines which devices are allowed, who may use them, where they may connect, how data must be encrypted, and what happens after loss or suspected compromise. Technical controls should support the policy rather than relying on employee memory alone.

Minimum policy controls

  • Allow only organization-issued devices with unique inventory IDs.
  • Block unknown USB storage or place it in read-only mode.
  • Require encryption for confidential or regulated information.
  • Use endpoint logging and alert on new device classes.
  • Provide an isolated scanning and transfer station.
  • Define loss, incident, return, and destruction procedures.

USB safe usage checklist

0 of 8 completed

Approved whitelisted USB drive for managed organizational security
End of life

USB Drive Safe Disposal and Data Wiping

Before reuse or disposal, identify the data sensitivity and the storage technology. For ordinary low-risk reuse, erase the drive, recreate the partition, and verify that no expected files remain. For confidential information, follow your organization’s sanitization standard and record the result.

Flash memory controllers use wear leveling, so repeated overwrite passes do not provide the same assurance as they once did on magnetic media. Cryptographic erase may be appropriate when strong encryption was used from the beginning and keys can be reliably destroyed. For highly sensitive data or a failing device, physical destruction by an approved service may be the defensible choice.

Formatting is not a universal sanitization method

A quick format mainly rebuilds file-system structures. Even a full format addresses the storage area, not malicious firmware. Match the disposal method to the data’s sensitivity, the device’s condition, and your compliance requirements.

Fine shredded material symbolizing secure destruction of sensitive data
Decision guide

Which USB Protection Method Is Right for You?

Home user

Recommended: current antivirus plus BitLocker To Go, encrypted APFS, or simple USB protection.

Alternative: avoid removable media and use end-to-end encrypted sharing.

Traveler

Recommended: encrypted drive, minimal data, trusted computers only, and a remote backup.

Alternative: hardware-encrypted USB for higher-risk travel.

Small team

Recommended: issued drives, encryption, inventory, scan-before-use rules, and incident reporting.

Alternative: managed cloud transfer with removable storage blocked.

Regulated organization

Recommended: centrally managed device control and validated cryptography aligned to policy.

Alternative: prohibit USB storage except approved exceptions.

Air-gapped environment

Recommended: dedicated one-direction transfer workflow and isolated scanning station.

Alternative: purpose-built data diode or controlled media gateway.

Unknown drive

Recommended: do not connect it. Return it to security, lost property, or appropriate authorities.

Alternative: none on a normal computer.

Frequently asked questions

USB Malware and Security Questions

It is the process of identifying malicious files or abnormal device behavior, removing or isolating threats, and reducing future exposure through trusted-device rules, software updates, scanning, encryption, write controls, and secure disposal.
Yes. Malware may exist outside the protected area, may activate after the drive is unlocked, or may be present on the computer used to unlock it. Password protection is a confidentiality control, not a substitute for scanning.
For high-risk use, look for a reputable hardware-encrypted drive with tamper resistance, signed firmware, clear recovery design, and a current validation that matches your compliance requirement. No device removes the need for trusted handling.
Use a trusted computer whenever possible. On a shared computer, assume administrators or malware could access files after unlocking. Keep only minimal data on the drive, scan before use, avoid saving credentials, and change sensitive passwords afterward if compromise is suspected.
BadUSB can make a device impersonate a keyboard, network adapter, or other peripheral. Use only trusted devices, enforce USB class controls, monitor new peripherals, and retire devices with unexplained behavior.
No. Hand it to the organization’s security team, lost property, or appropriate authorities. Curiosity is a common social-engineering vector.
Ordinary USB drives usually do not maintain trustworthy access logs. File timestamps can change for benign reasons and can be altered. For accountability, use managed encrypted devices, endpoint logging, or a document system with audit records.
Organizations can log device identifiers, connection times, user sessions, file events, or policy violations on managed endpoints. Consumer USB drives generally do not provide location tracking by themselves.
Hardware-encrypted drives perform cryptographic operations within the device and may unlock by keypad or onboard controls. Software encryption uses the operating system or an application. Hardware can simplify cross-platform use but costs more and still requires vendor trust.
Back up what must be retained, identify the storage type, and follow an approved sanitization method. For sensitive flash media, cryptographic erase or certified physical destruction may provide more defensible assurance than repeated overwriting.
BitLocker To Go integrates with supported Windows editions and provides full-volume encryption. USB Secure offers a simpler dedicated protection workflow. Choose based on Windows edition, destination computers, recovery needs, and administrative policy.
Use a purpose-built FIDO2 security key for phishing-resistant authentication. Some systems can store a startup or recovery key on removable media, but that is different from a FIDO authenticator and should follow the platform’s official setup process.
Google Drive access is controlled through the Google account and sharing permissions rather than a separate password for each folder. For an additional layer, encrypt files locally before upload or use an approved cloud-folder protection tool. Do not share encryption passwords through the same channel as the files.
OneDrive does not add an arbitrary password directly to a normal folder. Depending on your account and use case, use sharing controls, Personal Vault, or encrypt files before synchronization. Workplace policies may restrict third-party encryption.
As the owner, unlock the drive, copy and verify your files, then use the product’s official uninstall or decryption workflow. If the drive cannot be unlocked, use legitimate recovery keys or vendor support. Reformatting destroys data and should be a last resort after backup.
A full format generally removes malware stored in the file system. Reinfection can occur from the computer or restored files, and firmware-level threats are outside the normal storage partition.
More on this topic

In-Depth Answers

Authoritative references: Microsoft BitLocker FAQ, Apple Disk Utility guidance, and NIST media sanitization guidance.

Our verdict

Scan for malware, control device trust, then encrypt the data

There is no single USB setting that solves every risk. File scanning addresses common malware, trusted-device policies address unknown peripherals, and encryption protects data after loss. BadUSB remains a separate firmware and device-identity problem.

For most Windows users who want a straightforward portable locking workflow, USB Secure is a reasonable option after the drive and computer are known to be clean. BitLocker To Go is stronger for native Windows full-volume encryption, while hardware-encrypted drives and managed device control fit higher-risk organizations.

You are hereUSB malware guide